| CVE-2026-84961 | 7.4 | — | — | — | — | undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes | 36d ago |
| CVE-2026-18489 | 7.4 | — | — | — | — | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtai | 36d ago |
| CVE-2026-85525 | 7.4 | — | — | — | — | Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS cer | 36d ago |
| CVE-2026-62906 | 7.4 | — | — | — | — | Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthoriz | 37d ago |
| CVE-2026-84777 | 7.4 | — | — | — | — | Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. | 37d ago |
| CVE-2026-75034 | 7.4 | — | — | — | — | A flaw was found in Rancher Manager. | 37d ago |
| CVE-2026-85091 | 7.4 | — | — | — | — | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when | 37d ago |
| CVE-2023-20577 | 7.4 | — | — | — | — | A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to | 38d ago |
| CVE-2026-84675 | 7.4 | — | — | — | — | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control bu | 38d ago |
| CVE-2026-84366 | 7.4 | — | — | — | — | Scrapy is a high-level web crawling and scraping framework for Python. | 39d ago |
| CVE-2026-73718 | 7.4 | — | — | — | arubanetworks / fabric composer | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthentic | 39d ago |
| CVE-2026-84059 | 7.4 | — | — | — | — | A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. | 39d ago |
| CVE-2026-82225 | 7.4 | — | — | — | — | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. | 40d ago |
| CVE-2026-82608 | 7.4 | — | — | — | — | A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. | 40d ago |
| CVE-2026-82597 | 7.4 | — | — | — | — | A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. | 41d ago |
| CVE-2026-82595 | 7.4 | — | — | — | — | A vulnerability was found in D-Link DIR-825M 1.1.8. | 41d ago |
| CVE-2026-82480 | 7.4 | — | — | — | — | A security flaw has been discovered in NASA cFS up to 7.0.1. | 41d ago |
| CVE-2026-82289 | 7.4 | — | — | — | — | Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gi | 43d ago |
| CVE-2026-82281 | 7.4 | — | — | — | — | Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv | 43d ago |
| CVE-2026-81020 | 7.4 | — | — | — | — | wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never i | 43d ago |
| CVE-2026-81019 | 7.4 | — | — | — | — | wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never | 43d ago |
| CVE-2026-73208 | 7.4 | — | — | — | — | An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token res | 43d ago |
| CVE-2026-40018 | 7.4 | — | — | — | — | None None None No publicly available exploits are known. | 43d ago |
| CVE-2026-18717 | 7.4 | — | — | — | — | ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an at | 44d ago |
| CVE-2026-59288 | 7.4 | — | — | — | vmware / spring for graphql | The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. | 44d ago |
| CVE-2026-47841 | 7.4 | — | — | — | vmware / spring security | An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a | 45d ago |
| CVE-2026-54550 | 7.4 | — | — | — | — | IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. | 45d ago |
| CVE-2026-41707 | 7.4 | — | — | — | — | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProof | 46d ago |
| CVE-2026-79286 | 7.4 | — | — | — | google / chrome | Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker | 46d ago |
| CVE-2026-79664 | 7.4 | — | — | — | — | Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to m | 46d ago |
| CVE-2026-53561 | 7.4 | — | — | — | apache / hive | An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through | 46d ago |
| CVE-2026-56135 | 7.4 | — | — | — | — | In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs- | 47d ago |
| CVE-2026-76072 | 7.4 | — | — | — | — | The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running una | 47d ago |
| CVE-2026-76844 | 7.4 | — | — | — | — | webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname ag | 47d ago |
| CVE-2026-21751 | 7.4 | — | — | — | — | HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauth | 47d ago |
| CVE-2026-10582 | 7.4 | — | — | — | — | Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it in | 47d ago |
| CVE-2026-78157 | 7.4 | — | — | — | — | A vulnerability was detected in Open5GS 2.8.0. | 47d ago |
| CVE-2026-78156 | 7.4 | — | — | — | — | A security vulnerability has been detected in Open5GS 2.8.0. | 48d ago |
| CVE-2026-78141exploited | 7.4 | 2.7% | 1/3 | +9d | — | A vulnerability has been found in Tenda CH22 1.0.0.1. | 48d ago |
| CVE-2026-78063 | 7.4 | — | — | — | — | A security flaw has been discovered in Tenda CH22 1.0.0.1. | 48d ago |
| CVE-2026-78122 | 7.4 | — | — | — | — | docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAIN | 49d ago |
| CVE-2026-77945 | 7.4 | — | — | — | — | A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. | 49d ago |
| CVE-2026-53525 | 7.4 | — | — | — | — | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. | 50d ago |
| CVE-2026-62960 | 7.4 | — | — | — | — | Git for Windows is the Windows port of Git. | 50d ago |
| CVE-2026-77031 | 7.4 | — | — | — | — | A vulnerability has been found in Tenda CH22 1.0.0.1. | 51d ago |
| CVE-2026-77004 | 7.4 | — | — | — | — | A flaw has been found in Comfast CF-N1-S 2.6.0.1. | 51d ago |
| CVE-2026-19611 | 7.4 | — | — | — | — | A flaw was found in WildFly Elytron. | 51d ago |
| CVE-2026-76591 | 7.4 | — | — | — | — | A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. | 52d ago |
| CVE-2026-76403 | 7.4 | — | — | — | splunk / connect for kafka | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could rea | 52d ago |
| CVE-2026-76362 | 7.4 | — | — | — | splunk / soar | In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splu | 52d ago |
| CVE-2025-36254 | 7.4 | — | — | — | ibm / ds8900f firmware | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an | 52d ago |
| CVE-2026-76583 | 7.4 | — | — | — | — | A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. | 52d ago |
| CVE-2026-76582 | 7.4 | — | — | — | — | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. | 52d ago |
| CVE-2026-16851 | 7.4 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a | 52d ago |
| CVE-2026-62669 | 7.4 | — | — | — | — | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. | 52d ago |
| CVE-2026-76214 | 7.4 | — | — | — | phpmyfaq / phpmyfaq | phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither | 52d ago |
| CVE-2026-76213 | 7.4 | — | — | — | phpmyfaq / phpmyfaq | phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure | 52d ago |
| CVE-2026-58088 | 7.4 | — | — | — | freebsd / freebsd | The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding pro | 52d ago |
| CVE-2026-75985 | 7.4 | — | — | — | — | A flaw has been found in TRENDnet Router 1.1.02b01. | 52d ago |
| CVE-2026-75984 | 7.4 | — | — | — | — | A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. | 52d ago |