| CVE-2026-48079 | 7.4 | — | — | — | — | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. | 64d ago |
| CVE-2026-19139 | 7.4 | — | — | — | google / chrome | Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform | 64d ago |
| CVE-2026-9205 | 7.4 | — | — | — | langflow / langflow | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. | 66d ago |
| CVE-2026-8470 | 7.4 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Pyt | 66d ago |
| CVE-2026-70604 | 7.4 | — | — | — | — | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. | 66d ago |
| CVE-2026-16442 | 7.4 | — | — | — | redhat / build of keycloak | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user au | 66d ago |
| CVE-2026-16443 | 7.4 | — | — | — | redhat / build of keycloak | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core e | 66d ago |
| CVE-2026-25288 | 7.4 | — | — | — | qualcomm / orne firmware | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | 67d ago |
| CVE-2026-60007 | 7.4 | — | — | — | eclipse / milo | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid | 67d ago |
| CVE-2026-14838 | 7.4 | — | — | — | — | Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy | 67d ago |
| CVE-2026-66321 | 7.4 | — | — | — | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 67d ago |
| CVE-2026-65802 | 7.4 | — | — | — | microsoft / edge chromium | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose in | 67d ago |
| CVE-2026-67598 | 7.4 | — | — | — | — | Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php th | 68d ago |
| CVE-2026-18556zero day | 7.4 | 7.9% | 3/3 | same day | n-able / n-central | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication B | 70d ago |
| CVE-2026-67316 | 7.4 | — | — | — | axios / axios | axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.proto | 70d ago |
| CVE-2026-51953 | 7.4 | — | — | — | — | An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authenti | 70d ago |
| CVE-2026-18394 | 7.4 | — | — | — | — | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers | 71d ago |
| CVE-2026-8497 | 7.4 | — | — | — | devolutions / password manager | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026. | 73d ago |
| CVE-2026-13697 | 7.4 | — | — | — | nodejs / undici | undici's cache interceptor mishandles malformed Cache-Control private directives. | 73d ago |
| CVE-2026-54660 | 7.4 | — | — | — | — | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. | 73d ago |
| CVE-2026-13690 | 7.4 | — | — | — | — | The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-facto | 73d ago |
| CVE-2026-56822 | 7.4 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 73d ago |
| CVE-2026-56821 | 7.4 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 73d ago |
| CVE-2026-15328 | 7.4 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0 | 73d ago |
| CVE-2026-14528 | 7.4 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive inform | 73d ago |
| CVE-2026-55953 | 7.4 | — | — | — | erlang / erlang\/otp | The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the ser | 75d ago |
| CVE-2026-59546 | 7.4 | — | — | — | — | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | 75d ago |
| CVE-2026-57990 | 7.4 | — | — | — | microsoft / edge chromium | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized atta | 76d ago |
| CVE-2026-57989 | 7.4 | — | — | — | microsoft / edge chromium | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information | 76d ago |
| CVE-2026-66141 | 7.4 | — | — | — | exim / exim | Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled. | 78d ago |
| CVE-2026-64829 | 7.4 | — | — | — | — | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previousl | 80d ago |
| CVE-2026-56820 | 7.4 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 80d ago |
| CVE-2026-61234 | 7.4 | — | — | — | oracle / peoplesoft enterprise fin common objects | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: ePro | 80d ago |
| CVE-2026-61210 | 7.4 | — | — | — | oracle / peoplesoft enterprise scm manufacturing | Vulnerability in the PeopleSoft Enterprise SCM Manufacturing product of Oracle PeopleSoft (component: Security). | 80d ago |
| CVE-2026-61185 | 7.4 | — | — | — | oracle / agile product lifecycle management for process | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (compone | 80d ago |
| CVE-2026-61173 | 7.4 | — | — | — | oracle / agile product lifecycle management | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). | 80d ago |
| CVE-2026-61164 | 7.4 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 80d ago |
| CVE-2026-61135 | 7.4 | — | — | — | oracle / commerce platform | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework) | 80d ago |
| CVE-2026-61113 | 7.4 | — | — | — | oracle / application object library | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). | 80d ago |
| CVE-2026-60827 | 7.4 | — | — | — | oracle / isupport | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | 80d ago |
| CVE-2026-60823 | 7.4 | — | — | — | oracle / isupport | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | 80d ago |
| CVE-2026-60725 | 7.4 | — | — | — | oracle / mysql router | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). | 80d ago |
| CVE-2026-60667 | 7.4 | — | — | — | oracle / peoplesoft enterprise hcm human resources | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). | 80d ago |
| CVE-2026-60317 | 7.4 | — | — | — | oracle / mysql connector\/net | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). | 80d ago |
| CVE-2026-60179 | 7.4 | — | — | — | oracle / mysql connector\/c\+\+ | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). | 80d ago |
| CVE-2026-47058 | 7.4 | — | — | — | oracle / jre | Vulnerability in Oracle Java SE (component: Scripting). | 80d ago |
| CVE-2026-47050 | 7.4 | — | — | — | oracle / vm virtualbox | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). | 80d ago |
| CVE-2026-47026 | 7.4 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboa | 80d ago |
| CVE-2026-46943 | 7.4 | — | — | — | oracle / retail eftlink | Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). | 80d ago |
| CVE-2026-16404 | 7.4 | — | — | — | mozilla / firefox mobile | Spoofing issue in Firefox for Android. | 81d ago |
| CVE-2026-62232 | 7.4 | — | — | — | — | Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenera | 85d ago |
| CVE-2026-46513 | 7.4 | — | — | — | — | Frogman provides headless PBX control through MCP and HTTP API. | 86d ago |
| CVE-2026-48287 | 7.4 | — | — | — | adobe / c2pa | CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code | 87d ago |
| CVE-2026-47473 | 7.4 | — | — | — | — | NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. | 87d ago |
| CVE-2026-4017 | 7.4 | — | — | — | — | Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to c | 88d ago |
| CVE-2026-54127 | 7.4 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-54429 | 7.4 | — | — | — | — | A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). | 88d ago |
| CVE-2026-62240 | 7.4 | — | — | — | crewai / crewai | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that perfor | 88d ago |
| CVE-2026-49969 | 7.4 | — | — | — | — | Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to | 89d ago |
| CVE-2026-10665 | 7.4 | — | — | — | zephyrproject / zephyr | In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an | 90d ago |