| CVE-2026-15081 | 7.4 | — | — | — | handkerchief / location selector | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Locat | 92d ago |
| CVE-2026-53450 | 7.4 | — | — | — | coturn project / coturn | Coturn is a free open source implementation of TURN and STUN Server. | 92d ago |
| CVE-2026-55672 | 7.4 | — | — | — | — | ZITADEL is an open source identity management platform. | 92d ago |
| CVE-2026-54919 | 7.4 | — | — | — | yhirose / cpp-httplib | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. | 92d ago |
| CVE-2026-56676 | 7.4 | — | — | — | — | 9Router is an AI router & token saver. | 92d ago |
| CVE-2026-54784 | 7.4 | — | — | — | — | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. | 94d ago |
| CVE-2026-54783 | 7.4 | — | — | — | — | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. | 94d ago |
| CVE-2026-54781 | 7.4 | — | — | — | — | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. | 94d ago |
| CVE-2026-54774 | 7.4 | — | — | — | — | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. | 94d ago |
| CVE-2026-59806 | 7.4 | — | — | — | — | Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers | 94d ago |
| CVE-2026-56776 | 7.4 | — | — | — | n8n / n8n | n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test- | 94d ago |
| CVE-2026-55436 | 7.4 | — | — | — | coder / coder | Coder allows organizations to provision remote development environments via Terraform. | 94d ago |
| CVE-2026-55076 | 7.4 | — | — | — | coder / coder | Coder allows organizations to provision remote development environments via Terraform. | 95d ago |
| CVE-2026-55075 | 7.4 | — | — | — | coder / coder | Coder allows organizations to provision remote development environments via Terraform. | 95d ago |
| CVE-2026-6900 | 7.4 | — | — | — | — | Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. | 96d ago |
| CVE-2026-57993 | 7.4 | — | — | — | microsoft / edge chromium | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform s | 99d ago |
| CVE-2026-57991 | 7.4 | — | — | — | microsoft / edge chromium | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauth | 99d ago |
| CVE-2026-13341 | 7.4 | — | — | — | — | A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could | 99d ago |
| CVE-2026-9547 | 7.4 | — | — | — | haxx / curl | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNC | 99d ago |
| CVE-2026-57736 | 7.4 | — | — | — | — | Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data | 101d ago |
| CVE-2026-57723 | 7.4 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Trav | 101d ago |
| CVE-2026-12579 | 7.4 | — | — | — | — | AS228T with Authentication Bypass Vulnerability | 101d ago |
| CVE-2026-7830 | 7.4 | — | — | — | uvnc / ultravnc | UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogon | 101d ago |
| CVE-2026-11541 | 7.4 | — | — | — | ibm / websphere application server | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and | 102d ago |
| CVE-2026-44946 | 7.4 | — | — | — | suse / rancher | A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce o | 102d ago |
| CVE-2026-10646 | 7.4 | — | — | — | zephyrproject / zephyr | Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a sta | 104d ago |
| CVE-2026-50136 | 7.4 | — | — | — | budibase / budibase | Budibase is an open-source low-code platform. | 106d ago |
| CVE-2026-54833 | 7.4 | — | — | — | — | Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions. | 106d ago |
| CVE-2026-12992 | 7.4 | — | — | — | redhat / build of apicurio registry | A flaw was found in Apicurio Registry. | 107d ago |
| CVE-2026-46608 | 7.4 | — | — | — | — | Glances is an open-source system cross-platform monitoring tool. | 107d ago |
| CVE-2026-54821 | 7.4 | — | — | — | — | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. | 107d ago |
| CVE-2026-57589 | 7.4 | — | — | — | openbsd / openbsd | sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. | 107d ago |
| CVE-2026-55759 | 7.4 | — | — | — | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. | 108d ago |
| CVE-2026-49440 | 7.4 | — | — | — | deno / deno | Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 109d ago |
| CVE-2026-44726 | 7.4 | — | — | — | deno / deno | Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 109d ago |
| CVE-2026-56815 | 7.4 | — | — | — | — | pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handl | 109d ago |
| CVE-2026-48505 | 7.4 | — | — | — | — | Filament is a collection of full-stack components for accelerated Laravel development. | 110d ago |
| CVE-2026-9006 | 7.4 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Pro | 110d ago |
| CVE-2026-8646 | 7.4 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0 | 110d ago |
| CVE-2026-49287 | 7.4 | — | — | — | — | Statamic is a Laravel and Git powered content management system (CMS). | 113d ago |
| CVE-2026-3195 | 7.4 | — | — | — | — | A flaw was found in QEMU. | 113d ago |
| CVE-2026-9697 | 7.4 | — | — | — | nodejs / undici | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// | 115d ago |
| CVE-2026-49502 | 7.4 | — | — | — | dell / powerflex manager | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. | 115d ago |
| CVE-2026-52698 | 7.4 | — | — | — | — | Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget | 115d ago |
| CVE-2026-48294exploited | 7.4 | 1.2% | 1/3 | +54d | adobe / acrobat | Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data | 115d ago |
| CVE-2026-12348 | 7.4 | — | — | — | — | Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address | 115d ago |
| CVE-2026-10303 | 7.4 | — | — | — | — | In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly valida | 116d ago |
| CVE-2024-39575 | 7.4 | — | — | — | — | update_disk_psu_baseline.sh requires password in plain text | 116d ago |
| CVE-2026-49082 | 7.4 | — | — | — | — | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk C | 117d ago |
| CVE-2026-45389 | 7.4 | — | — | — | — | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the c | 117d ago |
| CVE-2026-12068 | 7.4 | — | — | — | — | Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote a | 120d ago |
| CVE-2026-50631 | 7.4 | — | — | — | apache / cxf | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass si | 120d ago |
| CVE-2026-53782 | 7.4 | — | — | — | — | Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a p | 121d ago |
| CVE-2026-47960 | 7.4 | — | — | — | adobe / coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Ref | 123d ago |
| CVE-2026-34181 | 7.4 | — | — | — | openssl / openssl | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Passwor | 123d ago |
| CVE-2026-46320 | 7.4 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_ | 123d ago |
| CVE-2026-41720 | 7.4 | — | — | — | — | Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty user | 123d ago |
| CVE-2026-40215 | 7.4 | — | — | — | openvpn / openvpn | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potential | 124d ago |
| CVE-2026-50752exploited | 7.4 | 0.26% | 1/3 | +100d | — | A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated a | 124d ago |
| CVE-2026-45300 | 7.4 | — | — | — | asynchttpclient project / async-http-client | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously proc | 127d ago |