| CVE-2026-73891 | 7.3 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 52d ago |
| CVE-2026-71138 | 7.3 | — | — | — | oracle / vm virtualbox | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). | 52d ago |
| CVE-2026-71136 | 7.3 | — | — | — | oracle / vm virtualbox | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). | 52d ago |
| CVE-2026-71094 | 7.3 | — | — | — | oracle / business intelligence | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Prese | 52d ago |
| CVE-2026-70800 | 7.3 | — | — | — | oracle / service delivery platform number portability | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operati | 52d ago |
| CVE-2026-62551 | 7.3 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 52d ago |
| CVE-2026-61339 | 7.3 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 52d ago |
| CVE-2026-15571 | 7.3 | — | — | — | — | A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source id | 52d ago |
| CVE-2026-71417 | 7.3 | — | — | — | — | Lemur manages TLS certificate creation. | 52d ago |
| CVE-2026-59915 | 7.3 | — | — | — | — | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerabili | 52d ago |
| CVE-2026-32657 | 7.3 | — | — | — | — | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0. | 52d ago |
| CVE-2026-75778 | 7.3 | — | — | — | — | A vulnerability was identified in code-projects Task Management System 1.0. | 53d ago |
| CVE-2026-75089 | 7.3 | — | — | — | — | A weakness has been identified in PHPGurukul Complaint Management System 1.0. | 53d ago |
| CVE-2026-75080 | 7.3 | — | — | — | — | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. | 53d ago |
| CVE-2026-75079 | 7.3 | — | — | — | — | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. | 53d ago |
| CVE-2026-75014 | 7.3 | — | — | — | — | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. | 53d ago |
| CVE-2026-56685 | 7.3 | — | — | — | dell / objectscale | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an | 53d ago |
| CVE-2026-56090 | 7.3 | — | — | — | dell / objectscale | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. | 53d ago |
| CVE-2026-19926 | 7.3 | — | — | — | — | A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. | 55d ago |
| CVE-2026-19919 | 7.3 | — | — | — | — | A vulnerability was found in code-projects Online Shopping System 1.0. | 55d ago |
| CVE-2026-19905 | 7.3 | — | — | — | — | A weakness has been identified in Jinher OA 1.0. | 55d ago |
| CVE-2026-19899 | 7.3 | — | — | — | — | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. | 55d ago |
| CVE-2026-74419 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Adjust size for copy_to_user() | 56d ago |
| CVE-2026-74365 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Handle preemption in BTT lane acqu | 56d ago |
| CVE-2026-74294 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: aiu: Validate written enum values | 56d ago |
| CVE-2026-72416 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_compat: ebtables emulation must | 56d ago |
| CVE-2026-72347 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_connmark: reject invalid shift p | 56d ago |
| CVE-2026-72122 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix lockless bound/ifindex race and | 56d ago |
| CVE-2026-72103 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dm: avoid leaking the caller's thread keyring | 56d ago |
| CVE-2026-72019 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: macsec: don't read an unset MAC header in macs | 56d ago |
| CVE-2026-19826 | 7.3 | — | — | — | — | A vulnerability was detected in alldatacenter alldata up to 0.6.8. | 57d ago |
| CVE-2026-19825 | 7.3 | — | — | — | — | A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. | 57d ago |
| CVE-2026-19764 | 7.3 | — | — | — | — | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. | 57d ago |
| CVE-2026-19762 | 7.3 | — | — | — | — | A vulnerability was found in DTStack Taier 1.4.0. | 57d ago |
| CVE-2026-19758 | 7.3 | — | — | — | — | A vulnerability was determined in dromara lamp-cloud up to 5.10.0. | 57d ago |
| CVE-2026-19757 | 7.3 | — | — | — | — | A vulnerability was found in Dromara lamp-cloud up to 5.10.0. | 57d ago |
| CVE-2026-19753 | 7.3 | — | — | — | — | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. | 57d ago |
| CVE-2026-18511 | 7.3 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow | 57d ago |
| CVE-2026-17099 | 7.3 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authent | 57d ago |
| CVE-2026-73669 | 7.3 | — | — | — | — | The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network int | 57d ago |
| CVE-2026-72677 | 7.3 | — | — | — | elastic / kibana | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative | 57d ago |
| CVE-2026-72658 | 7.3 | — | — | — | elastic / kibana | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CA | 57d ago |
| CVE-2026-14875 | 7.3 | — | — | — | ibm / i access client solutions | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when i | 57d ago |
| CVE-2026-19710 | 7.3 | — | — | — | — | A vulnerability was found in SourceCodester Simple Student Information System. | 57d ago |
| CVE-2026-63424 | 7.3 | — | — | — | — | During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that cou | 57d ago |
| CVE-2026-28188 | 7.3 | — | — | — | — | Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. | 58d ago |
| CVE-2026-13476 | 7.3 | — | — | — | ibm / informix dynamic server | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary comman | 58d ago |
| CVE-2026-67260 | 7.3 | — | — | — | apache / airflow | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept b | 58d ago |
| CVE-2026-71383 | 7.3 | — | — | — | adobe / coldfusion | is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. | 59d ago |
| CVE-2026-70355 | 7.3 | — | — | — | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 59d ago |
| CVE-2026-68821 | 7.3 | — | — | — | microsoft / app installer | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges local | 59d ago |
| CVE-2026-64900 | 7.3 | — | — | — | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 59d ago |
| CVE-2026-62914 | 7.3 | — | — | — | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 59d ago |
| CVE-2026-59119 | 7.3 | — | — | — | microsoft / powershell | Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 59d ago |
| CVE-2026-20890 | 7.3 | — | — | — | intel / proset\/wireless wifi | Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privilege | 59d ago |
| CVE-2026-18639 | 7.3 | — | — | — | — | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. | 59d ago |
| CVE-2026-44765 | 7.3 | — | — | — | — | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthent | 60d ago |
| CVE-2026-44764 | 7.3 | — | — | — | — | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthent | 60d ago |
| CVE-2026-59091 | 7.3 | — | — | — | gimp / gimp | A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. | 60d ago |
| CVE-2026-6374 | 7.3 | — | — | — | — | Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Exe | 61d ago |