| CVE-2026-47668 | 10 | critical | — | DbGate is cross-platform database manager. | 44d ago |
| CVE-2026-64813 | 10 | critical | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development s | 44d ago |
| CVE-2026-64812 | 10 | critical | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | 44d ago |
| CVE-2026-59555 | 10 | critical | — | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | 44d ago |
| CVE-2026-60366 | 10 | critical | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-60644 | 10 | critical | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Manageme | 46d ago |
| CVE-2026-60389 | 10 | critical | oracle / service delivery platform | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | 46d ago |
| CVE-2026-60379 | 10 | critical | oracle / service delivery platform | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | 46d ago |
| CVE-2026-60365 | 10 | critical | oracle / http server | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic | 46d ago |
| CVE-2026-60360 | 10 | critical | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 46d ago |
| CVE-2026-60358 | 10 | critical | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 46d ago |
| CVE-2026-60217 | 10 | critical | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-47056 | 10 | critical | oracle / data integrator | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). | 46d ago |
| CVE-2026-16367 | 10 | critical | mozilla / firefox | Sandbox escape due to invalid pointer in the Disability Access APIs component. | 46d ago |
| CVE-2026-46412 | 10 | critical | — | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect s | 47d ago |
| CVE-2026-44359 | 10 | critical | — | Meshtastic is an open source mesh networking solution. | 48d ago |
| CVE-2026-63795 | 10 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() e | 48d ago |
| CVE-2026-16117 | 10 | critical | fastify / fastify\/http-proxy | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix | 49d ago |
| CVE-2026-54159 | 10 | critical | — | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. | 50d ago |
| CVE-2026-44182 | 10 | critical | jupyter / enterprise gateway | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, | 51d ago |
| CVE-2026-44181 | 10 | critical | jupyter / enterprise gateway | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, | 51d ago |
| CVE-2026-45336 | 10 | critical | — | HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking h | 51d ago |
| CVE-2026-52887 | 10 | critical | — | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. | 52d ago |
| CVE-2026-46339 | 10 | critical | — | 9Router is an AI router & token saver. | 52d ago |
| CVE-2026-50148 | 10 | critical | metabase / metabase | Metabase is an open-source business intelligence and embedded analytics tool. | 52d ago |
| CVE-2026-15409exploited | 10 | critical | sonicwall / sma6210 firmware | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interfa | 53d ago |
| CVE-2026-62422 | 10 | critical | jetbrains / youtrack | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.1484 | 53d ago |
| CVE-2026-56451 | 10 | critical | — | A vulnerability has been identified in Opcenter X (All versions < V2604). | 53d ago |
| CVE-2026-57811 | 10 | critical | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin re | 54d ago |
| CVE-2026-57719 | 10 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Usi | 54d ago |
| CVE-2026-61447 | 10 | critical | — | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that execute | 56d ago |
| CVE-2026-54769 | 10 | critical | — | Langroid is a framework for building large-language-model-powered applications. | 58d ago |
| CVE-2026-59726 | 10 | critical | — | Ruflo is an agent meta-harness for Claude Code and Codex. | 58d ago |
| CVE-2026-54782 | 10 | critical | — | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. | 59d ago |
| CVE-2026-57572 | 10 | critical | kidocode / crawl4ai | Crawl4AI is an open-source LLM-friendly web crawler and scraper. | 61d ago |
| CVE-2026-54763 | 10 | critical | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 61d ago |
| CVE-2026-48316 | 10 | critical | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 61d ago |
| CVE-2026-13768 | 10 | critical | — | Gardyn devices expose a privileged iothubowner key. | 65d ago |
| CVE-2026-56004 | 10 | critical | — | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be us | 65d ago |
| CVE-2026-50746 | 10 | critical | ui / unifi connect application | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi | 65d ago |
| CVE-2026-57624 | 10 | critical | — | Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. | 65d ago |
| CVE-2026-50160 | 10 | critical | hoppscotch / hoppscotch | Hoppscotch is an API development ecosystem. | 66d ago |
| CVE-2026-56415 | 10 | critical | — | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is rea | 67d ago |
| CVE-2026-56413 | 10 | critical | — | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which li | 67d ago |
| CVE-2026-13782 | 10 | critical | google / chrome | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised th | 67d ago |
| CVE-2026-10134 | 10 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, re | 67d ago |
| CVE-2026-48286 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vuln | 67d ago |
| CVE-2026-48283 | 10 | critical | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type | 67d ago |
| CVE-2026-48282exploited | 10 | critical | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 67d ago |
| CVE-2026-48281 | 10 | critical | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 67d ago |
| CVE-2026-48277 | 10 | critical | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 67d ago |
| CVE-2026-48276 | 10 | critical | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type | 67d ago |
| CVE-2026-53576 | 10 | critical | kestra / kestra | Kestra is an open-source, event-driven orchestration platform. | 71d ago |
| CVE-2026-49869exploited | 10 | critical | kestra / kestra | Kestra is an open-source, event-driven orchestration platform. | 71d ago |
| CVE-2026-54350 | 10 | critical | budibase / budibase | Budibase is an open-source low-code platform. | 71d ago |
| CVE-2025-71338 | 10 | critical | flowiseai / flowise | Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows | 72d ago |
| CVE-2026-57700 | 10 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. | 72d ago |
| CVE-2026-54917 | 10 | critical | seaweedfs / seaweedfs | SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. | 72d ago |
| CVE-2026-52813 | 10 | critical | — | Gogs is an open source self-hosted Git service. | 73d ago |
| CVE-2026-12848 | 10 | critical | — | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and | 73d ago |