| CVE-2026-64391 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alte | 43d ago |
| CVE-2026-64387 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double | 43d ago |
| CVE-2026-64386 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-fr | 43d ago |
| CVE-2026-64385 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() r | 43d ago |
| CVE-2026-64384 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-f | 43d ago |
| CVE-2026-64383 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() r | 43d ago |
| CVE-2026-64355 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap | 43d ago |
| CVE-2026-64303 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX | 43d ago |
| CVE-2026-64268 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the | 43d ago |
| CVE-2026-16766 | 9.8 | — | — | — | — | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render opti | 43d ago |
| CVE-2026-16280 | 9.8 | — | — | — | imaginationtech / ddk | An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address c | 43d ago |
| CVE-2026-61884 | 9.8 | — | — | — | — | The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set t | 43d ago |
| CVE-2026-64232 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_ | 43d ago |
| CVE-2026-64216 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_aband | 43d ago |
| CVE-2026-58586 | 9.8 | — | — | — | — | Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. | 44d ago |
| CVE-2026-16634 | 9.8 | — | — | — | — | TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. | 44d ago |
| CVE-2026-15704 | 9.8 | — | — | — | — | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an a | 44d ago |
| CVE-2026-56165 | 9.8 | — | — | — | microsoft / account | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | 44d ago |
| CVE-2026-52439 | 9.8 | — | — | — | — | An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and | 44d ago |
| CVE-2026-15981exploited | 9.8 | 0.81% | 1/3 | +29d | — | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up | 44d ago |
| CVE-2026-63359 | 9.8 | — | — | — | equifax / victim information notification exchange | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticat | 44d ago |
| CVE-2026-65700 | 9.8 | — | — | — | — | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauth | 44d ago |
| CVE-2026-65689 | 9.8 | — | — | — | syncfusion / standalone report designer | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its | 45d ago |
| CVE-2026-65688 | 9.8 | — | — | — | syncfusion / standalone report designer | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its | 45d ago |
| CVE-2026-65687 | 9.8 | — | — | — | syncfusion / standalone report designer | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its | 45d ago |
| CVE-2026-61951 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | 45d ago |
| CVE-2026-59544 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | 45d ago |
| CVE-2026-59540 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | 45d ago |
| CVE-2026-65431 | 9.8 | — | — | — | — | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadl | 45d ago |
| CVE-2026-64874 | 9.8 | — | — | — | — | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exp | 45d ago |
| CVE-2026-64873 | 9.8 | — | — | — | — | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal | 45d ago |
| CVE-2026-15015 | 9.8 | — | — | — | — | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all vers | 45d ago |
| CVE-2026-15011 | 9.8 | — | — | — | — | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' | 45d ago |
| CVE-2026-14282 | 9.8 | — | — | — | — | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugi | 45d ago |
| CVE-2026-60372 | 9.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-60367 | 9.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-64796 | 9.8 | — | — | — | — | Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require | 45d ago |
| CVE-2025-50329 | 9.8 | — | — | — | — | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges an | 45d ago |
| CVE-2026-16606 | 9.8 | — | — | — | — | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 | 45d ago |
| CVE-2026-2395 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye | 46d ago |
| CVE-2026-16232zero day | 9.8 | 72.1% | 3/3 | 3d before | checkpoint / multi-domain security management | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated rem | 46d ago |
| CVE-2026-65590 | 9.8 | — | — | — | n8n / n8n | n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the | 46d ago |
| CVE-2026-56817 | 9.8 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 46d ago |
| CVE-2026-8986 | 9.8 | — | — | — | autel / maxicharger single charger firmware | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetD | 46d ago |
| CVE-2026-8985 | 9.8 | — | — | — | autel / maxicharger single charger firmware | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exp | 46d ago |
| CVE-2026-8984 | 9.8 | — | — | — | autel / maxicharger single charger firmware | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service li | 46d ago |
| CVE-2026-61245 | 9.8 | — | — | — | oracle / peoplesoft enterprise fin manufacturing brazil | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integ | 46d ago |
| CVE-2026-61233 | 9.8 | — | — | — | oracle / peoplesoft enterprise fin common objects | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Inte | 46d ago |
| CVE-2026-61196 | 9.8 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 46d ago |
| CVE-2026-61183 | 9.8 | — | — | — | oracle / agile product lifecycle management for process | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (compone | 46d ago |
| CVE-2026-61178 | 9.8 | — | — | — | oracle / agile product lifecycle management for process | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (compone | 46d ago |
| CVE-2026-61167 | 9.8 | — | — | — | oracle / agile product lifecycle management | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). | 46d ago |
| CVE-2026-61161 | 9.8 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 46d ago |
| CVE-2026-61154 | 9.8 | — | — | — | oracle / commerce guided search platform services | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge) | 46d ago |
| CVE-2026-61145 | 9.8 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 46d ago |
| CVE-2026-61140 | 9.8 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 46d ago |
| CVE-2026-61131 | 9.8 | — | — | — | oracle / commerce platform | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework) | 46d ago |
| CVE-2026-61129 | 9.8 | — | — | — | oracle / commerce platform | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). | 46d ago |
| CVE-2026-61100 | 9.8 | — | — | — | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-61065 | 9.8 | — | — | — | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 46d ago |