| CVE-2026-62536 | 7.1 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 51d ago |
| CVE-2026-62522 | 7.1 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Secur | 51d ago |
| CVE-2026-62458 | 7.1 | — | — | — | oracle / work in process | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-61306 | 7.1 | — | — | — | oracle / complex maintenance repair and overhaul | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component | 51d ago |
| CVE-2026-61295 | 7.1 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 51d ago |
| CVE-2026-61290 | 7.1 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 51d ago |
| CVE-2026-61288 | 7.1 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 51d ago |
| CVE-2026-61259 | 7.1 | — | — | — | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-61124 | 7.1 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 51d ago |
| CVE-2026-60949 | 7.1 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 51d ago |
| CVE-2026-60781 | 7.1 | — | — | — | oracle / payments | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). | 51d ago |
| CVE-2026-60752 | 7.1 | — | — | — | oracle / siebel apps - marketing | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). | 51d ago |
| CVE-2026-60693 | 7.1 | — | — | — | oracle / general ledger | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-24185 | 7.1 | — | — | — | — | NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component | 51d ago |
| CVE-2026-74038 | 7.1 | — | — | — | — | Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to | 51d ago |
| CVE-2026-73396 | 7.1 | — | — | — | — | Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | 52d ago |
| CVE-2026-73393 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. | 52d ago |
| CVE-2026-73382exploited | 7.1 | 0.25% | 1/3 | +45d | — | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | 52d ago |
| CVE-2026-73378 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | 52d ago |
| CVE-2026-73375 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | 52d ago |
| CVE-2026-73362 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. | 52d ago |
| CVE-2026-73361 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | 52d ago |
| CVE-2026-73360 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | 52d ago |
| CVE-2026-73358 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | 52d ago |
| CVE-2026-73351 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | 52d ago |
| CVE-2026-73345 | 7.1 | — | — | — | — | Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | 52d ago |
| CVE-2026-73342 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. | 52d ago |
| CVE-2026-73338 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | 52d ago |
| CVE-2026-73190 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | 52d ago |
| CVE-2026-68567 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | 52d ago |
| CVE-2026-66667 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | 52d ago |
| CVE-2026-66633 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | 52d ago |
| CVE-2026-66629zero day | 7.1 | 0.25% | 1/3 | same day | — | Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | 52d ago |
| CVE-2026-66621 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG | 52d ago |
| CVE-2026-48798 | 7.1 | — | — | — | — | SSH.NET is a Secure Shell (SSH) library for .NET. | 52d ago |
| CVE-2026-32547 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | 52d ago |
| CVE-2026-32333 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | 52d ago |
| CVE-2026-28569 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | 52d ago |
| CVE-2026-28568 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | 52d ago |
| CVE-2026-75846 | 7.1 | — | — | — | — | ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE | 52d ago |
| CVE-2026-75844 | 7.1 | — | — | — | — | ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command | 52d ago |
| CVE-2026-75830 | 7.1 | — | — | — | — | grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnera | 52d ago |
| CVE-2026-74905 | 7.1 | — | — | — | — | SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in ke | 52d ago |
| CVE-2026-69148 | 7.1 | — | — | — | — | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. | 52d ago |
| CVE-2026-75109 | 7.1 | — | — | — | — | Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. | 52d ago |
| CVE-2026-54356 | 7.1 | — | — | — | — | Budibase is an open-source low-code platform. | 52d ago |
| CVE-2026-19589 | 7.1 | — | — | — | — | Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file s | 52d ago |
| CVE-2026-19650 | 7.1 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0. | 52d ago |
| CVE-2026-75050 | 7.1 | — | — | — | — | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | 53d ago |
| CVE-2026-59909 | 7.1 | — | — | — | dell / objectscale | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. | 53d ago |
| CVE-2026-75002 | 7.1 | — | — | — | — | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization c | 53d ago |
| CVE-2026-74579 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for par | 53d ago |
| CVE-2026-74578 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous pro | 54d ago |
| CVE-2026-74567 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_ke | 55d ago |
| CVE-2026-74564 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validate hashtable su | 55d ago |
| CVE-2026-74507 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payl | 55d ago |
| CVE-2026-74485 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: reject a flag character as the fi | 55d ago |
| CVE-2026-74364 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject exclusive maps as inner maps in ma | 55d ago |
| CVE-2026-74349 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a clu | 55d ago |
| CVE-2026-74295 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: hdac_hdmi: Validate written enum | 55d ago |