| CVE-2026-64091 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported v | 81d ago |
| CVE-2026-64089 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_le | 81d ago |
| CVE-2026-64069 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of a DIO and single re | 81d ago |
| CVE-2026-64068 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding | 81d ago |
| CVE-2026-64067 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing str | 81d ago |
| CVE-2026-64066 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause | 81d ago |
| CVE-2026-64061 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_re | 81d ago |
| CVE-2026-64056 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port T | 81d ago |
| CVE-2026-64055 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counte | 81d ago |
| CVE-2026-64047 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry cou | 81d ago |
| CVE-2026-64046 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain t | 81d ago |
| CVE-2026-64037 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: fix TSO segmentation explo | 81d ago |
| CVE-2026-64035 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: igc: set tx buffer type for SMD frames Sashiko | 81d ago |
| CVE-2026-64033 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file cre | 81d ago |
| CVE-2026-64025 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdict sk_data_ready racing w | 81d ago |
| CVE-2026-64016 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix durable reconnect error path file l | 81d ago |
| CVE-2026-64007 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ | 81d ago |
| CVE-2026-64000 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervis | 81d ago |
| CVE-2026-63994 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() | 81d ago |
| CVE-2026-63993 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value afte | 81d ago |
| CVE-2026-63984 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh | 81d ago |
| CVE-2026-63979 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file refere | 81d ago |
| CVE-2026-63978 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net n | 81d ago |
| CVE-2026-63924 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_h | 81d ago |
| CVE-2026-63922 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO o | 81d ago |
| CVE-2026-63912 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length | 81d ago |
| CVE-2026-63888 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and doub | 81d ago |
| CVE-2026-63887 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_o | 81d ago |
| CVE-2026-63886 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length be | 81d ago |
| CVE-2026-63857 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragmen | 81d ago |
| CVE-2026-63825 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concur | 81d ago |
| CVE-2026-63808 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_f | 81d ago |
| CVE-2026-63800 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout | 81d ago |
| CVE-2026-53399 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure | 81d ago |
| CVE-2026-53398 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup | 81d ago |
| CVE-2026-53384 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_n | 81d ago |
| CVE-2026-47865 | 9.8 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains an authentication bypass vulnerability. | 83d ago |
| CVE-2026-52348 | 9.8 | — | — | — | — | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | 83d ago |
| CVE-2026-48062 | 9.8 | — | — | — | — | CodeIgniter is a PHP full-stack web framework. | 83d ago |
| CVE-2026-13446 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, wh | 83d ago |
| CVE-2026-8505 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthe | 83d ago |
| CVE-2026-63030zero day | 9.8 | 10.6% | 3/3 | same day | wordpress / wordpress | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue | 83d ago |
| CVE-2026-36669 | 9.8 | — | — | — | — | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows r | 83d ago |
| CVE-2026-9103 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper aut | 83d ago |
| CVE-2026-9202 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Lan | 83d ago |
| CVE-2026-9198exploited | 9.8 | 28.7% | 3/3 | +18d | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER | 83d ago |
| CVE-2026-9586exploited | 9.8 | 19.0% | 3/3 | +46d | sangoma / switchvox | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). | 83d ago |
| CVE-2026-8297 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informati | 83d ago |
| CVE-2026-12692 | 9.8 | — | — | — | — | Unverified password change vulnerability in Vimesoft Inc. | 83d ago |
| CVE-2026-60024 | 9.8 | — | — | — | — | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension | 83d ago |
| CVE-2026-51080 | 9.8 | — | — | — | proxmox / libpve-storage-perl | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) v | 83d ago |
| CVE-2026-9810 | 9.8 | — | — | — | — | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any | 84d ago |
| CVE-2026-15982 | 9.8 | — | — | — | — | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulne | 84d ago |
| CVE-2026-14956 | 9.8 | — | — | — | — | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3 | 84d ago |
| CVE-2026-53412 | 9.8 | — | — | — | zoom / workplace desktop | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK fo | 84d ago |
| CVE-2026-44180 | 9.8 | — | — | — | jupyter / enterprise gateway | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, | 84d ago |
| CVE-2026-38158 | 9.8 | — | — | — | — | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers | 84d ago |
| CVE-2026-63087 | 9.8 | — | — | — | — | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to ob | 84d ago |
| CVE-2026-46562 | 9.8 | — | — | — | spaceapplications / yamcs | Yamcs is a mission control framework. | 84d ago |
| CVE-2026-3031 | 9.8 | — | — | — | — | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. | 84d ago |