| CVE-2026-64091 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported v | 49d ago |
| CVE-2026-64089 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_le | 49d ago |
| CVE-2026-64069 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of a DIO and single re | 49d ago |
| CVE-2026-64068 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding | 49d ago |
| CVE-2026-64067 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing str | 49d ago |
| CVE-2026-64066 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause | 49d ago |
| CVE-2026-64061 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_re | 49d ago |
| CVE-2026-64056 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port T | 49d ago |
| CVE-2026-64055 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counte | 49d ago |
| CVE-2026-64047 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry cou | 49d ago |
| CVE-2026-64046 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain t | 49d ago |
| CVE-2026-64037 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: fix TSO segmentation explo | 49d ago |
| CVE-2026-64035 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: igc: set tx buffer type for SMD frames Sashiko | 49d ago |
| CVE-2026-64033 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file cre | 49d ago |
| CVE-2026-64025 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdict sk_data_ready racing w | 49d ago |
| CVE-2026-64016 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix durable reconnect error path file l | 49d ago |
| CVE-2026-64007 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ | 49d ago |
| CVE-2026-64000 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervis | 49d ago |
| CVE-2026-63994 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() | 49d ago |
| CVE-2026-63993 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value afte | 49d ago |
| CVE-2026-63984 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh | 49d ago |
| CVE-2026-63979 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file refere | 49d ago |
| CVE-2026-63978 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net n | 49d ago |
| CVE-2026-63924 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_h | 49d ago |
| CVE-2026-63922 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO o | 49d ago |
| CVE-2026-63912 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length | 49d ago |
| CVE-2026-63888 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and doub | 49d ago |
| CVE-2026-63887 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_o | 49d ago |
| CVE-2026-63886 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length be | 49d ago |
| CVE-2026-63857 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragmen | 49d ago |
| CVE-2026-63825 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concur | 49d ago |
| CVE-2026-63808 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_f | 49d ago |
| CVE-2026-63800 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout | 49d ago |
| CVE-2026-53399 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure | 49d ago |
| CVE-2026-53398 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup | 49d ago |
| CVE-2026-53384 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_n | 49d ago |
| CVE-2026-47865 | 9.8 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains an authentication bypass vulnerability. | 50d ago |
| CVE-2026-52348 | 9.8 | — | — | — | — | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | 50d ago |
| CVE-2026-48062 | 9.8 | — | — | — | — | CodeIgniter is a PHP full-stack web framework. | 50d ago |
| CVE-2026-13446 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, wh | 50d ago |
| CVE-2026-8505 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthe | 50d ago |
| CVE-2026-63030zero day | 9.8 | 97.3% | 3/3 | same day | wordpress / wordpress | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue | 50d ago |
| CVE-2026-36669 | 9.8 | — | — | — | — | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows r | 50d ago |
| CVE-2026-9103 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper aut | 50d ago |
| CVE-2026-9202 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Lan | 50d ago |
| CVE-2026-9198exploited | 9.8 | 57.0% | 3/3 | +18d | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER | 50d ago |
| CVE-2026-9586exploited | 9.8 | 11.8% | 3/3 | +46d | sangoma / switchvox | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). | 51d ago |
| CVE-2026-8297 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informati | 51d ago |
| CVE-2026-12692 | 9.8 | — | — | — | — | Unverified password change vulnerability in Vimesoft Inc. | 51d ago |
| CVE-2026-60024 | 9.8 | — | — | — | — | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension | 51d ago |
| CVE-2026-51080 | 9.8 | — | — | — | proxmox / libpve-storage-perl | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) v | 51d ago |
| CVE-2026-9810 | 9.8 | — | — | — | — | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any | 51d ago |
| CVE-2026-15982 | 9.8 | — | — | — | — | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulne | 51d ago |
| CVE-2026-14956 | 9.8 | — | — | — | — | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3 | 51d ago |
| CVE-2026-53412 | 9.8 | — | — | — | zoom / workplace desktop | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK fo | 51d ago |
| CVE-2026-44180 | 9.8 | — | — | — | jupyter / enterprise gateway | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, | 51d ago |
| CVE-2026-38158 | 9.8 | — | — | — | — | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers | 51d ago |
| CVE-2026-63087 | 9.8 | — | — | — | — | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to ob | 52d ago |
| CVE-2026-46562 | 9.8 | — | — | — | spaceapplications / yamcs | Yamcs is a mission control framework. | 52d ago |
| CVE-2026-3031 | 9.8 | — | — | — | — | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. | 52d ago |