| CVE-2026-45695 | 9.8 | — | — | — | — | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end | 52d ago |
| CVE-2023-49900 | 9.8 | — | — | — | — | An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user inpu | 52d ago |
| CVE-2023-49899 | 9.8 | — | — | — | — | An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying t | 52d ago |
| CVE-2026-12492 | 9.8 | — | — | — | — | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password wa | 52d ago |
| CVE-2026-15013 | 9.8 | — | — | — | — | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature | 52d ago |
| CVE-2026-55652 | 9.8 | — | — | — | — | Wekan is open source kanban built with Meteor. | 52d ago |
| CVE-2026-30623 | 9.8 | — | — | — | — | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. | 52d ago |
| CVE-2026-30618 | 9.8 | — | — | — | — | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command exe | 52d ago |
| CVE-2025-65720 | 9.8 | — | — | — | — | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system vi | 52d ago |
| CVE-2026-51380 | 9.8 | — | — | — | — | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denia | 52d ago |
| CVE-2026-49352 | 9.8 | — | — | — | — | 9Router is an AI router & token saver. | 52d ago |
| CVE-2026-14960 | 9.8 | — | — | — | — | Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device | 52d ago |
| CVE-2026-5270 | 9.8 | — | — | — | — | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), M | 53d ago |
| CVE-2026-5269 | 9.8 | — | — | — | — | In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts us | 53d ago |
| CVE-2026-51808 | 9.8 | — | — | — | — | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via th | 53d ago |
| CVE-2026-51807 | 9.8 | — | — | — | — | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and ear | 53d ago |
| CVE-2026-46634 | 9.8 | — | — | — | symfony / twig | Twig is a template language for PHP. | 53d ago |
| CVE-2026-46633 | 9.8 | — | — | — | symfony / twig | Twig is a template language for PHP. | 53d ago |
| CVE-2026-38450 | 9.8 | — | — | — | — | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via th | 53d ago |
| CVE-2026-53633 | 9.8 | — | — | — | — | Vitest is a testing framework powered by Vite. | 53d ago |
| CVE-2026-47429 | 9.8 | — | — | — | vitest.dev / vitest | Vitest is a testing framework powered by Vite. | 53d ago |
| CVE-2026-13001 | 9.8 | — | — | — | — | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ | 53d ago |
| CVE-2026-47767 | 9.8 | — | — | — | sensiolabs / symfony | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 53d ago |
| CVE-2026-56190 | 9.8 | — | — | — | microsoft / windows 10 1607 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-56188 | 9.8 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Netw | 53d ago |
| CVE-2026-56159 | 9.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-55944 | 9.8 | — | — | — | microsoft / dynamics nav | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a | 53d ago |
| CVE-2026-55010 | 9.8 | — | — | — | microsoft / minecraft bedrock dedicated server | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-50518 | 9.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-50447 | 9.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a netwo | 53d ago |
| CVE-2026-58644zero day | 9.8 | 15.9% | 3/3 | same day | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o | 54d ago |
| CVE-2026-54990 | 9.8 | — | — | — | microsoft / windows 11 24h2 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 54d ago |
| CVE-2026-54118 | 9.8 | — | — | — | microsoft / sql server 2016 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 54d ago |
| CVE-2026-54117 | 9.8 | — | — | — | microsoft / sql server 2016 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 54d ago |
| CVE-2026-50522exploited | 9.8 | 84.6% | 3/3 | +6d | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o | 54d ago |
| CVE-2026-49172 | 9.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | 54d ago |
| CVE-2026-42990 | 9.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a networ | 54d ago |
| CVE-2026-15701 | 9.8 | — | — | — | — | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. | 54d ago |
| CVE-2026-58479 | 9.8 | — | — | — | dan-in-ca / sustainable irrigation platform | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the opt | 54d ago |
| CVE-2026-62392 | 9.8 | — | — | — | apache / kylin | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache | 54d ago |
| CVE-2026-62390 | 9.8 | — | — | — | apache / kylin | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin | 54d ago |
| CVE-2026-15043 | 9.8 | — | — | — | — | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. | 54d ago |
| CVE-2026-59801 | 9.8 | — | — | — | — | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to in | 54d ago |
| CVE-2026-52533 | 9.8 | — | — | — | — | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow com | 54d ago |
| CVE-2026-51821 | 9.8 | — | — | — | — | SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute a | 54d ago |
| CVE-2026-51540 | 9.8 | — | — | — | opener project / opener | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an i | 54d ago |
| CVE-2026-61500 | 9.8 | — | — | — | — | Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() ge | 54d ago |
| CVE-2026-57433 | 9.8 | — | — | — | nwclark / storable | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. | 55d ago |
| CVE-2026-61498 | 9.8 | — | — | — | vitec / flamingo | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs. | 55d ago |
| CVE-2026-60121 | 9.8 | — | — | — | vitec / flamingo | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php en | 55d ago |
| CVE-2026-59518 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issu | 55d ago |
| CVE-2026-57813 | 9.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.Thi | 55d ago |
| CVE-2026-57770 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Inj | 55d ago |
| CVE-2026-57744 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object I | 55d ago |
| CVE-2026-57738 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue | 55d ago |
| CVE-2026-57724 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects | 55d ago |
| CVE-2026-4769 | 9.8 | — | — | — | — | Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial s | 55d ago |
| CVE-2026-15511 | 9.8 | — | — | — | — | A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. | 55d ago |
| CVE-2026-56271 | 9.8 | — | — | — | flowiseai / flowise | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', | 56d ago |
| CVE-2026-60090 | 9.8 | — | — | — | — | PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra k | 57d ago |