| CVE-2026-57827 | 9.8 | — | — | — | rsjoomla / rsfiles\! | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extensio | 57d ago |
| CVE-2026-20744 | 9.8 | — | — | — | — | The charging station websocket endpoint accepts connections without proper authentication, which could lead to pri | 57d ago |
| CVE-2026-11913 | 9.8 | — | — | — | — | vulnerability in Drupal Mother May I allows . | 57d ago |
| CVE-2026-12535 | 9.8 | — | — | — | zroger / formatter field | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter F | 57d ago |
| CVE-2026-10768 | 9.8 | — | — | — | localgovdrupal / localgov workflows | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. | 57d ago |
| CVE-2026-9726 | 9.8 | — | — | — | alternativecommerce / alternativecommerce | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alter | 57d ago |
| CVE-2026-57807 | 9.8 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. | 57d ago |
| CVE-2026-12761 | 9.8 | — | — | — | — | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable t | 57d ago |
| CVE-2026-57156 | 9.8 | — | — | — | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 57d ago |
| CVE-2026-61459 | 9.8 | — | — | — | suyogs / mcp-server-kubernetes | MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, | 57d ago |
| CVE-2026-5801 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Inform | 57d ago |
| CVE-2026-2397 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail A | 58d ago |
| CVE-2026-56765 | 9.8 | — | — | — | — | Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to | 58d ago |
| CVE-2026-53363 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in ip | 58d ago |
| CVE-2026-40008 | 9.8 | — | — | — | — | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. | 58d ago |
| CVE-2026-28564 | 9.8 | — | — | — | — | Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. | 58d ago |
| CVE-2026-15282 | 9.8 | — | — | — | — | The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali | 58d ago |
| CVE-2026-14894zero day | 9.8 | 5.3% | 1/3 | 1d before | — | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all vers | 58d ago |
| CVE-2026-58123 | 9.8 | — | — | — | — | Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote at | 58d ago |
| CVE-2026-51599 | 9.8 | — | — | — | — | An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.799 | 59d ago |
| CVE-2026-12116 | 9.8 | — | — | — | — | A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server set | 59d ago |
| CVE-2026-56291zero day | 9.8 | 14.6% | 3/3 | 1d before | balbooa / forms | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla exten | 59d ago |
| CVE-2026-5955 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Softwa | 59d ago |
| CVE-2026-15158 | 9.8 | — | — | — | — | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and inclu | 59d ago |
| CVE-2026-14245 | 9.8 | — | — | — | — | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication | 59d ago |
| CVE-2026-52200 | 9.8 | — | — | — | — | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the | 59d ago |
| CVE-2026-44024 | 9.8 | — | — | — | fluentd / fluentd | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and s | 59d ago |
| CVE-2026-31309 | 9.8 | — | — | — | — | Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 al | 59d ago |
| CVE-2026-58480zero day | 9.8 | 3.6% | 1/3 | 6d before | — | Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnera | 60d ago |
| CVE-2026-8307 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web | 60d ago |
| CVE-2026-14454 | 9.8 | — | — | — | tonycoz / imager | Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. | 60d ago |
| CVE-2026-9695 | 9.8 | — | — | — | — | An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow | 60d ago |
| CVE-2026-12153 | 9.8 | — | — | — | — | The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi | 60d ago |
| CVE-2026-9701 | 9.8 | — | — | — | — | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and i | 60d ago |
| CVE-2026-59705 | 9.8 | — | — | — | — | mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attac | 60d ago |
| CVE-2026-37271 | 9.8 | — | — | — | — | Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device acce | 60d ago |
| CVE-2026-37270 | 9.8 | — | — | — | — | Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper p | 60d ago |
| CVE-2026-14739 | 9.8 | — | — | — | perl / dbi | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of p | 60d ago |
| CVE-2026-59800zero day | 9.8 | 2.0% | 1/3 | same day | — | 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tails | 60d ago |
| CVE-2026-13019 | 9.8 | — | — | — | esri / portal for arcgis | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication fo | 61d ago |
| CVE-2026-53483 | 9.8 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 61d ago |
| CVE-2026-53481 | 9.8 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 61d ago |
| CVE-2011-10043 | 9.8 | — | — | — | — | Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. | 61d ago |
| CVE-2026-33264 | 9.8 | — | — | — | apache / airflow | A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class pat | 61d ago |
| CVE-2026-14345 | 9.8 | — | — | — | — | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable | 61d ago |
| CVE-2026-12375 | 9.8 | — | — | — | — | The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's u | 61d ago |
| CVE-2026-11405 | 9.8 | — | — | — | — | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 00 | 61d ago |
| CVE-2026-9182 | 9.8 | — | — | — | esri / arcgis server | Esri ArcGIS Server contains an unrestricted file upload vulnerability. | 61d ago |
| CVE-2026-9181 | 9.8 | — | — | — | esri / arcgis server | Esri ArcGIS Server contains a directory traversal vulnerability. | 61d ago |
| CVE-2026-40139 | 9.8 | — | — | — | beyondtrust / privileged remote access | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. | 62d ago |
| CVE-2026-56140 | 9.8 | — | — | — | apache / camel | Improper Input Validation vulnerability in Apache Camel AWS SNS component. | 62d ago |
| CVE-2026-53913 | 9.8 | — | — | — | apache / camel | Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulne | 62d ago |
| CVE-2026-48204 | 9.8 | — | — | — | apache / camel | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component | 62d ago |
| CVE-2026-46456 | 9.8 | — | — | — | apache / camel | Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. | 62d ago |
| CVE-2026-46455 | 9.8 | — | — | — | apache / camel | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. | 62d ago |
| CVE-2026-46454 | 9.8 | — | — | — | apache / camel | Improper Input Validation vulnerability in Apache Camel Cometd Component. | 62d ago |
| CVE-2026-43867 | 9.8 | — | — | — | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. | 62d ago |
| CVE-2026-24014 | 9.8 | — | — | — | apache / iotdb | Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name t | 62d ago |
| CVE-2026-14808 | 9.8 | — | — | — | — | Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unaut | 62d ago |
| CVE-2026-14807 | 9.8 | — | — | — | — | ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote a | 62d ago |