| CVE-2026-58422 | 9.8 | — | — | — | — | Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts | 64d ago |
| CVE-2026-27780 | 9.8 | — | — | — | — | Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, a | 64d ago |
| CVE-2026-26292 | 9.8 | — | — | — | — | Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypa | 64d ago |
| CVE-2026-20896exploited | 9.8 | 2.8% | 1/3 | +3d | — | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing an | 64d ago |
| CVE-2026-12481 | 9.8 | — | — | — | keras / keras | A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of | 64d ago |
| CVE-2026-4321 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankar | 65d ago |
| CVE-2026-47898 | 9.8 | — | — | — | apache / lucene.net | Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Comm | 65d ago |
| CVE-2026-14544 | 9.8 | — | — | — | — | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). | 65d ago |
| CVE-2026-9079 | 9.8 | — | — | — | haxx / curl | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving | 65d ago |
| CVE-2026-8925 | 9.8 | — | — | — | haxx / curl | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clear | 65d ago |
| CVE-2026-11856 | 9.8 | — | — | — | haxx / curl | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and | 65d ago |
| CVE-2026-10536 | 9.8 | — | — | — | haxx / curl | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree v | 65d ago |
| CVE-2026-38968 | 9.8 | — | — | — | ntop / ntopng | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. | 65d ago |
| CVE-2026-58466 | 9.8 | — | — | — | — | AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attac | 65d ago |
| CVE-2024-14037zero day | 9.8 | 1.3% | 1/3 | same day | — | Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve | 66d ago |
| CVE-2022-50973zero day | 9.8 | 1.5% | 1/3 | same day | — | Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload | 66d ago |
| CVE-2026-58455exploited | 9.8 | 8.0% | 1/3 | +19d | — | Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attack | 66d ago |
| CVE-2026-4767 | 9.8 | — | — | — | — | Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. | 66d ago |
| CVE-2026-5524zero day | 9.8 | 0.92% | 1/3 | same day | — | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution | 66d ago |
| CVE-2026-57677 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. | 66d ago |
| CVE-2026-57621 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. | 66d ago |
| CVE-2026-52186 | 9.8 | — | — | — | — | SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitra | 66d ago |
| CVE-2026-58457exploited | 9.8 | 2.9% | 1/3 | +65d | — | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnera | 66d ago |
| CVE-2026-14363 | 9.8 | — | — | — | mediawiki / cargo | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedi | 66d ago |
| CVE-2026-51947 | 9.8 | — | — | — | — | An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6. | 66d ago |
| CVE-2026-58521 | 9.8 | — | — | — | mediawiki / cargo | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedi | 67d ago |
| CVE-2026-58453 | 9.8 | — | — | — | — | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerabilit | 67d ago |
| CVE-2026-34117 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (lin | 67d ago |
| CVE-2026-34116 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) w | 67d ago |
| CVE-2026-34115 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (lin | 67d ago |
| CVE-2026-34114 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 1 | 67d ago |
| CVE-2026-34113 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) | 67d ago |
| CVE-2026-34112 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) wi | 67d ago |
| CVE-2026-34111 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 1 | 67d ago |
| CVE-2026-34110 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14 | 67d ago |
| CVE-2026-34109 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) witho | 67d ago |
| CVE-2026-34108 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without | 67d ago |
| CVE-2026-34107 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) wi | 67d ago |
| CVE-2026-34106 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) wi | 67d ago |
| CVE-2026-34099 | 9.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line | 67d ago |
| CVE-2026-58127 | 9.8 | — | — | — | hyland / pacsgear | PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, reg | 67d ago |
| CVE-2026-58126 | 9.8 | — | — | — | hyland / pacsgear | PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attack | 67d ago |
| CVE-2026-58025 | 9.8 | — | — | — | mediawiki / mediawiki | Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. | 67d ago |
| CVE-2026-57517 | 9.8 | — | — | — | — | Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remot | 67d ago |
| CVE-2026-24270 | 9.8 | — | — | — | — | NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. | 67d ago |
| CVE-2025-15646 | 9.8 | — | — | — | — | HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. | 67d ago |
| CVE-2026-57692 | 9.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. | 67d ago |
| CVE-2026-53355 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RD | 67d ago |
| CVE-2026-11387 | 9.8 | — | — | — | — | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is v | 67d ago |
| CVE-2026-7840 | 9.8 | — | — | — | uvnc / ultravnc | UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. | 67d ago |
| CVE-2026-56700 | 9.8 | — | — | — | — | Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. | 67d ago |
| CVE-2026-14121 | 9.8 | — | — | — | google / chrome | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute | 67d ago |
| CVE-2026-14104 | 9.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a rem | 67d ago |
| CVE-2026-13776 | 9.8 | — | — | — | google / chrome | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the r | 67d ago |
| CVE-2026-13775 | 9.8 | — | — | — | google / chrome | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the re | 67d ago |
| CVE-2026-58449 | 9.8 | — | — | — | — | txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is r | 67d ago |
| CVE-2026-50003 | 9.8 | — | — | — | — | A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outs | 67d ago |
| CVE-2026-37106 | 9.8 | — | — | — | — | An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register f | 67d ago |
| CVE-2026-7871 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full applicatio | 67d ago |
| CVE-2026-7803 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes | 67d ago |