| CVE-2026-10109 | 9.8 | — | — | — | ibm / db2 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pr | 100d ago |
| CVE-2026-58138exploited | 9.8 | 14.7% | 1/3 | +27d | — | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows | 100d ago |
| CVE-2026-14241 | 9.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox 152.0.3. | 100d ago |
| CVE-2026-8655 | 9.8 | — | — | — | citrix / netscaler application delivery controller | Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneo | 101d ago |
| CVE-2026-8452exploited | 9.8 | 1.0% | 3/3 | +48d | citrix / netscaler application delivery controller | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior an | 101d ago |
| CVE-2026-58116 | 9.8 | — | — | — | hiyouga / llama-factory | LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access | 101d ago |
| CVE-2026-8402 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Elec | 101d ago |
| CVE-2026-14162 | 9.8 | — | — | — | — | Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthent | 101d ago |
| CVE-2026-13766 | 9.8 | — | — | — | — | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. | 101d ago |
| CVE-2026-9711 | 9.8 | — | — | — | — | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection vi | 101d ago |
| CVE-2026-12073 | 9.8 | — | — | — | — | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation | 101d ago |
| CVE-2026-13763 | 9.8 | — | — | — | amazon / application load balancer | Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow r | 101d ago |
| CVE-2026-13762 | 9.8 | — | — | — | amazon / cloudfront | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors | 101d ago |
| CVE-2026-56782 | 9.8 | — | — | — | — | Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints th | 101d ago |
| CVE-2026-56290zero day | 9.8 | 30.9% | 3/3 | 2d before | joomlack / page builder ck | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla ext | 101d ago |
| CVE-2026-49048 | 9.8 | — | — | — | joomcoder / joomcck | The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly conca | 102d ago |
| CVE-2026-12415 | 9.8 | — | — | — | — | The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check | 104d ago |
| CVE-2026-28701 | 9.8 | — | — | — | daktronics / dmp-5000 firmware | Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to e | 104d ago |
| CVE-2026-53309 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions | 104d ago |
| CVE-2026-0685 | 9.8 | — | — | — | — | Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 a | 104d ago |
| CVE-2026-56057 | 9.8 | — | — | — | — | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. | 104d ago |
| CVE-2026-56033 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. | 104d ago |
| CVE-2026-56032 | 9.8 | — | — | — | — | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | 104d ago |
| CVE-2026-56030 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. | 104d ago |
| CVE-2026-56028 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4. | 104d ago |
| CVE-2026-57881 | 9.8 | — | — | — | — | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC221 | 105d ago |
| CVE-2026-57880 | 9.8 | — | — | — | — | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 | 105d ago |
| CVE-2026-57879 | 9.8 | — | — | — | — | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 | 105d ago |
| CVE-2026-57878 | 9.8 | — | — | — | — | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC22 | 105d ago |
| CVE-2026-48930 | 9.8 | — | — | — | nodejs / node.js | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding du | 105d ago |
| CVE-2025-71336 | 9.8 | — | — | — | flowiseai / flowise | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution v | 105d ago |
| CVE-2025-71334exploited | 9.8 | 4.4% | 1/3 | +8d | flowiseai / flowise | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to | 105d ago |
| CVE-2025-71333 | 9.8 | — | — | — | flowiseai / flowise | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments e | 105d ago |
| CVE-2026-7531 | 9.8 | — | — | — | wolfssl / wolfssl | Use-after-free in PQC hybrid key-share handling. | 105d ago |
| CVE-2026-56786 | 9.8 | — | — | — | rtklib / rtklib | RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp | 105d ago |
| CVE-2026-50549 | 9.8 | — | — | — | anysphere / cursor | Cursor is a code editor built for programming with AI. | 105d ago |
| CVE-2026-50548 | 9.8 | — | — | — | anysphere / cursor | Cursor is a code editor built for programming with AI. | 105d ago |
| CVE-2026-41120 | 9.8 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With | 105d ago |
| CVE-2026-53260 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in | 106d ago |
| CVE-2026-53247 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free | 106d ago |
| CVE-2026-53246 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length i | 106d ago |
| CVE-2026-53228 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO | 106d ago |
| CVE-2026-53221 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6 | 106d ago |
| CVE-2026-53216 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buf | 106d ago |
| CVE-2026-53215 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or sk | 106d ago |
| CVE-2026-53176 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_ | 106d ago |
| CVE-2026-53175 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the | 106d ago |
| CVE-2026-53151 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK | 106d ago |
| CVE-2026-40079 | 9.8 | — | — | — | cacti / cacti | Cacti is an open source performance and fault management framework. | 106d ago |
| CVE-2026-39955 | 9.8 | — | — | — | cacti / cacti | Cacti is an open source performance and fault management framework. | 106d ago |
| CVE-2026-39948 | 9.8 | — | — | — | cacti / cacti | Cacti is an open source performance and fault management framework. | 106d ago |
| CVE-2026-39938 | 9.8 | — | — | — | cacti / cacti | Cacti is an open source performance and fault management framework. | 106d ago |
| CVE-2026-39893 | 9.8 | — | — | — | cacti / cacti | Cacti is an open source performance and fault management framework. | 106d ago |
| CVE-2026-49980 | 9.8 | — | — | — | rclone / rclone | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. | 106d ago |
| CVE-2026-54906 | 9.8 | — | — | — | rubyconcurrency / concurrent ruby | concurrent-ruby is a modern concurrency tools for Ruby. | 106d ago |
| CVE-2026-53088 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_ | 106d ago |
| CVE-2026-53086 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The | 106d ago |
| CVE-2026-53055 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-afte | 106d ago |
| CVE-2026-53049 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gf | 106d ago |
| CVE-2026-53046 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on | 106d ago |