| CVE-2026-53045 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The | 106d ago |
| CVE-2026-53010 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during | 106d ago |
| CVE-2026-53006 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching | 106d ago |
| CVE-2026-53002 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Rep | 106d ago |
| CVE-2026-52993 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tip | 106d ago |
| CVE-2026-52989 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec | 106d ago |
| CVE-2026-52986 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_ | 106d ago |
| CVE-2026-52982 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl81 | 106d ago |
| CVE-2026-52955 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in | 106d ago |
| CVE-2026-56121 | 9.8 | — | — | — | — | Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized a | 106d ago |
| CVE-2026-52931 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit send | 107d ago |
| CVE-2026-52924 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO hand | 107d ago |
| CVE-2026-52914 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length acc | 107d ago |
| CVE-2026-12417 | 9.8 | — | — | — | — | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation | 107d ago |
| CVE-2026-12416 | 9.8 | — | — | — | — | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up | 107d ago |
| CVE-2026-53753 | 9.8 | — | — | — | kidocode / crawl4ai | Crawl4AI is an open-source LLM friendly web crawler & scraper. | 107d ago |
| CVE-2026-56315 | 9.8 | — | — | — | — | picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_suppor | 108d ago |
| CVE-2026-12866 | 9.8 | — | — | — | — | All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. | 108d ago |
| CVE-2026-49468 | 9.8 | — | — | — | litellm / litellm | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. | 108d ago |
| CVE-2026-7664 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resource | 108d ago |
| CVE-2026-6653 | 9.8 | — | — | — | xmlsoft / libxml2 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote atta | 109d ago |
| CVE-2026-56265 | 9.8 | — | — | — | kidocode / crawl4ai | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key i | 110d ago |
| CVE-2024-58351 | 9.8 | — | — | — | — | Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfi | 110d ago |
| CVE-2022-50972 | 9.8 | — | — | — | — | WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP co | 111d ago |
| CVE-2019-25763 | 9.8 | — | — | — | — | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows a | 111d ago |
| CVE-2026-48939exploited | 9.8 | 20.1% | 3/3 | +20d | joomlic / icagenda | A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment f | 111d ago |
| CVE-2026-48908zero day | 9.8 | 88.5% | 3/3 | 5d before | ollyo / sp page builder | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately r | 111d ago |
| CVE-2026-11551 | 9.8 | — | — | — | — | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, | 111d ago |
| CVE-2026-48773 | 9.8 | — | — | — | proxysql / proxysql | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. | 111d ago |
| CVE-2026-51846 | 9.8 | — | — | — | tenda / ac7 firmware | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow | 111d ago |
| CVE-2026-51845 | 9.8 | — | — | — | tenda / ac7 firmware | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via | 111d ago |
| CVE-2026-51844 | 9.8 | — | — | — | tenda / ac7 firmware | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via | 111d ago |
| CVE-2026-51843 | 9.8 | — | — | — | tenda / ac7 firmware | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via | 111d ago |
| CVE-2026-56141 | 9.8 | — | — | — | jetbrains / hub | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 ac | 112d ago |
| CVE-2026-7515zero day | 9.8 | 0.94% | 1/3 | same day | — | The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8 | 112d ago |
| CVE-2026-54414 | 9.8 | — | — | — | — | FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToS | 112d ago |
| CVE-2026-40624 | 9.8 | — | — | — | — | Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticate | 112d ago |
| CVE-2026-54130 | 9.8 | — | — | — | microsoft / 365 copilot | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose informati | 112d ago |
| CVE-2026-47846 | 9.8 | — | — | — | — | Bitnami Cassandra container images are affected by a retained default superuser vulnerability. | 112d ago |
| CVE-2026-54390 | 9.8 | — | — | — | — | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthen | 112d ago |
| CVE-2026-54103 | 9.8 | — | — | — | — | The U.S. | 112d ago |
| CVE-2026-38717 | 9.8 | — | — | — | inhandnetworks / ir915l-fq39-s firmware | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contai | 112d ago |
| CVE-2026-38716 | 9.8 | — | — | — | inhandnetworks / ir915l-fq39-s firmware | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contai | 112d ago |
| CVE-2026-38715 | 9.8 | — | — | — | inhandnetworks / ir915l-fq39-s firmware | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contai | 112d ago |
| CVE-2026-38714 | 9.8 | — | — | — | inhandnetworks / ir915l-fq39-s firmware | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contai | 112d ago |
| CVE-2026-9158 | 9.8 | — | — | — | eclipse / 4diac forte | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management int | 113d ago |
| CVE-2026-8024 | 9.8 | — | — | — | — | A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDa | 113d ago |
| CVE-2026-54419 | 9.8 | — | — | — | — | claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b | 113d ago |
| CVE-2026-55740 | 9.8 | — | — | — | — | Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an u | 113d ago |
| CVE-2026-12569exploited | 9.8 | 46.0% | 3/3 | +7d | ptc / flexplm | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. | 113d ago |
| CVE-2026-53805 | 9.8 | — | — | — | — | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in t | 113d ago |
| CVE-2026-53874 | 9.8 | — | — | — | — | picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute | 113d ago |
| CVE-2026-53873 | 9.8 | — | — | — | — | picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-lev | 113d ago |
| CVE-2025-71325 | 9.8 | — | — | — | — | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL o | 113d ago |
| CVE-2025-71323 | 9.8 | — | — | — | — | picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by | 113d ago |
| CVE-2025-71321 | 9.8 | — | — | — | — | picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dang | 113d ago |
| CVE-2025-71320 | 9.8 | — | — | — | — | picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcall | 113d ago |
| CVE-2026-47103 | 9.8 | — | — | — | fgmacedo / python statemachine | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attacke | 113d ago |
| CVE-2026-49108 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Moderno < 1.43 versions. | 114d ago |
| CVE-2025-69127 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. | 114d ago |