| CVE-2026-12847 | 10 | critical | — | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and | 73d ago |
| CVE-2026-12846 | 10 | critical | — | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and | 73d ago |
| CVE-2026-12485 | 10 | critical | — | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and | 73d ago |
| CVE-2026-53622 | 10 | critical | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 74d ago |
| CVE-2026-48491 | 10 | critical | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 74d ago |
| CVE-2026-48020 | 10 | critical | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 74d ago |
| CVE-2026-54309 | 10 | critical | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-10561 | 10 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combine | 75d ago |
| CVE-2026-45480 | 10 | critical | microsoft / azure active directory | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a net | 78d ago |
| CVE-2026-48772 | 10 | critical | proxysql / proxysql | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. | 78d ago |
| CVE-2026-50242 | 10 | critical | jetbrains / hub | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 au | 78d ago |
| CVE-2026-49257 | 10 | critical | — | mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. | 79d ago |
| CVE-2026-3490 | 10 | critical | — | picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by r | 80d ago |
| CVE-2026-48055 | 10 | critical | — | Streambert is a cross-platform Electron Desktop App to stream and download any video media. | 80d ago |
| CVE-2026-25470 | 10 | critical | — | Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plu | 80d ago |
| CVE-2025-69129 | 10 | critical | — | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0. | 80d ago |
| CVE-2026-46978 | 10 | critical | oracle / solaris | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). | 80d ago |
| CVE-2026-46846 | 10 | critical | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). | 80d ago |
| CVE-2026-46803 | 10 | critical | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). | 80d ago |
| CVE-2026-46800 | 10 | critical | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 80d ago |
| CVE-2026-46798 | 10 | critical | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 80d ago |
| CVE-2026-46781 | 10 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 80d ago |
| CVE-2026-46778 | 10 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 80d ago |
| CVE-2026-35308 | 10 | critical | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars | 80d ago |
| CVE-2026-35307 | 10 | critical | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 80d ago |
| CVE-2026-35301 | 10 | critical | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). | 80d ago |
| CVE-2026-35292 | 10 | critical | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). | 80d ago |
| CVE-2026-48836 | 10 | critical | — | Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | 82d ago |
| CVE-2026-40772 | 10 | critical | — | Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions. | 82d ago |
| CVE-2026-52704 | 10 | critical | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Bui | 82d ago |
| CVE-2026-48558exploited | 10 | critical | simple-help / simplehelp | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability i | 85d ago |
| CVE-2026-50086 | 10 | critical | aqara / iam\/sso gateway | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's sign | 85d ago |
| CVE-2026-47208 | 10 | critical | — | vm2 is an open source vm/sandbox for Node.js. | 85d ago |
| CVE-2026-47140 | 10 | critical | — | vm2 is an open source vm/sandbox for Node.js. | 85d ago |
| CVE-2026-47137 | 10 | critical | — | vm2 is an open source vm/sandbox for Node.js. | 85d ago |
| CVE-2026-47131 | 10 | critical | — | vm2 is an open source vm/sandbox for Node.js. | 85d ago |
| CVE-2026-49261 | 10 | critical | mariadb / mariadb | MariaDB server is a community developed fork of MySQL server. | 86d ago |
| CVE-2026-46695 | 10 | critical | — | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI conta | 87d ago |
| CVE-2026-48303 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vuln | 88d ago |
| CVE-2026-47938 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery ( | 88d ago |
| CVE-2026-10520exploited | 10 | critical | ivanti / standalone sentry | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a r | 88d ago |
| CVE-2026-46389 | 10 | critical | defenseunicorns / uds identity config | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by | 92d ago |
| CVE-2026-49777 | 10 | critical | — | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCo | 92d ago |
| CVE-2026-48567 | 10 | critical | microsoft / azure horizondb | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a | 93d ago |
| CVE-2026-7312 | 10 | critical | progress / sitefinity | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4 | 95d ago |
| CVE-2026-10611 | 10 | critical | misp-project / misp | An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforceme | 95d ago |
| CVE-2026-40965 | 10 | critical | — | Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. | 96d ago |
| CVE-2026-45132 | 10 | critical | — | CloudPirates Open Source Helm Charts is a collection of Helm charts. | 96d ago |
| CVE-2026-45131 | 10 | critical | — | CloudPirates Open Source Helm Charts is a collection of Helm charts. | 96d ago |
| CVE-2026-45631 | 10 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 99d ago |
| CVE-2026-46840 | 10 | critical | oracle / rest data services | Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). | 100d ago |
| CVE-2026-43898 | 10 | critical | nyariv / sandboxjs | SandboxJS is a JavaScript sandboxing library. | 100d ago |
| CVE-2026-45087 | 10 | critical | — | Dalfox is a powerful open-source XSS scanner and utility focused on automation. | 101d ago |
| CVE-2026-44330 | 10 | critical | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 101d ago |
| CVE-2026-44329 | 10 | critical | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 101d ago |
| CVE-2026-44327 | 10 | critical | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 101d ago |
| CVE-2026-47280 | 10 | critical | microsoft / azure resource manager | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over | 106d ago |
| CVE-2026-42901 | 10 | critical | microsoft / entra id | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network | 106d ago |
| CVE-2026-41104 | 10 | critical | microsoft / planetary computer | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose | 106d ago |
| CVE-2026-40412 | 10 | critical | microsoft / azure orbital spatio | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute | 106d ago |