| CVE-2026-35293 | 9.8 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 114d ago |
| CVE-2026-35286 | 9.8 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 114d ago |
| CVE-2026-35278 | 9.8 | — | — | — | oracle / peoplesoft enterprise pt peopletools | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Mon | 114d ago |
| CVE-2026-0126 | 9.8 | — | — | — | google / android | In WC-Radio, there is a possible out of bounds write due to a missing bounds check. | 114d ago |
| CVE-2026-12293 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the Graphics: WebGPU component. | 115d ago |
| CVE-2026-9691 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninj | 115d ago |
| CVE-2026-49781 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. | 115d ago |
| CVE-2026-49770 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | 115d ago |
| CVE-2026-49769 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | 115d ago |
| CVE-2026-49768 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | 115d ago |
| CVE-2026-49765 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Fo | 115d ago |
| CVE-2026-49764 | 9.8 | — | — | — | — | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. | 115d ago |
| CVE-2026-49763 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. | 115d ago |
| CVE-2026-49109 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formida | 115d ago |
| CVE-2026-49106 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | 115d ago |
| CVE-2026-49105 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Fo | 115d ago |
| CVE-2026-49104 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, | 115d ago |
| CVE-2026-49085 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja | 115d ago |
| CVE-2026-39583 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions. | 115d ago |
| CVE-2026-34901 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. | 115d ago |
| CVE-2026-27053 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. | 115d ago |
| CVE-2026-50890 | 9.8 | — | — | — | — | Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter a | 115d ago |
| CVE-2026-50880 | 9.8 | — | — | — | — | An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitra | 115d ago |
| CVE-2026-50873 | 9.8 | — | — | — | — | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers t | 115d ago |
| CVE-2026-50872 | 9.8 | — | — | — | — | An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute a | 115d ago |
| CVE-2026-50871 | 9.8 | — | — | — | — | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Remin | 115d ago |
| CVE-2026-50869 | 9.8 | — | — | — | — | An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via s | 115d ago |
| CVE-2026-48114 | 9.8 | — | — | — | — | Metacat is data repository software that helps researchers preserve, share, and discover data. | 115d ago |
| CVE-2026-39196 | 9.8 | — | — | — | — | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter | 115d ago |
| CVE-2026-39006 | 9.8 | — | — | — | — | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath com | 115d ago |
| CVE-2026-38812 | 9.8 | — | — | — | — | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. | 115d ago |
| CVE-2026-38329 | 9.8 | — | — | — | — | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. | 115d ago |
| CVE-2026-38065 | 9.8 | — | — | — | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn vi | 115d ago |
| CVE-2026-38064 | 9.8 | — | — | — | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the | 115d ago |
| CVE-2026-38063 | 9.8 | — | — | — | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_a | 115d ago |
| CVE-2026-38062 | 9.8 | — | — | — | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via t | 115d ago |
| CVE-2026-38061 | 9.8 | — | — | — | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the | 115d ago |
| CVE-2026-38060 | 9.8 | — | — | — | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the | 115d ago |
| CVE-2026-36537 | 9.8 | — | — | — | — | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. | 115d ago |
| CVE-2026-30120 | 9.8 | — | — | — | remotion / remotion | remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. | 115d ago |
| CVE-2026-9862 | 9.8 | — | — | — | fortra / core privileged access manager server | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregis | 116d ago |
| CVE-2018-25436 | 9.8 | — | — | — | — | WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that | 116d ago |
| CVE-2026-8935 | 9.8 | — | — | — | — | The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce t | 116d ago |
| CVE-2026-11526 | 9.8 | — | — | — | — | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename argu | 117d ago |
| CVE-2026-12183 | 9.8 | — | — | — | — | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Aut | 118d ago |
| CVE-2026-53838 | 9.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired | 118d ago |
| CVE-2026-41157 | 9.8 | — | — | — | — | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of- | 118d ago |
| CVE-2026-28742 | 9.8 | — | — | — | — | Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every f | 118d ago |
| CVE-2026-44170 | 9.8 | — | — | — | mariadb / mariadb | MariaDB server is a community developed fork of MySQL server. | 119d ago |
| CVE-2026-6853 | 9.8 | — | — | — | — | Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Indu | 119d ago |
| CVE-2026-54133 | 9.8 | — | — | — | jmespath / jmespath | jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JS | 119d ago |
| CVE-2026-53787 | 9.8 | — | — | — | — | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulne | 119d ago |
| CVE-2026-47210 | 9.8 | — | — | — | — | vm2 is an open source vm/sandbox for Node.js. | 119d ago |
| CVE-2026-10557 | 9.8 | — | — | — | — | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users | 119d ago |
| CVE-2026-11849 | 9.8 | — | — | — | — | The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowin | 119d ago |
| CVE-2026-50628 | 9.8 | — | — | — | apache / cxf | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blind | 119d ago |
| CVE-2026-49875 | 9.8 | — | — | — | apache / cxf | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the nec | 119d ago |
| CVE-2026-48611exploited | 9.8 | 2.9% | 1/3 | +38d | — | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configur | 119d ago |
| CVE-2026-45060 | 9.8 | — | — | — | — | ClipBucket v5 is an open source video sharing platform. | 119d ago |
| CVE-2026-42846 | 9.8 | — | — | — | — | ClipBucket v5 is an open source video sharing platform. | 119d ago |