| CVE-2026-49060zero day | 9.8 | 1.6% | 1/3 | 3d before | — | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. | 119d ago |
| CVE-2026-38581 | 9.8 | — | — | — | — | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute a | 120d ago |
| CVE-2026-7852 | 9.8 | — | — | — | — | Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. | 120d ago |
| CVE-2026-11561 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an expression language statement ('expression language injecti | 120d ago |
| CVE-2026-35273zero day | 9.8 | 9.4% | 3/3 | same day | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environmen | 120d ago |
| CVE-2026-46614 | 9.8 | — | — | — | — | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and | 120d ago |
| CVE-2026-20253exploited | 9.8 | 96.9% | 3/3 | +5d | splunk / splunk | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create | 120d ago |
| CVE-2025-6254 | 9.8 | — | — | — | — | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, | 121d ago |
| CVE-2025-66276 | 9.8 | — | — | — | qnap / qts | QuTS hero is not affected. | 121d ago |
| CVE-2026-36721 | 9.8 | — | — | — | — | A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attacke | 121d ago |
| CVE-2026-30141 | 9.8 | — | — | — | — | An issue was discovered in bitbank2 AnimatedGIF v2.2.0. | 121d ago |
| CVE-2026-10045 | 9.8 | — | — | — | — | Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hard | 121d ago |
| CVE-2026-49841 | 9.8 | — | — | — | freeswitch / freeswitch | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switch | 121d ago |
| CVE-2026-47643 | 9.8 | — | — | — | microsoft / azure stack edge | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a n | 121d ago |
| CVE-2026-47291 | 9.8 | — | — | — | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | 121d ago |
| CVE-2026-45657 | 9.8 | — | — | — | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | 121d ago |
| CVE-2026-44815 | 9.8 | — | — | — | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 121d ago |
| CVE-2026-38615 | 9.8 | — | — | — | — | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. | 121d ago |
| CVE-2026-26142 | 9.8 | — | — | — | microsoft / nuance powerscribe 360 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a net | 121d ago |
| CVE-2026-8025 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Informat | 122d ago |
| CVE-2026-25089exploited | 9.8 | 76.1% | 3/3 | +6d | fortinet / fortisandbox | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fort | 122d ago |
| CVE-2026-7486 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Softwa | 122d ago |
| CVE-2026-46325 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR pag | 122d ago |
| CVE-2017-20251 | 9.8 | — | — | — | — | WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthent | 122d ago |
| CVE-2026-9698 | 9.8 | — | — | — | perl / dbi | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. | 122d ago |
| CVE-2026-44083 | 9.8 | — | — | — | qnap / qumagie | An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. | 122d ago |
| CVE-2026-5067 | 9.8 | — | — | — | zephyrproject / zephyr | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by | 122d ago |
| CVE-2026-27671 | 9.8 | — | — | — | — | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and | 122d ago |
| CVE-2026-52778 | 9.8 | — | — | — | — | YesWiki is a wiki system written in PHP. | 122d ago |
| CVE-2026-46289 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in ex | 122d ago |
| CVE-2026-25555 | 9.8 | — | — | — | — | OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication mi | 122d ago |
| CVE-2026-44631 | 9.8 | — | — | — | apache / http server | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. | 123d ago |
| CVE-2026-29167 | 9.8 | — | — | — | apache / http server | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects | 123d ago |
| CVE-2026-11499 | 9.8 | — | — | — | — | A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. | 123d ago |
| CVE-2024-58349 | 9.8 | — | — | — | — | WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated atta | 123d ago |
| CVE-2024-58348 | 9.8 | — | — | — | — | WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthen | 123d ago |
| CVE-2023-54352 | 9.8 | — | — | — | — | WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute | 123d ago |
| CVE-2026-45779 | 9.8 | — | — | — | buffalo / open xdmod | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. | 125d ago |
| CVE-2026-45777 | 9.8 | — | — | — | buffalo / open xdmod | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. | 125d ago |
| CVE-2026-11420 | 9.8 | — | — | — | altium / on-prem enterprise server | Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an | 125d ago |
| CVE-2026-11414 | 9.8 | — | — | — | altium / on-prem enterprise server | A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service | 125d ago |
| CVE-2026-10580 | 9.8 | — | — | — | — | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Admin | 125d ago |
| CVE-2026-45748 | 9.8 | — | — | — | termix / termix | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 125d ago |
| CVE-2025-71318 | 9.8 | — | — | — | — | NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. | 125d ago |
| CVE-2025-71317 | 9.8 | — | — | — | — | NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrativ | 125d ago |
| CVE-2026-11362 | 9.8 | — | — | — | binary / datadog\ | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. | 126d ago |
| CVE-2026-10879 | 9.8 | — | — | — | perl / dbi | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. | 126d ago |
| CVE-2026-6274 | 9.8 | — | — | — | — | Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Ele | 126d ago |
| CVE-2026-48907exploited | 9.8 | 16.2% | 3/3 | +7d | widgetfactorylimited / jce | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthentica | 126d ago |
| CVE-2026-7763 | 9.8 | — | — | — | — | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 sof | 126d ago |
| CVE-2026-7762 | 9.8 | — | — | — | — | A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 s | 126d ago |
| CVE-2025-71316 | 9.8 | — | — | — | — | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters | 126d ago |
| CVE-2026-25550 | 9.8 | — | — | — | — | Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in | 126d ago |
| CVE-2026-10880 | 9.8 | — | — | — | — | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. | 126d ago |
| CVE-2025-67447 | 9.8 | — | — | — | — | The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS comman | 126d ago |
| CVE-2025-67446 | 9.8 | — | — | — | — | Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. | 126d ago |
| CVE-2026-36182 | 9.8 | — | — | — | — | GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowin | 127d ago |
| CVE-2026-35905 | 9.8 | — | — | — | — | T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded | 127d ago |
| CVE-2026-35904 | 9.8 | — | — | — | — | Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0. | 127d ago |
| CVE-2019-25741 | 9.8 | — | — | — | — | Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the u | 127d ago |