| CVE-2026-38703 | 9.8 | — | — | — | inhandnetworks / ir315 firmware | A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, I | 101d ago |
| CVE-2026-38702 | 9.8 | — | — | — | inhandnetworks / ir315 firmware | A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, I | 101d ago |
| CVE-2026-24444 | 9.8 | — | — | — | — | SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerab | 101d ago |
| CVE-2026-46195 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before buildi | 101d ago |
| CVE-2026-46137 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-ra | 101d ago |
| CVE-2026-46135 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and | 101d ago |
| CVE-2026-46115 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeabl | 101d ago |
| CVE-2026-45083 | 9.8 | — | — | — | — | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. | 101d ago |
| CVE-2026-8364 | 9.8 | — | — | — | — | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and proces | 101d ago |
| CVE-2026-8363 | 9.8 | — | — | — | — | A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting | 101d ago |
| CVE-2026-8362 | 9.8 | — | — | — | — | A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting | 101d ago |
| CVE-2026-44888 | 9.8 | — | — | — | — | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. | 101d ago |
| CVE-2026-44887 | 9.8 | — | — | — | — | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. | 101d ago |
| CVE-2026-48027zero day | 9.8 | 1.8% | 3/3 | same day | nx / nx console | Nx Console is the user interface for Nx & Lerna. | 102d ago |
| CVE-2026-8175 | 9.8 | — | — | — | ibm / aspera high-speed transfer endpoint | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3. | 102d ago |
| CVE-2026-7524 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links | 102d ago |
| CVE-2026-46039 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length | 102d ago |
| CVE-2026-45988 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets I | 102d ago |
| CVE-2026-45972 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free | 102d ago |
| CVE-2026-45898 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by re | 102d ago |
| CVE-2026-42758 | 9.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows P | 102d ago |
| CVE-2026-42731 | 9.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification | 102d ago |
| CVE-2025-12686 | 9.8 | — | — | — | synology / beestation os | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology Be | 102d ago |
| CVE-2026-8760 | 9.8 | — | — | — | — | The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including | 102d ago |
| CVE-2026-48689 | 9.8 | — | — | — | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary | 102d ago |
| CVE-2026-3660 | 9.8 | — | — | — | ibm / engineering lifecycle management | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to upda | 102d ago |
| CVE-2026-9170 | 9.8 | — | — | — | ibm / http server | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improp | 103d ago |
| CVE-2026-8633 | 9.8 | — | — | — | ibm / websphere application server | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application S | 103d ago |
| CVE-2026-7251 | 9.8 | — | — | — | — | Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. | 103d ago |
| CVE-2026-44668 | 9.8 | — | — | — | — | FACTION is a PenTesting Report Generation and Collaboration Framework. | 103d ago |
| CVE-2026-48904 | 9.8 | — | — | — | joomla / joomla\! | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. | 103d ago |
| CVE-2026-48902 | 9.8 | — | — | — | joomla / joomla\! | The password and username reset features created plain http links for https connections if the "Force SSL" flag wa | 103d ago |
| CVE-2026-48899 | 9.8 | — | — | — | joomla / joomla\! | An improper access check allows privilege escalation through the com_users batch task. | 103d ago |
| CVE-2026-48898 | 9.8 | — | — | — | joomla / joomla\! | An improper access check allows privilege escalation through the com_users batch task. | 103d ago |
| CVE-2026-48691 | 9.8 | — | — | — | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. | 103d ago |
| CVE-2026-40383 | 9.8 | — | — | — | joomla / joomla\! | An improper validation of user-supplied input leads to a local file inclusion vulnerability. | 103d ago |
| CVE-2026-35223 | 9.8 | — | — | — | joomla / joomla\! | An improper access check allows unauthorized access to com_config webservice endpoints. | 103d ago |
| CVE-2026-35222 | 9.8 | — | — | — | joomla / joomla\! | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | 103d ago |
| CVE-2026-35221 | 9.8 | — | — | — | joomla / joomla\! | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | 103d ago |
| CVE-2026-48687 | 9.8 | — | — | — | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router in | 103d ago |
| CVE-2026-48686 | 9.8 | — | — | — | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer R | 103d ago |
| CVE-2026-45247exploited | 9.8 | 27.5% | 3/3 | +3d | mirasvit / full page cache warmer | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability | 103d ago |
| CVE-2026-9543 | 9.8 | — | — | — | — | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. | 103d ago |
| CVE-2026-8376 | 9.8 | — | — | — | perl / perl | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed | 103d ago |
| CVE-2026-9478 | 9.8 | — | — | — | — | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9477 | 9.8 | — | — | — | — | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9476 | 9.8 | — | — | — | — | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9475 | 9.8 | — | — | — | — | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9458 | 9.8 | — | — | — | — | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9457 | 9.8 | — | — | — | — | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9456 | 9.8 | — | — | — | — | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9455 | 9.8 | — | — | — | — | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9454 | 9.8 | — | — | — | — | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9436 | 9.8 | — | — | — | — | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9435 | 9.8 | — | — | — | — | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9434 | 9.8 | — | — | — | — | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9433 | 9.8 | — | — | — | — | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9432 | 9.8 | — | — | — | — | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9408 | 9.8 | — | — | — | — | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9407 | 9.8 | — | — | — | — | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |