| CVE-2026-9406 | 9.8 | — | — | — | — | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9405 | 9.8 | — | — | — | — | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9404 | 9.8 | — | — | — | — | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. | 104d ago |
| CVE-2026-9388 | 9.8 | — | — | — | — | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. | 105d ago |
| CVE-2026-9387 | 9.8 | — | — | — | — | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. | 105d ago |
| CVE-2026-9386 | 9.8 | — | — | — | — | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. | 105d ago |
| CVE-2026-9385 | 9.8 | — | — | — | — | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. | 105d ago |
| CVE-2026-9384 | 9.8 | — | — | — | — | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. | 105d ago |
| CVE-2018-25357 | 9.8 | — | — | — | dolibarr / dolibarr erp\/crm | Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to exe | 105d ago |
| CVE-2018-25350 | 9.8 | — | — | — | — | userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover v | 105d ago |
| CVE-2026-32253 | 9.8 | — | — | — | lizardbyte / sunshine | Sunshine is a self-hosted game stream host for Moonlight. | 107d ago |
| CVE-2026-44930 | 9.8 | — | — | — | apache / cxf | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an a | 107d ago |
| CVE-2026-6960 | 9.8 | — | — | — | — | The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati | 107d ago |
| CVE-2026-48207 | 9.8 | — | — | — | apache / fory | Deserialization of untrusted data in Apache Fory PyFory. | 108d ago |
| CVE-2025-71211 | 9.8 | — | — | — | trendmicro / apex one | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious c | 108d ago |
| CVE-2025-71210 | 9.8 | — | — | — | trendmicro / apex one | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious c | 108d ago |
| CVE-2026-5118 | 9.8 | — | — | — | — | The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, | 108d ago |
| CVE-2026-43501 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recom | 108d ago |
| CVE-2026-6279 | 9.8 | — | — | — | — | The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via | 108d ago |
| CVE-2026-48172zero day | 9.8 | 18.9% | 3/3 | same day | litespeedtech / litespeed cpanel plugin | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the | 108d ago |
| CVE-2026-8631 | 9.8 | — | — | — | hp / linux imaging and printing | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. | 108d ago |
| CVE-2026-9141 | 9.8 | — | — | — | — | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedde | 108d ago |
| CVE-2026-9139 | 9.8 | — | — | — | — | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded | 108d ago |
| CVE-2026-9082exploited | 9.8 | 87.9% | 3/3 | +2d | drupal / drupal | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal | 108d ago |
| CVE-2026-33278 | 9.8 | — | — | — | nlnetlabs / unbound | NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enab | 109d ago |
| CVE-2026-7637 | 9.8 | — | — | — | — | The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via de | 109d ago |
| CVE-2026-24207 | 9.8 | — | — | — | nvidia / triton inference server | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. | 109d ago |
| CVE-2026-7284 | 9.8 | — | — | — | — | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escala | 109d ago |
| CVE-2026-6555 | 9.8 | — | — | — | — | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and includ | 109d ago |
| CVE-2026-8495 | 9.8 | — | — | — | date ical project / date ical | Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. | 109d ago |
| CVE-2026-8605 | 9.8 | — | — | — | scadabr / scadabr | In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA | 110d ago |
| CVE-2026-8603 | 9.8 | — | — | — | scadabr / scadabr | In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root | 110d ago |
| CVE-2026-36829 | 9.8 | — | — | — | — | An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including | 110d ago |
| CVE-2026-37281 | 9.8 | — | — | — | — | An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allow | 110d ago |
| CVE-2026-31072 | 9.8 | — | — | — | — | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to | 110d ago |
| CVE-2026-31070 | 9.8 | — | — | — | — | The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate pr | 110d ago |
| CVE-2026-30118 | 9.8 | — | — | — | — | scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parame | 110d ago |
| CVE-2026-30117 | 9.8 | — | — | — | — | scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query | 110d ago |
| CVE-2026-44159 | 9.8 | — | — | — | — | Tyler Identity Local (TID-L) uses documented, default administrative credentials. | 110d ago |
| CVE-2026-8956 | 9.8 | — | — | — | mozilla / firefox | Integer overflow in the Networking: JAR component. | 110d ago |
| CVE-2026-47323 | 9.8 | — | — | — | apache / camel | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilte | 110d ago |
| CVE-2026-4883 | 9.8 | — | — | — | — | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation i | 110d ago |
| CVE-2026-43493 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG r | 110d ago |
| CVE-2026-45434 | 9.8 | — | — | — | apache / ofbiz | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execut | 110d ago |
| CVE-2026-4885 | 9.8 | — | — | — | — | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing fil | 110d ago |
| CVE-2026-8838 | 9.8 | — | — | — | — | Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver | 110d ago |
| CVE-2026-25244 | 9.8 | — | — | — | openjsf / webdriverio | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and | 110d ago |
| CVE-2026-8836 | 9.8 | — | — | — | — | A vulnerability was found in lwIP up to 2.2.1. | 110d ago |
| CVE-2026-7304 | 9.8 | — | — | — | lmsys / sglang | SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-cust | 111d ago |
| CVE-2026-7301 | 9.8 | — | — | — | lmsys / sglang | SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink tha | 111d ago |
| CVE-2026-8721 | 9.8 | — | — | — | — | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. | 111d ago |
| CVE-2026-8507 | 9.8 | — | — | — | — | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. | 111d ago |
| CVE-2018-25335 | 9.8 | — | — | — | — | WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated att | 112d ago |
| CVE-2018-25332 | 9.8 | — | — | — | gitbucket / gitbucket | GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute | 112d ago |
| CVE-2018-25320 | 9.8 | — | — | — | — | ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attac | 112d ago |
| CVE-2021-47952 | 9.8 | — | — | — | — | python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary | 113d ago |
| CVE-2020-37239 | 9.8 | — | — | — | — | libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety | 113d ago |
| CVE-2020-37228 | 9.8 | — | — | — | — | iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to b | 113d ago |
| CVE-2026-46364 | 9.8 | — | — | — | — | phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector( | 113d ago |
| CVE-2021-47965 | 9.8 | — | — | — | — | WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKedit | 113d ago |