| CVE-2026-44717 | 9.8 | — | — | — | — | MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. | 114d ago |
| CVE-2026-45772 | 9.8 | — | — | — | vercel / turborepo | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. | 114d ago |
| CVE-2026-8398zero day | 9.8 | 1.5% | 3/3 | 7d before | disc-soft / daemon tools | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0. | 114d ago |
| CVE-2026-5229 | 9.8 | — | — | — | — | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. | 114d ago |
| CVE-2026-26191 | 9.8 | — | — | — | fleetdm / fleet | Fleet is open source device management software. | 114d ago |
| CVE-2026-41315 | 9.8 | — | — | — | midoks / mdserver-web | mdserver-web is a simple Linux panel. | 114d ago |
| CVE-2026-42589exploited | 9.8 | 3.0% | 1/3 | +40d | thecodingmachine / gotenberg | Gotenberg is a Docker-powered stateless API for PDF files. | 115d ago |
| CVE-2026-44484 | 9.8 | — | — | — | lightningai / pytorch lightning | PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. | 115d ago |
| CVE-2026-2347 | 9.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. | 115d ago |
| CVE-2025-11024 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Comme | 115d ago |
| CVE-2026-6510 | 9.8 | — | — | — | — | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all vers | 115d ago |
| CVE-2026-6271 | 9.8 | — | — | — | — | The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including | 115d ago |
| CVE-2026-8181zero day | 9.8 | 14.6% | 1/3 | same day | — | The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is | 115d ago |
| CVE-2026-8500 | 9.8 | — | — | — | — | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. | 115d ago |
| CVE-2026-42031 | 9.8 | — | — | — | okfn / ckan | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. | 115d ago |
| CVE-2026-45411 | 9.8 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-44009 | 9.8 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-44008 | 9.8 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-0264 | 9.8 | — | — | — | paloaltonetworks / pan-os | A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software all | 115d ago |
| CVE-2026-0263 | 9.8 | — | — | — | paloaltonetworks / pan-os | A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenti | 115d ago |
| CVE-2020-37168 | 9.8 | — | — | — | — | Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute | 116d ago |
| CVE-2026-42062 | 9.8 | — | — | — | — | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. | 116d ago |
| CVE-2026-40621 | 9.8 | — | — | — | — | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. | 116d ago |
| CVE-2026-32661zero day | 9.8 | 0.47% | 1/3 | same day | — | Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (S | 116d ago |
| CVE-2026-42854 | 9.8 | — | — | — | espressif / arduino-esp32 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrolle | 116d ago |
| CVE-2026-45185 | 9.8 | — | — | — | exim / exim | Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body par | 116d ago |
| CVE-2026-44343 | 9.8 | — | — | — | wgdashboard / wgdashboard | WGDashboard is a dashboard for WireGuard VPN. | 116d ago |
| CVE-2026-44277 | 9.8 | — | — | — | fortinet / fortiauthenticator | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthe | 116d ago |
| CVE-2026-44183 | 9.8 | — | — | — | — | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported down | 116d ago |
| CVE-2026-41096 | 9.8 | — | — | — | microsoft / windows 11 23h2 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network | 116d ago |
| CVE-2026-41089exploited | 9.8 | 79.6% | 1/3 | +17d | microsoft / windows server 2012 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | 116d ago |
| CVE-2026-31239 | 9.8 | — | — | — | — | The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre | 116d ago |
| CVE-2026-31238 | 9.8 | — | — | — | — | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving componen | 116d ago |
| CVE-2026-31237 | 9.8 | — | — | — | — | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. | 116d ago |
| CVE-2026-31236 | 9.8 | — | — | — | — | The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line arg | 116d ago |
| CVE-2026-31235 | 9.8 | — | — | — | — | The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class | 116d ago |
| CVE-2026-31234 | 9.8 | — | — | — | — | Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server compon | 116d ago |
| CVE-2026-31233 | 9.8 | — | — | — | — | Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanis | 116d ago |
| CVE-2026-31231 | 9.8 | — | — | — | — | Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endp | 116d ago |
| CVE-2026-31230 | 9.8 | — | — | — | — | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in i | 116d ago |
| CVE-2026-31229 | 9.8 | — | — | — | — | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) | 116d ago |
| CVE-2026-26083 | 9.8 | — | — | — | fortinet / fortisandbox | A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4 | 116d ago |
| CVE-2026-43992 | 9.8 | — | — | — | — | JunoClaw is an agentic AI platform built on Juno Network. | 117d ago |
| CVE-2025-65719 | 9.8 | — | — | — | — | An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system vi | 117d ago |
| CVE-2026-43512 | 9.8 | — | — | — | apache / tomcat | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. | 117d ago |
| CVE-2026-41293 | 9.8 | — | — | — | apache / tomcat | Improper Input Validation vulnerability in Apache Tomcat. | 117d ago |
| CVE-2026-34187 | 9.8 | — | — | — | artica / pandora fms | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph co | 117d ago |
| CVE-2026-31228 | 9.8 | — | — | — | — | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflo | 117d ago |
| CVE-2026-31226 | 9.8 | — | — | — | — | The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command | 117d ago |
| CVE-2026-31220 | 9.8 | — | — | — | — | PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficie | 117d ago |
| CVE-2026-31217 | 9.8 | — | — | — | nebuly / optimate | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481 | 117d ago |
| CVE-2026-31214 | 9.8 | — | — | — | — | The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852c | 117d ago |
| CVE-2026-8401 | 9.8 | — | — | — | mozilla / firefox | Sandbox escape in the Profile Backup component. | 117d ago |
| CVE-2025-6577 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commer | 117d ago |
| CVE-2026-43995 | 9.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 117d ago |
| CVE-2026-38567 | 9.8 | — | — | — | — | HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. | 117d ago |
| CVE-2026-40636 | 9.8 | — | — | — | dell / elastic cloud storage | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-c | 118d ago |
| CVE-2021-47940 | 9.8 | — | — | — | — | WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that | 119d ago |
| CVE-2021-47936 | 9.8 | — | — | — | — | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arb | 119d ago |
| CVE-2021-47933 | 9.8 | — | — | — | — | WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers t | 119d ago |