| CVE-2021-47932 | 9.8 | — | — | — | — | WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attacker | 119d ago |
| CVE-2021-47923 | 9.8 | — | — | — | — | OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by inject | 119d ago |
| CVE-2026-7261 | 9.8 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapSer | 119d ago |
| CVE-2026-6722 | 9.8 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP ext | 119d ago |
| CVE-2025-14179 | 9.8 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Fir | 119d ago |
| CVE-2026-4729 | 9.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox 148 and Thunderbird 148. | 166d ago |
| CVE-2026-4723 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the JavaScript Engine component. | 166d ago |
| CVE-2026-4721 | 9.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunder | 166d ago |
| CVE-2026-4720 | 9.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. | 166d ago |
| CVE-2026-4717 | 9.8 | — | — | — | mozilla / firefox | Privilege escalation in the Netmonitor component. | 166d ago |
| CVE-2026-4711 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the Widget: Cocoa component. | 166d ago |
| CVE-2026-4710 | 9.8 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video component. | 166d ago |
| CVE-2026-4705 | 9.8 | — | — | — | mozilla / firefox | Undefined behavior in the WebRTC: Signaling component. | 166d ago |
| CVE-2026-4702 | 9.8 | — | — | — | mozilla / firefox | JIT miscompilation in the JavaScript Engine component. | 166d ago |
| CVE-2026-4701 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the JavaScript Engine component. | 166d ago |
| CVE-2026-4700 | 9.8 | — | — | — | mozilla / firefox | Mitigation bypass in the Networking: HTTP component. | 166d ago |
| CVE-2026-4698 | 9.8 | — | — | — | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 166d ago |
| CVE-2026-4696 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the Layout: Text and Fonts component. | 166d ago |
| CVE-2026-4691 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the CSS Parsing and Computation component. | 166d ago |
| CVE-2019-25646 | 9.8 | — | — | — | tabslab / mailcarrier | Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote | 166d ago |
| CVE-2019-25628 | 9.8 | — | — | — | — | Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that | 166d ago |
| CVE-2026-4755 | 9.8 | — | — | — | molotovcherry / android-imagemagick7 | CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11 | 166d ago |
| CVE-2026-4001zero day | 9.8 | 0.71% | 1/3 | same day | — | The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versio | 166d ago |
| CVE-2026-33195 | 9.8 | — | — | — | rubyonrails / rails | Active Storage allows users to attach cloud and local files in Rails applications. | 166d ago |
| CVE-2026-3055exploited | 9.8 | 87.2% | 3/3 | +6d | citrix / netscaler application delivery controller | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memor | 166d ago |
| CVE-2026-30849 | 9.8 | — | — | — | mantisbt / mantisbt | Mantis Bug Tracker (MantisBT) is an open source issue tracker. | 166d ago |
| CVE-2026-33352 | 9.8 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 167d ago |
| CVE-2026-31851 | 9.8 | — | — | — | nexxtsolutions / nebula300plus firmware | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account locko | 167d ago |
| CVE-2026-31848 | 9.8 | — | — | — | nexxtsolutions / nebula300plus firmware | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which | 167d ago |
| CVE-2026-4585 | 9.8 | — | — | — | — | A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. | 167d ago |
| CVE-2026-32968 | 9.8 | — | — | — | — | Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker c | 167d ago |
| CVE-2026-4567 | 9.8 | — | — | — | tenda / a15 firmware | A vulnerability has been found in Tenda A15 15.13.07.13. | 167d ago |
| CVE-2019-25614 | 9.8 | — | — | — | freefloat / freefloat ftp server | Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attacke | 168d ago |
| CVE-2019-25568 | 9.8 | — | — | — | microvirt / memu | Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate pr | 169d ago |
| CVE-2026-33228 | 9.8 | — | — | — | webreflection / flatted | flatted is a circular JSON parser. | 169d ago |
| CVE-2026-3584zero day | 9.8 | 7.2% | 1/3 | same day | — | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2. | 169d ago |
| CVE-2026-22901 | 9.8 | — | — | — | qnap / qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2026-22900 | 9.8 | — | — | — | qnap / qunetswitch | A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2026-22898 | 9.8 | — | — | — | qnap / qvr pro | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. | 169d ago |
| CVE-2026-22897 | 9.8 | — | — | — | qnap / qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2025-15608 | 9.8 | — | — | — | tp-link / archer ax53 firmware | This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe handling logic, w | 169d ago |
| CVE-2025-15607 | 9.8 | — | — | — | tp-link / archer ax53 firmware | A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling | 169d ago |
| CVE-2024-44722 | 9.8 | — | — | — | anolis / sysak | SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd. | 170d ago |
| CVE-2026-33057 | 9.8 | — | — | — | mesop-dev / mesop | Mesop is a Python-based UI framework that allows users to build web applications. | 170d ago |
| CVE-2026-33017zero day | 9.8 | 96.2% | 3/3 | 1d before | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 170d ago |
| CVE-2026-4038 | 9.8 | — | — | — | — | The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation | 170d ago |
| CVE-2026-32945 | 9.8 | — | — | — | pjsip / pjsip | PJSIP is a free and open source multimedia communication library written in C. | 170d ago |
| CVE-2026-21992 | 9.8 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and | 170d ago |
| CVE-2026-32771 | 9.8 | — | — | — | ctfer / monitoring | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. | 170d ago |
| CVE-2026-32769 | 9.8 | — | — | — | ctfer / fullchain | Fullchain is an umbrella project for deploying a ready-to-use CTF platform. | 170d ago |
| CVE-2026-32767 | 9.8 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 170d ago |
| CVE-2026-32985 | 9.8 | — | — | — | apereo / xerte online toolkits | Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in | 170d ago |
| CVE-2026-32760 | 9.8 | — | — | — | filebrowser / filebrowser | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within | 170d ago |
| CVE-2026-32194 | 9.8 | — | — | — | microsoft / bing images | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allow | 170d ago |
| CVE-2026-32038 | 9.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators | 170d ago |
| CVE-2026-30872 | 9.8 | — | — | — | openwrt / openwrt | OpenWrt Project is a Linux operating system targeting embedded devices. | 170d ago |
| CVE-2026-30871 | 9.8 | — | — | — | openwrt / openwrt | OpenWrt Project is a Linux operating system targeting embedded devices. | 170d ago |
| CVE-2026-4395 | 9.8 | — | — | — | wolfssl / wolfssl | Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remo | 170d ago |
| CVE-2026-3849 | 9.8 | — | — | — | wolfssl / wolfssl | Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. | 170d ago |
| CVE-2026-3549 | 9.8 | — | — | — | wolfssl / wolfssl | Heap Overflow in TLS 1.3 ECH parsing. | 170d ago |