| CVE-2026-32191 | 9.8 | — | — | — | microsoft / bing images | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Image | 170d ago |
| CVE-2026-3548 | 9.8 | — | — | — | wolfssl / wolfssl | Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer | 170d ago |
| CVE-2026-30694 | 9.8 | — | — | — | dedecms / dedecms | An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter c | 170d ago |
| CVE-2025-67114 | 9.8 | — | — | — | — | Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (Freedom | 170d ago |
| CVE-2025-67113 | 9.8 | — | — | — | — | OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmw | 170d ago |
| CVE-2025-67112 | 9.8 | — | — | — | — | Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE42 | 170d ago |
| CVE-2026-32865 | 9.8 | — | — | — | opexustech / ecase ecomplaint | OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when | 171d ago |
| CVE-2026-30402 | 9.8 | — | — | — | wgstart / wgcloud | An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection | 171d ago |
| CVE-2006-10003 | 9.8 | — | — | — | toddr / xml\ | XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. | 171d ago |
| CVE-2026-27065 | 9.8 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 171d ago |
| CVE-2025-60237 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag | 171d ago |
| CVE-2025-60233 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: | 171d ago |
| CVE-2026-27542zero day | 9.8 | 1.7% | 1/3 | 27d before | — | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. | 171d ago |
| CVE-2026-31972 | 9.8 | — | — | — | samtools / samtools | SAMtools is a program for reading, manipulating and writing bioinformatics file formats. | 171d ago |
| CVE-2026-25873 | 9.8 | — | — | — | — | OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that al | 171d ago |
| CVE-2026-30703 | 9.8 | — | — | — | — | A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW | 171d ago |
| CVE-2026-30702 | 9.8 | — | — | — | — | The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web | 171d ago |
| CVE-2026-29859 | 9.8 | — | — | — | aapanel / aapanel | An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading | 171d ago |
| CVE-2025-67830 | 9.8 | — | — | — | murasoftware / mura cms | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. | 171d ago |
| CVE-2025-67829 | 9.8 | — | — | — | murasoftware / mura cms | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. | 172d ago |
| CVE-2026-25449 | 9.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue | 172d ago |
| CVE-2026-27459 | 9.8 | — | — | — | pyopenssl / pyopenssl | pyOpenSSL is a Python wrapper around the OpenSSL library. | 172d ago |
| CVE-2026-21994 | 9.8 | — | — | — | oracle / okit | Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open So | 172d ago |
| CVE-2026-3207 | 9.8 | — | — | — | tibco / bpm enterprise | Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised acc | 172d ago |
| CVE-2026-4312 | 9.8 | — | — | — | dragonsoft / gcb\/fcb government financial cybersecurity configuration audit software | GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated | 173d ago |
| CVE-2025-69902 | 9.8 | — | — | — | — | A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attacker | 173d ago |
| CVE-2026-32267 | 9.8 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 173d ago |
| CVE-2026-28430 | 9.8 | — | — | — | chamilo / chamilo lms | Chamilo LMS is a learning management system. | 173d ago |
| CVE-2025-69809 | 9.8 | — | — | — | p2r3 / bareiron | A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary va | 173d ago |
| CVE-2026-4254 | 9.8 | — | — | — | tenda / ac8 firmware | A weakness has been identified in Tenda AC8 up to 16.03.50.11. | 173d ago |
| CVE-2026-4252 | 9.8 | — | — | — | tenda / ac8 firmware | A vulnerability was identified in Tenda AC8 16.03.50.11. | 173d ago |
| CVE-2025-62319 | 9.8 | — | — | — | hcltech / unica | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injectin | 174d ago |
| CVE-2026-4184 | 9.8 | — | — | — | dlink / dir-816 firmware | A vulnerability was detected in D-Link DIR-816 1.10CNB05. | 174d ago |
| CVE-2026-4183 | 9.8 | — | — | — | dlink / dir-816 firmware | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. | 174d ago |
| CVE-2026-4182 | 9.8 | — | — | — | dlink / dir-816 firmware | A weakness has been identified in D-Link DIR-816 1.10CNB05. | 174d ago |
| CVE-2026-4181 | 9.8 | — | — | — | dlink / dir-816 firmware | A security flaw has been discovered in D-Link DIR-816 1.10CNB05. | 174d ago |
| CVE-2026-4170 | 9.8 | — | — | — | — | A weakness has been identified in Topsec TopACM 3.0. | 174d ago |
| CVE-2026-4164 | 9.8 | — | — | — | — | A flaw has been found in Wavlink WL-WN578W2 221110. | 174d ago |
| CVE-2026-4163 | 9.8 | — | — | — | — | A vulnerability was detected in Wavlink WL-WN579A3 220323. | 174d ago |
| CVE-2026-32640 | 9.8 | — | — | — | danthedeckie / simpleeval | SimpleEval is a library for adding evaluatable expressions into python projects. | 174d ago |
| CVE-2026-20998 | 9.8 | — | — | — | samsung / smart switch | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authenticatio | 174d ago |
| CVE-2026-20997 | 9.8 | — | — | — | samsung / smart switch | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attacker | 174d ago |
| CVE-2025-69246 | 9.8 | — | — | — | raytha / raytha | Raytha CMS does not have any brute force protection mechanism implemented. | 174d ago |
| CVE-2025-15060 | 9.8 | — | — | — | — | claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. | 174d ago |
| CVE-2017-20224 | 9.8 | — | — | — | telesquare / sdt-cs3b1 firmware | Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unau | 174d ago |
| CVE-2017-20223 | 9.8 | — | — | — | telesquare / sdt-cs3b1 firmware | Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerabil | 174d ago |
| CVE-2016-20030 | 9.8 | — | — | — | — | ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discov | 174d ago |
| CVE-2016-20026 | 9.8 | — | — | — | — | ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthentic | 174d ago |
| CVE-2016-20024 | 9.8 | — | — | — | — | ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to es | 174d ago |
| CVE-2026-3891 | 9.8 | — | — | — | — | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability chec | 176d ago |
| CVE-2026-32746 | 9.8 | — | — | — | gnu / inetutils | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) subo | 176d ago |
| CVE-2026-32304 | 9.8 | — | — | — | locutus / locutus | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. | 176d ago |
| CVE-2026-31806 | 9.8 | — | — | — | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 176d ago |
| CVE-2026-25823 | 9.8 | — | — | — | — | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmw | 176d ago |
| CVE-2026-1668 | 9.8 | — | — | — | tp-link / omada sg2005p-pd firmware | The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead t | 176d ago |
| CVE-2026-32248 | 9.8 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 177d ago |
| CVE-2026-32232 | 9.8 | — | — | — | aisarlabs / zeptoclaw | ZeptoClaw is a personal AI assistant. | 177d ago |
| CVE-2026-26793 | 9.8 | — | — | — | gl-inet / ar300m16 firmware | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config functio | 177d ago |
| CVE-2025-70245 | 9.8 | — | — | — | dlink / dir-513 firmware | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelec | 177d ago |
| CVE-2026-28256 | 9.8 | — | — | — | trane / tracer sc\+ firmware | A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierg | 177d ago |