| CVE-2026-28255 | 9.8 | — | — | — | trane / tracer sc firmware | A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an | 177d ago |
| CVE-2026-28252 | 9.8 | — | — | — | trane / tracer sc firmware | A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concie | 177d ago |
| CVE-2026-26795 | 9.8 | — | — | — | gl-inet / ar300m16 firmware | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter i | 177d ago |
| CVE-2026-26792 | 9.8 | — | — | — | gl-inet / ar300m16 firmware | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrad | 177d ago |
| CVE-2026-26791 | 9.8 | — | — | — | gl-inet / ar300m16 firmware | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parame | 177d ago |
| CVE-2026-3060 | 9.8 | — | — | — | lmsys / sglang | SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the d | 178d ago |
| CVE-2026-3059 | 9.8 | — | — | — | lmsys / sglang | SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker | 178d ago |
| CVE-2025-59388 | 9.8 | — | — | — | qnap / hyper data protector | A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. | 178d ago |
| CVE-2026-32136 | 9.8 | — | — | — | adguard / adguardhome | AdGuard Home is a network-wide software for blocking ads and tracking. | 178d ago |
| CVE-2025-70041 | 9.8 | — | — | — | — | An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master. | 178d ago |
| CVE-2025-70024 | 9.8 | — | — | — | — | An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered i | 178d ago |
| CVE-2026-31976 | 9.8 | — | — | — | xygeni / xygeni-action | xygeni-action is the GitHub Action for Xygeni Scanner. | 178d ago |
| CVE-2026-31900 | 9.8 | — | — | — | python / black | Black is the uncompromising Python code formatter. | 178d ago |
| CVE-2026-31896 | 9.8 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 178d ago |
| CVE-2026-31877 | 9.8 | — | — | — | frappe / frappe | Frappe is a full-stack web application framework. | 178d ago |
| CVE-2026-31874 | 9.8 | — | — | — | taskosaur / taskosaur | Taskosaur is an open source project management platform with conversational AI for task execution in-app. | 178d ago |
| CVE-2019-25487 | 9.8 | — | — | — | — | SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to | 178d ago |
| CVE-2019-25471 | 9.8 | — | — | — | leefish / file thingie | FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files | 178d ago |
| CVE-2019-25468 | 9.8 | — | — | — | — | NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to ex | 178d ago |
| CVE-2018-25159 | 9.8 | — | — | — | — | Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerabil | 178d ago |
| CVE-2026-31975 | 9.8 | — | — | — | cloudcli / cloud cli | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. | 178d ago |
| CVE-2026-31871 | 9.8 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 178d ago |
| CVE-2026-31856 | 9.8 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 178d ago |
| CVE-2026-31840 | 9.8 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 178d ago |
| CVE-2026-1524 | 9.8 | — | — | — | neo4j / neo4j | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unautho | 178d ago |
| CVE-2025-67039 | 9.8 | — | — | — | lantronix / eds3016ps1ns firmware | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. | 178d ago |
| CVE-2025-67038exploited | 9.8 | 22.0% | 3/3 | +104d | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 178d ago |
| CVE-2026-30741 | 9.8 | — | — | — | openclaw / openclaw | A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbit | 178d ago |
| CVE-2026-28229 | 9.8 | — | — | — | argoproj / argo workflows | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. | 178d ago |
| CVE-2026-75925 | 9.6 | — | — | — | — | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute co | 1d ago |
| CVE-2026-19274 | 9.6 | — | — | — | — | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an aut | 1d ago |
| CVE-2026-85085 | 9.6 | — | — | — | — | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. | 2d ago |
| CVE-2026-85050 | 9.6 | — | — | — | — | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to ex | 2d ago |
| CVE-2026-85047 | 9.6 | — | — | — | — | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a rem | 2d ago |
| CVE-2026-85042 | 9.6 | — | — | — | — | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary | 2d ago |
| CVE-2026-53649 | 9.6 | — | — | — | — | Joro is a web exploitation framework. | 3d ago |
| CVE-2026-84354 | 9.6 | — | — | — | google / chrome | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging | 4d ago |
| CVE-2026-84353 | 9.6 | — | — | — | — | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacke | 4d ago |
| CVE-2026-84352 | 9.6 | — | — | — | — | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute | 4d ago |
| CVE-2026-84333 | 9.6 | — | — | — | — | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute | 4d ago |
| CVE-2026-19766 | 9.6 | — | — | — | arubanetworks / fabric composer | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer | 4d ago |
| CVE-2026-84121 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the DOM: Security component. | 5d ago |
| CVE-2026-84119 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the DOM: Navigation component. | 5d ago |
| CVE-2026-53552 | 9.6 | — | — | — | — | Goploy is an open-source automation deployment system. | 5d ago |
| CVE-2026-49003 | 9.6 | — | — | — | — | Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitorin | 6d ago |
| CVE-2026-82870 | 9.6 | — | — | — | — | ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing | 6d ago |
| CVE-2026-54755 | 9.6 | — | — | — | — | Klever-Go is the Go implementation of the Klever blockchain protocol. | 8d ago |
| CVE-2026-54754 | 9.6 | — | — | — | — | Klever-Go is the Go implementation of the Klever blockchain protocol. | 8d ago |
| CVE-2026-59354 | 9.6 | — | — | — | vmware / spring security | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Regis | 10d ago |
| CVE-2026-77016 | 9.6 | — | — | — | — | The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate | 10d ago |
| CVE-2026-54523 | 9.6 | — | — | — | — | Kyverno is a policy engine designed for cloud native platform engineering teams. | 11d ago |
| CVE-2026-77532 | 9.6 | — | — | — | — | A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCP | 11d ago |
| CVE-2026-79290 | 9.6 | — | — | — | google / chrome | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code | 11d ago |
| CVE-2026-79282 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute | 11d ago |
| CVE-2026-79275 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary cod | 11d ago |
| CVE-2026-79257 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary cod | 11d ago |
| CVE-2026-79235 | 9.6 | — | — | — | google / chrome | Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary cod | 11d ago |
| CVE-2026-79232 | 9.6 | — | — | — | google / chrome | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar | 11d ago |
| CVE-2026-79200 | 9.6 | — | — | — | google / chrome | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code | 11d ago |
| CVE-2026-79189 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec | 11d ago |