| CVE-2026-23652 | 10 | — | — | — | microsoft / power pages | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allow | 139d ago |
| CVE-2026-33712 | 10 | — | — | — | — | Typebot is a chatbot builder tool. | 139d ago |
| CVE-2026-46595 | 10 | — | — | — | golang / crypto | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type | 139d ago |
| CVE-2026-34910exploited | 10 | 45.8% | 3/3 | +18d | ui / unifi os server | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni | 139d ago |
| CVE-2026-34909exploited | 10 | 1.8% | 3/3 | +18d | ui / unifi os server | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS device | 139d ago |
| CVE-2026-34908exploited | 10 | 15.2% | 3/3 | +18d | ui / unifi os server | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi | 139d ago |
| CVE-2026-45444zero day | 10 | 0.52% | 1/3 | same day | — | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows U | 141d ago |
| CVE-2026-20223 | 10 | — | — | — | cisco / secure workload | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauth | 141d ago |
| CVE-2026-42960 | 10 | — | — | — | nlnetlabs / unbound | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the a | 141d ago |
| CVE-2026-34234zero day | 10 | 4.5% | 1/3 | same day | — | CtrlPanel is open-source billing software for hosting providers. | 142d ago |
| CVE-2026-43633 | 10 | — | — | — | — | HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused | 142d ago |
| CVE-2026-42822 | 10 | — | — | — | microsoft / azure local | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileg | 143d ago |
| CVE-2026-45829 | 10 | — | — | — | — | A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows | 143d ago |
| CVE-2026-41553 | 10 | — | — | — | dhtmlx / pdf export module | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack | 146d ago |
| CVE-2026-44523 | 10 | — | — | — | — | Note Mark is an open-source note-taking application. | 147d ago |
| CVE-2026-20182zero day | 10 | 91.5% | 3/3 | same day | cisco / catalyst sd-wan manager | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered | 147d ago |
| CVE-2026-44006 | 10 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 148d ago |
| CVE-2026-44005 | 10 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 148d ago |
| CVE-2026-43997 | 10 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 148d ago |
| CVE-2026-42288 | 10 | — | — | — | — | ChurchCRM is an open-source church management system. | 149d ago |
| CVE-2026-42869 | 10 | — | — | — | — | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. | 150d ago |
| CVE-2026-44643 | 10 | — | — | — | peerigon / angular-expressions | Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. | 150d ago |
| CVE-2026-4725 | 10 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. | 198d ago |
| CVE-2026-4692 | 10 | — | — | — | mozilla / firefox | Sandbox escape in the Responsive Design Mode component. | 198d ago |
| CVE-2026-4689 | 10 | — | — | — | mozilla / firefox | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | 198d ago |
| CVE-2026-4688 | 10 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 198d ago |
| CVE-2026-33478exploited | 10 | 11.2% | 1/3 | +38d | wwbn / avideo | WWBN AVideo is an open source video platform. | 199d ago |
| CVE-2026-3587 | 10 | — | — | — | — | An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interfa | 199d ago |
| CVE-2026-33054 | 10 | — | — | — | mesop-dev / mesop | Mesop is a Python-based UI framework that allows users to build web applications. | 202d ago |
| CVE-2026-32169 | 10 | — | — | — | microsoft / azure cloud shell | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over | 203d ago |
| CVE-2026-30836 | 10 | — | — | — | smallstep / step-ca | Step CA is an online certificate authority for secure, automated certificate management for DevOps. | 203d ago |
| CVE-2026-22557 | 10 | — | — | — | — | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Netwo | 203d ago |
| CVE-2026-32737 | 10 | — | — | — | ctfer-io / romeo | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for fu | 204d ago |
| CVE-2026-26954 | 10 | — | — | — | nyariv / sandboxjs | SandboxJS is a JavaScript sandboxing library. | 209d ago |
| CVE-2026-3611 | 10 | — | — | — | honeywell / iq4e firmware | The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its fac | 210d ago |
| CVE-2026-31957 | 10 | — | — | — | himmelblau-idm / himmelblau | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. | 211d ago |
| CVE-2026-31852 | 10 | — | — | — | jellyfin / jellyfin | Jellyfin is an open-source media system. | 211d ago |
| CVE-2026-27897 | 10 | — | — | — | wanderingastronomer / vociferous | Vociferous provides cross-platform, offline speech-to-text with local AI refinement. | 211d ago |
| CVE-2026-85223 | 9.9 | — | — | — | — | A vulnerability was found in D-Link DNS-340L 1.01B04. | 35d ago |
| CVE-2026-85031 | 9.9 | — | — | — | — | A vulnerability was found in TOTOLINK CP450 4.1.0. | 35d ago |
| CVE-2026-77009 | 9.9 | — | — | — | — | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which execute | 36d ago |
| CVE-2026-83772 | 9.9 | — | — | — | — | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. | 37d ago |
| CVE-2026-83524 | 9.9 | — | — | — | — | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 u | 38d ago |
| CVE-2026-82954 | 9.9 | — | — | — | — | A vulnerability was detected in Dokploy up to 0.29.7. | 38d ago |
| CVE-2026-79748 | 9.9 | — | — | — | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 38d ago |
| CVE-2026-82692 | 9.9 | — | — | — | — | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. | 38d ago |
| CVE-2026-82689 | 9.9 | — | — | — | — | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. | 38d ago |
| CVE-2026-82874 | 9.9 | — | — | — | — | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the or | 38d ago |
| CVE-2026-82616 | 9.9 | — | — | — | — | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. | 38d ago |
| CVE-2026-82593 | 9.9 | — | — | — | — | A flaw has been found in D-Link DIR-825M 1.1.8. | 38d ago |
| CVE-2026-82592 | 9.9 | — | — | — | — | A vulnerability was detected in D-Link DIR-825M 1.1.8. | 39d ago |
| CVE-2026-19295 | 9.9 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system comma | 41d ago |
| CVE-2026-18527 | 9.9 | — | — | — | — | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote atta | 41d ago |
| CVE-2026-55634 | 9.9 | — | — | — | — | Pimcore is an Open Source Data & Experience Management Platform. | 41d ago |
| CVE-2026-55565 | 9.9 | — | — | — | — | Yamcs is a mission control framework. | 41d ago |
| CVE-2026-77553 | 9.9 | — | — | — | — | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi | 43d ago |
| CVE-2026-77548 | 9.9 | — | — | — | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 43d ago |
| CVE-2026-77547 | 9.9 | — | — | — | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 43d ago |
| CVE-2026-77546 | 9.9 | — | — | — | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 43d ago |
| CVE-2026-77543 | 9.9 | — | — | — | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 43d ago |