| CVE-2026-23652 | 10 | critical | microsoft / power pages | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allow | 106d ago |
| CVE-2026-33712 | 10 | critical | — | Typebot is a chatbot builder tool. | 106d ago |
| CVE-2026-46595 | 10 | critical | golang / crypto | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type | 107d ago |
| CVE-2026-34910exploited | 10 | critical | ui / unifi os server | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni | 107d ago |
| CVE-2026-34909exploited | 10 | critical | ui / unifi os server | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS device | 107d ago |
| CVE-2026-34908exploited | 10 | critical | ui / unifi os server | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi | 107d ago |
| CVE-2026-45444 | 10 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows U | 108d ago |
| CVE-2026-20223 | 10 | critical | cisco / secure workload | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauth | 108d ago |
| CVE-2026-42960 | 10 | critical | nlnetlabs / unbound | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the a | 108d ago |
| CVE-2026-34234 | 10 | critical | — | CtrlPanel is open-source billing software for hosting providers. | 109d ago |
| CVE-2026-43633 | 10 | critical | — | HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused | 109d ago |
| CVE-2026-42822 | 10 | critical | microsoft / azure local | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileg | 110d ago |
| CVE-2026-45829 | 10 | critical | — | A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows | 110d ago |
| CVE-2026-41553 | 10 | critical | dhtmlx / pdf export module | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack | 113d ago |
| CVE-2026-44523 | 10 | critical | — | Note Mark is an open-source note-taking application. | 114d ago |
| CVE-2026-20182exploited | 10 | critical | cisco / catalyst sd-wan manager | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered | 114d ago |
| CVE-2026-44006 | 10 | critical | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-44005 | 10 | critical | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-43997 | 10 | critical | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-42288 | 10 | critical | — | ChurchCRM is an open-source church management system. | 116d ago |
| CVE-2026-42869 | 10 | critical | — | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. | 117d ago |
| CVE-2026-44643 | 10 | critical | peerigon / angular-expressions | Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. | 117d ago |
| CVE-2026-4725 | 10 | critical | mozilla / firefox | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. | 165d ago |
| CVE-2026-4692 | 10 | critical | mozilla / firefox | Sandbox escape in the Responsive Design Mode component. | 165d ago |
| CVE-2026-4689 | 10 | critical | mozilla / firefox | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | 165d ago |
| CVE-2026-4688 | 10 | critical | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 165d ago |
| CVE-2026-33478 | 10 | critical | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-3587 | 10 | critical | — | An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interfa | 166d ago |
| CVE-2026-33054 | 10 | critical | mesop-dev / mesop | Mesop is a Python-based UI framework that allows users to build web applications. | 169d ago |
| CVE-2026-32169 | 10 | critical | microsoft / azure cloud shell | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over | 170d ago |
| CVE-2026-30836 | 10 | critical | smallstep / step-ca | Step CA is an online certificate authority for secure, automated certificate management for DevOps. | 170d ago |
| CVE-2026-22557 | 10 | critical | — | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Netwo | 170d ago |
| CVE-2026-32737 | 10 | critical | ctfer-io / romeo | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for fu | 171d ago |
| CVE-2026-26954 | 10 | critical | nyariv / sandboxjs | SandboxJS is a JavaScript sandboxing library. | 176d ago |
| CVE-2026-3611 | 10 | critical | honeywell / iq4e firmware | The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its fac | 177d ago |
| CVE-2026-31957 | 10 | critical | himmelblau-idm / himmelblau | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. | 178d ago |
| CVE-2026-31852 | 10 | critical | jellyfin / jellyfin | Jellyfin is an open-source media system. | 178d ago |
| CVE-2026-27897 | 10 | critical | wanderingastronomer / vociferous | Vociferous provides cross-platform, offline speech-to-text with local AI refinement. | 178d ago |
| CVE-2026-85223 | 9.9 | critical | — | A vulnerability was found in D-Link DNS-340L 1.01B04. | 2d ago |
| CVE-2026-85031 | 9.9 | critical | — | A vulnerability was found in TOTOLINK CP450 4.1.0. | 2d ago |
| CVE-2026-77009 | 9.9 | critical | — | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which execute | 3d ago |
| CVE-2026-83772 | 9.9 | critical | — | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. | 4d ago |
| CVE-2026-83524 | 9.9 | critical | — | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 u | 5d ago |
| CVE-2026-82954 | 9.9 | critical | — | A vulnerability was detected in Dokploy up to 0.29.7. | 5d ago |
| CVE-2026-79748 | 9.9 | critical | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 5d ago |
| CVE-2026-82692 | 9.9 | critical | — | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. | 5d ago |
| CVE-2026-82689 | 9.9 | critical | — | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. | 5d ago |
| CVE-2026-82874 | 9.9 | critical | — | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the or | 5d ago |
| CVE-2026-82616 | 9.9 | critical | — | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. | 5d ago |
| CVE-2026-82593 | 9.9 | critical | — | A flaw has been found in D-Link DIR-825M 1.1.8. | 6d ago |
| CVE-2026-82592 | 9.9 | critical | — | A vulnerability was detected in D-Link DIR-825M 1.1.8. | 6d ago |
| CVE-2026-19295 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system comma | 8d ago |
| CVE-2026-18527 | 9.9 | critical | — | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote atta | 8d ago |
| CVE-2026-55634 | 9.9 | critical | — | Pimcore is an Open Source Data & Experience Management Platform. | 8d ago |
| CVE-2026-55565 | 9.9 | critical | — | Yamcs is a mission control framework. | 8d ago |
| CVE-2026-77553 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi | 10d ago |
| CVE-2026-77548 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 10d ago |
| CVE-2026-77547 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 10d ago |
| CVE-2026-77546 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 10d ago |
| CVE-2026-77543 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 10d ago |