| CVE-2026-71424 | 9.6 | — | — | — | — | Onyx is an open-source AI platform. | 19d ago |
| CVE-2026-73843 | 9.6 | — | — | — | — | OpenChoreo is a complete, open-source developer platform for Kubernetes. | 23d ago |
| CVE-2026-8715 | 9.6 | — | — | — | — | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue | 23d ago |
| CVE-2026-73644 | 9.6 | — | — | — | — | OpenDJ is an LDAPv3 compliant directory service. | 23d ago |
| CVE-2026-56443 | 9.6 | — | — | — | — | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after C | 23d ago |
| CVE-2026-71193 | 9.6 | — | — | — | — | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB | 24d ago |
| CVE-2026-49481 | 9.6 | — | — | — | — | UpSnap is a wake on lan web app. | 24d ago |
| CVE-2026-73300 | 9.6 | — | — | — | — | Budibase is an open-source low-code platform. | 24d ago |
| CVE-2026-17276 | 9.6 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper au | 24d ago |
| CVE-2026-70398 | 9.6 | — | — | — | — | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). | 25d ago |
| CVE-2026-73032 | 9.6 | — | — | — | — | PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitra | 25d ago |
| CVE-2026-47705 | 9.6 | — | — | — | — | TypeBot is a chatbot builder tool. | 25d ago |
| CVE-2026-71384 | 9.6 | — | — | — | adobe / coldfusion | is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. | 25d ago |
| CVE-2026-18972 | 9.6 | — | — | — | — | An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \" | 26d ago |
| CVE-2026-72878 | 9.6 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72877 | 9.6 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72737 | 9.6 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-68124 | 9.6 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to pre | 27d ago |
| CVE-2026-72564 | 9.6 | — | — | — | — | An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker | 27d ago |
| CVE-2026-46409 | 9.6 | — | — | — | — | OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. | 29d ago |
| CVE-2026-50540 | 9.6 | — | — | — | — | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (V | 29d ago |
| CVE-2026-70332 | 9.6 | — | — | — | microsoft / sharepoint online | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 30d ago |
| CVE-2026-62896 | 9.6 | — | — | — | microsoft / teams | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-56161 | 9.6 | — | — | — | microsoft / azure logic apps | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | 30d ago |
| CVE-2026-19175 | 9.6 | — | — | — | google / chrome | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perfo | 30d ago |
| CVE-2026-19171 | 9.6 | — | — | — | google / chrome | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potential | 30d ago |
| CVE-2026-19170 | 9.6 | — | — | — | google / chrome | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potential | 30d ago |
| CVE-2026-19166 | 9.6 | — | — | — | google / chrome | Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potenti | 30d ago |
| CVE-2026-19164 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote att | 30d ago |
| CVE-2026-19157 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to pote | 30d ago |
| CVE-2026-19149 | 9.6 | — | — | — | google / chrome | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially | 30d ago |
| CVE-2026-12605 | 9.6 | — | — | — | eclipse / glassfish | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `g | 31d ago |
| CVE-2026-71319 | 9.6 | — | — | — | — | Nuxt is an open-source web development framework for Vue.js. | 31d ago |
| CVE-2026-70376 | 9.6 | — | — | — | — | Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functio | 32d ago |
| CVE-2026-25289 | 9.6 | — | — | — | qualcomm / sm7550p firmware | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames wi | 32d ago |
| CVE-2026-48317 | 9.6 | — | — | — | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code | 33d ago |
| CVE-2026-18667 | 9.6 | — | — | — | — | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by induc | 33d ago |
| CVE-2026-68579 | 9.6 | — | — | — | — | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrS | 35d ago |
| CVE-2026-54725 | 9.6 | — | — | — | — | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. | 36d ago |
| CVE-2026-17349 | 9.6 | — | — | — | pgadmin / pgadmin 4 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the | 36d ago |
| CVE-2026-18015 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to p | 38d ago |
| CVE-2026-18002 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote | 38d ago |
| CVE-2026-17991 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | 38d ago |
| CVE-2026-17990 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote at | 38d ago |
| CVE-2026-17987 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remo | 38d ago |
| CVE-2026-17947 | 9.6 | — | — | — | google / chrome | Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perf | 38d ago |
| CVE-2026-17940 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.7 | 38d ago |
| CVE-2026-17924 | 9.6 | — | — | — | google / chrome | Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re | 38d ago |
| CVE-2026-17865 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker wh | 38d ago |
| CVE-2026-17856 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker w | 38d ago |
| CVE-2026-17855 | 9.6 | — | — | — | google / chrome | Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17848 | 9.6 | — | — | — | google / chrome | Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perfor | 38d ago |
| CVE-2026-17847 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attac | 38d ago |
| CVE-2026-17837 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote at | 38d ago |
| CVE-2026-17834 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote a | 38d ago |
| CVE-2026-17832 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17804 | 9.6 | — | — | — | google / chrome | Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17803 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remo | 38d ago |
| CVE-2026-17801 | 9.6 | — | — | — | google / chrome | Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti | 38d ago |
| CVE-2026-17768 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote | 38d ago |