| CVE-2024-27892 | 9.6 | — | — | — | — | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should hav | 93d ago |
| CVE-2024-27890 | 9.6 | — | — | — | — | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should hav | 93d ago |
| CVE-2026-35906 | 9.6 | — | — | — | — | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthentica | 93d ago |
| CVE-2026-8037exploited | 9.6 | 99.6% | 3/3 | +27d | progress / connection manager for objectscale | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated | 93d ago |
| CVE-2026-5241 | 9.6 | — | — | — | huggingface / transformers | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-co | 94d ago |
| CVE-2026-32625 | 9.6 | — | — | — | librechat / librechat | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. | 95d ago |
| CVE-2026-44211 | 9.6 | — | — | — | cline / cline | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. | 96d ago |
| CVE-2026-48866 | 9.6 | — | — | — | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. | 96d ago |
| CVE-2026-45628 | 9.6 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 99d ago |
| CVE-2026-9967 | 9.6 | — | — | — | google / chrome | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perfor | 100d ago |
| CVE-2026-9918 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentia | 100d ago |
| CVE-2026-9886 | 9.6 | — | — | — | google / chrome | Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially per | 100d ago |
| CVE-2026-9876 | 9.6 | — | — | — | google / chrome | Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentiall | 100d ago |
| CVE-2026-9875 | 9.6 | — | — | — | google / chrome | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potent | 100d ago |
| CVE-2026-9874 | 9.6 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a | 100d ago |
| CVE-2026-9872 | 9.6 | — | — | — | google / chrome | Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potenti | 100d ago |
| CVE-2026-45374 | 9.6 | — | — | — | — | CodeWhale is a DeepSeek + MiMo coding agent in terminal. | 100d ago |
| CVE-2026-45323 | 9.6 | — | — | — | jpettitt / meshcore card | MeshCore Card provides MeshCore Lovelace card for Home Assistant. | 100d ago |
| CVE-2026-45311 | 9.6 | — | — | — | — | CodeWhale is a DeepSeek + MiMo coding agent in terminal. | 100d ago |
| CVE-2026-45570 | 9.6 | — | — | — | go-git project / go-git | go-git is an extensible git implementation library written in pure Go. | 101d ago |
| CVE-2026-44985 | 9.6 | — | — | — | amirraminfar / dozzle | Dozzle is a realtime log viewer for docker containers. | 102d ago |
| CVE-2026-39821 | 9.6 | — | — | — | golang / net | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. | 106d ago |
| CVE-2026-8670 | 9.6 | — | — | — | avantra / avantra | Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Sessi | 106d ago |
| CVE-2026-2587 | 9.6 | — | — | — | eclipse / glassfish | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism | 109d ago |
| CVE-2026-8959 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. | 109d ago |
| CVE-2026-8953 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 109d ago |
| CVE-2026-2611 | 9.6 | — | — | — | lfprojects / mlflow | In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoi | 110d ago |
| CVE-2026-8580 | 9.6 | — | — | — | google / chrome | Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a | 114d ago |
| CVE-2026-8511 | 9.6 | — | — | — | google / chrome | Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sa | 114d ago |
| CVE-2026-41615 | 9.6 | — | — | — | microsoft / authenticator | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attac | 114d ago |
| CVE-2026-44482 | 9.6 | — | — | — | — | soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. | 114d ago |
| CVE-2026-42557 | 9.6 | — | — | — | jupyter / jupyterlab | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook | 115d ago |
| CVE-2026-44547 | 9.6 | — | — | — | — | ChurchCRM is an open-source church management system. | 116d ago |
| CVE-2026-34659 | 9.6 | — | — | — | adobe / connect desktop application | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulne | 116d ago |
| CVE-2026-42048 | 9.6 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 116d ago |
| CVE-2026-8043 | 9.6 | — | — | — | ivanti / xtraction | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to | 116d ago |
| CVE-2026-34263 | 9.6 | — | — | — | — | Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malici | 117d ago |
| CVE-2026-34260 | 9.6 | — | — | — | — | SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated a | 117d ago |
| CVE-2026-45321exploited | 9.6 | 2.3% | 3/3 | +15d | tanstack / tanstack\/arktype-adapter | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages wer | 117d ago |
| CVE-2026-43899 | 9.6 | — | — | — | — | DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. | 117d ago |
| CVE-2026-33334 | 9.6 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-33211 | 9.6 | — | — | — | linuxfoundation / tekton pipelines | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. | 166d ago |
| CVE-2026-21732 | 9.6 | — | — | — | imaginationtech / ddk | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write o | 169d ago |
| CVE-2026-32890 | 9.6 | — | — | — | openvessl / anchorr | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a | 170d ago |
| CVE-2026-30924 | 9.6 | — | — | — | getqui / qui | qui is a web interface for managing qBittorrent instances. | 170d ago |
| CVE-2026-31938 | 9.6 | — | — | — | parall / jspdf | jsPDF is a library to generate PDFs in JavaScript. | 172d ago |
| CVE-2026-30884 | 9.6 | — | — | — | — | mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete c | 172d ago |
| CVE-2026-32626 | 9.6 | — | — | — | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 173d ago |
| CVE-2026-28792 | 9.6 | — | — | — | ssw / tinacms\/cli | Tina is a headless content management system. | 177d ago |
| CVE-2026-3916 | 9.6 | — | — | — | google / chrome | Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially p | 178d ago |
| CVE-2026-85695 | 9.4 | — | — | — | — | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthentica | 1d ago |
| CVE-2026-59270 | 9.4 | — | — | — | vmware / spring security | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative | 10d ago |
| CVE-2026-80585 | 9.4 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with | 10d ago |
| CVE-2026-74751 | 9.4 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count | 10d ago |
| CVE-2026-78207 | 9.4 | — | — | — | — | exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __ | 13d ago |
| CVE-2026-76312 | 9.4 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the H | 17d ago |
| CVE-2026-76311 | 9.4 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedde | 17d ago |
| CVE-2026-76310 | 9.4 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedde | 17d ago |
| CVE-2026-16839 | 9.4 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to | 17d ago |
| CVE-2026-73920 | 9.4 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |