| CVE-2026-71167 | 9.4 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-71166 | 9.4 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-62629 | 9.4 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-19478exploited | 9.4 | 5.8% | 1/3 | +2d | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0. | 19d ago |
| CVE-2026-72318 | 9.4 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: cifs: validate DFS referral string offsets par | 22d ago |
| CVE-2026-14525 | 9.4 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is v | 23d ago |
| CVE-2026-73653 | 9.4 | — | — | — | — | Vitest is a testing framework powered by Vite. | 23d ago |
| CVE-2026-73296 | 9.4 | — | — | — | — | Microsoft UFO open-source framework for intelligent automation across devices and platforms. | 24d ago |
| CVE-2026-50561 | 9.4 | — | — | — | — | Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. | 24d ago |
| CVE-2026-66147 | 9.4 | — | — | — | — | An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and e | 25d ago |
| CVE-2026-50516 | 9.4 | — | — | — | microsoft / azure kubernetes service | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker | 25d ago |
| CVE-2026-48088 | 9.4 | — | — | — | — | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. | 30d ago |
| CVE-2025-15039 | 9.4 | — | — | — | wso2 / api control plane | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all r | 31d ago |
| CVE-2026-15930 | 9.4 | — | — | — | — | The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registrati | 34d ago |
| CVE-2026-63221 | 9.4 | — | — | — | — | CodeIgniter is a PHP full-stack web framework. | 37d ago |
| CVE-2026-44100 | 9.4 | — | — | — | — | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. | 38d ago |
| CVE-2026-14529 | 9.4 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0 | 38d ago |
| CVE-2026-11841 | 9.4 | — | — | — | — | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine | 40d ago |
| CVE-2026-61203 | 9.4 | — | — | — | oracle / peoplesoft enterprise fin expenses | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). | 46d ago |
| CVE-2026-61186 | 9.4 | — | — | — | oracle / agile engineering data management | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). | 46d ago |
| CVE-2026-53595 | 9.4 | — | — | — | — | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. | 47d ago |
| CVE-2026-16242 | 9.4 | — | — | — | — | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. | 48d ago |
| CVE-2026-64024 | 9.4 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enablin | 48d ago |
| CVE-2026-63830 | 9.4 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transfo | 49d ago |
| CVE-2026-12693 | 9.4 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. | 50d ago |
| CVE-2026-52830 | 9.4 | — | — | — | — | fast-mcp-telegram is a Telegram MCP Server. | 65d ago |
| CVE-2026-50137 | 9.4 | — | — | — | budibase / budibase | Budibase is an open-source low-code platform. | 71d ago |
| CVE-2026-40702 | 9.4 | — | — | — | — | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. | 72d ago |
| CVE-2026-53131 | 9.4 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before | 73d ago |
| CVE-2026-56073 | 9.4 | — | — | — | — | Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers t | 78d ago |
| CVE-2026-49973 | 9.4 | — | — | — | — | Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated | 86d ago |
| CVE-2026-41448 | 9.4 | — | — | — | — | AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows una | 89d ago |
| CVE-2026-50208 | 9.4 | — | — | — | acer / connect m6e 5g firmware | High-risk TrustAllCerts routines disable standard TLS certificate validation. | 94d ago |
| CVE-2026-44326 | 9.4 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 101d ago |
| CVE-2026-44315 | 9.4 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 101d ago |
| CVE-2026-41948exploited | 9.4 | 7.4% | 1/3 | +106d | dify / dify | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate | 110d ago |
| CVE-2026-44592 | 9.4 | — | — | — | — | Gradient is a nix-based continuous integration system. | 114d ago |
| CVE-2026-42596 | 9.4 | — | — | — | thecodingmachine / gotenberg | Gotenberg is a Docker-powered stateless API for PDF files. | 114d ago |
| CVE-2026-44262 | 9.4 | — | — | — | — | Scramble generates API documentation for Laravel project. | 116d ago |
| CVE-2026-42882 | 9.4 | — | — | — | — | oxyno-zeta/s3-proxy is an aws s3 proxy written in go. | 117d ago |
| CVE-2026-42613 | 9.4 | — | — | — | — | Grav is a file-based Web platform. | 117d ago |
| CVE-2026-2298 | 9.4 | — | — | — | — | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Mark | 166d ago |
| CVE-2026-33716 | 9.4 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-4404 | 9.4 | — | — | — | linuxfoundation / harbor | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default pass | 166d ago |
| CVE-2026-29796 | 9.4 | — | — | — | igl / eparking.fi | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impe | 169d ago |
| CVE-2026-25192 | 9.4 | — | — | — | ctek / charge portal | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impe | 169d ago |
| CVE-2026-23941 | 9.4 | — | — | — | erlang / erlang\/inets | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd m | 176d ago |
| CVE-2026-80098 | 9.3 | — | — | — | — | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate priv | 2d ago |
| CVE-2026-84813 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | 2d ago |
| CVE-2026-84768 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | 2d ago |
| CVE-2026-85183 | 9.3 | — | — | — | — | Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page | 2d ago |
| CVE-2026-80726 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when | 2d ago |
| CVE-2026-81286 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | 4d ago |
| CVE-2026-81763 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | 5d ago |
| CVE-2026-81756 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | 5d ago |
| CVE-2026-81293 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | 5d ago |
| CVE-2026-59111 | 9.3 | — | — | — | — | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitá | 5d ago |
| CVE-2026-77012 | 9.3 | — | — | — | — | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticat | 8d ago |
| CVE-2026-80693 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: idpf: bound interrupt-vector register fill to | 9d ago |
| CVE-2026-80684 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV a | 9d ago |