| CVE-2026-80671 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: perf sched: Fix register_pid() overflow, strcp | 9d ago |
| CVE-2026-16279 | 9.3 | — | — | — | — | An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through | 9d ago |
| CVE-2026-78288 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | 10d ago |
| CVE-2026-78260 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. | 10d ago |
| CVE-2026-32479 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. | 10d ago |
| CVE-2026-51106 | 9.3 | — | — | — | — | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/seria | 10d ago |
| CVE-2026-80554 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel pro | 10d ago |
| CVE-2026-80551 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains const | 10d ago |
| CVE-2026-32555 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | 12d ago |
| CVE-2026-32554 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | 12d ago |
| CVE-2026-32551 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions. | 13d ago |
| CVE-2026-74712 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_ | 14d ago |
| CVE-2026-62834 | 9.3 | — | — | — | microsoft / azure data factory | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate | 16d ago |
| CVE-2026-17422 | 9.3 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buff | 16d ago |
| CVE-2026-71428 | 9.3 | — | — | — | — | The unstructured library provides open-source components for ingesting and pre-processing images and text document | 16d ago |
| CVE-2026-68566 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | 17d ago |
| CVE-2026-66680 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | 17d ago |
| CVE-2026-66649 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | 17d ago |
| CVE-2026-66609 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | 17d ago |
| CVE-2026-66593 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | 17d ago |
| CVE-2026-66592 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | 17d ago |
| CVE-2025-15688 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | 17d ago |
| CVE-2026-16822 | 9.3 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server a | 17d ago |
| CVE-2026-66794 | 9.3 | — | — | — | — | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. | 17d ago |
| CVE-2026-47187 | 9.3 | — | — | — | — | SSHFS is a network filesystem client for connecting to SSH servers. | 17d ago |
| CVE-2026-73391 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | 17d ago |
| CVE-2026-73388 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | 17d ago |
| CVE-2026-73185 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | 17d ago |
| CVE-2026-73183 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | 17d ago |
| CVE-2026-71065 | 9.3 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-71037 | 9.3 | — | — | — | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70998 | 9.3 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70855 | 9.3 | — | — | — | — | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). | 18d ago |
| CVE-2026-70673 | 9.3 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62637 | 9.3 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62618 | 9.3 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62613 | 9.3 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-67921 | 9.3 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.ja | 18d ago |
| CVE-2026-75913 | 9.3 | — | — | — | — | CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability | 18d ago |
| CVE-2026-45118 | 9.3 | — | — | — | — | MyBB is free and open source forum software. | 18d ago |
| CVE-2026-74015 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | 18d ago |
| CVE-2026-73392 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | 18d ago |
| CVE-2026-73365 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | 18d ago |
| CVE-2026-73355 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | 18d ago |
| CVE-2026-73339 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | 18d ago |
| CVE-2026-73187 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | 18d ago |
| CVE-2026-75626 | 9.3 | — | — | — | — | SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners | 19d ago |
| CVE-2026-64849exploited | 9.3 | 16.4% | 3/3 | +1d | lfprojects / mlflow | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. | 19d ago |
| CVE-2026-55674 | 9.3 | — | — | — | — | Discourse is an open-source discussion platform. | 19d ago |
| CVE-2026-71566 | 9.3 | — | — | — | — | FakeFish handles incoming credentials by passing them down to scripts. | 19d ago |
| CVE-2026-74799 | 9.3 | — | — | — | — | SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authent | 20d ago |
| CVE-2026-74573 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one | 21d ago |
| CVE-2026-74568 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release | 21d ago |
| CVE-2026-74517 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling | 21d ago |
| CVE-2026-74439 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing d | 22d ago |
| CVE-2026-74310 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubufs only once v | 22d ago |
| CVE-2026-72495 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated requests to alloc | 22d ago |
| CVE-2026-72412 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_UNUSED pte bit | 22d ago |
| CVE-2026-72329 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci_dev LUT The P | 22d ago |
| CVE-2026-72291 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix unlikely race in try_get_locked | 22d ago |