| CVE-2026-72289 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still | 22d ago |
| CVE-2026-72288 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrup | 22d ago |
| CVE-2026-72278 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injec | 22d ago |
| CVE-2026-72277 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't | 22d ago |
| CVE-2026-72239 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setti | 22d ago |
| CVE-2026-72085 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubmitted command | 22d ago |
| CVE-2026-17181 | 9.3 | — | — | — | ibm / db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to | 22d ago |
| CVE-2026-66478 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | 23d ago |
| CVE-2026-66472 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | 23d ago |
| CVE-2026-66458 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | 23d ago |
| CVE-2026-66446 | 9.3 | — | — | — | — | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | 23d ago |
| CVE-2026-66436 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | 23d ago |
| CVE-2026-61969 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. | 23d ago |
| CVE-2026-61966 | 9.3 | — | — | — | — | Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. | 23d ago |
| CVE-2026-28142 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | 23d ago |
| CVE-2026-28001 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | 23d ago |
| CVE-2026-59507 | 9.3 | — | — | — | — | : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Con | 24d ago |
| CVE-2026-59506 | 9.3 | — | — | — | — | : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (d | 24d ago |
| CVE-2026-66659 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tabl | 25d ago |
| CVE-2026-73090 | 9.3 | — | — | — | — | PeerTube is an ActivityPub-federated video streaming platform. | 25d ago |
| CVE-2026-70306 | 9.3 | — | — | — | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 25d ago |
| CVE-2026-73080 | 9.3 | — | — | — | — | SeaweedFS is a distributed storage system. | 25d ago |
| CVE-2026-47754 | 9.3 | — | — | — | — | Metacat is data repository software that helps researchers preserve, share, and discover data. | 26d ago |
| CVE-2026-59118 | 9.3 | — | — | — | microsoft / power apps | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-18367 | 9.3 | — | — | — | — | A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for | 30d ago |
| CVE-2026-66447 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | 30d ago |
| CVE-2026-65546 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | 30d ago |
| CVE-2026-65520 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | 30d ago |
| CVE-2026-65508 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | 30d ago |
| CVE-2026-9195 | 9.3 | — | — | — | progress / marklogic server | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 all | 31d ago |
| CVE-2026-9273 | 9.3 | — | — | — | — | The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to passw | 32d ago |
| CVE-2026-15958 | 9.3 | — | — | — | — | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of | 33d ago |
| CVE-2026-66421 | 9.3 | — | — | — | tugcantopaloglu / openclaw agent dashboard | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attacke | 37d ago |
| CVE-2026-66418 | 9.3 | — | — | — | tugcantopaloglu / openclaw agent dashboard | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote | 37d ago |
| CVE-2026-11707 | 9.3 | — | — | — | ibm / websphere application server | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-s | 37d ago |
| CVE-2026-47876 | 9.3 | — | — | — | — | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. | 37d ago |
| CVE-2026-67426 | 9.3 | — | — | — | — | Flyto2 Core is an execution kernel for automation and AI-agent workflows. | 38d ago |
| CVE-2026-58155 | 9.3 | — | — | — | apache / traffic server | Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy by | 39d ago |
| CVE-2026-41920 | 9.3 | — | — | — | apache / traffic server | Improper Access Control vulnerability in Apache Traffic Server. | 39d ago |
| CVE-2026-14973 | 9.3 | — | — | — | ibm / aspera | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the us | 39d ago |
| CVE-2026-64740 | 9.3 | — | — | — | apple / ipados | A parsing issue in the handling of directory paths was addressed with improved path validation. | 40d ago |
| CVE-2026-59550 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | 40d ago |
| CVE-2026-59549 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | 40d ago |
| CVE-2026-59538 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | 40d ago |
| CVE-2026-59533 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | 40d ago |
| CVE-2026-59527 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | 40d ago |
| CVE-2026-62835 | 9.3 | — | — | — | microsoft / azure portal | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | 43d ago |
| CVE-2026-61950 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | 44d ago |
| CVE-2026-61949 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | 44d ago |
| CVE-2026-61948 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | 44d ago |
| CVE-2026-59526 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | 44d ago |
| CVE-2026-59525 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | 44d ago |
| CVE-2026-59514 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | 44d ago |
| CVE-2026-50252 | 9.3 | — | — | — | nlnetlabs / unbound | In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a | 45d ago |
| CVE-2026-16416 | 9.3 | — | — | — | google / chrome | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially pe | 46d ago |
| CVE-2026-61207 | 9.3 | — | — | — | oracle / peoplesoft enterprise scm eprocurement | Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requis | 46d ago |
| CVE-2026-61175 | 9.3 | — | — | — | oracle / product lifecycle analytics | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Is | 46d ago |
| CVE-2026-60632 | 9.3 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 46d ago |
| CVE-2026-60631 | 9.3 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 46d ago |
| CVE-2026-60248 | 9.3 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 46d ago |