| CVE-2026-77536 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi | 10d ago |
| CVE-2026-77534 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi | 10d ago |
| CVE-2026-77533 | 9.9 | critical | — | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 10d ago |
| CVE-2026-65093 | 9.9 | critical | nvidia / openshell | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. | 11d ago |
| CVE-2026-65083 | 9.9 | critical | nvidia / openshell | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause | 11d ago |
| CVE-2026-32559 | 9.9 | critical | — | Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | 12d ago |
| CVE-2026-66897 | 9.9 | critical | — | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permis | 12d ago |
| CVE-2026-78169 | 9.9 | critical | — | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 13d ago |
| CVE-2026-78155 | 9.9 | critical | — | privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator | 13d ago |
| CVE-2026-78050 | 9.9 | critical | — | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. | 14d ago |
| CVE-2026-62283 | 9.9 | critical | — | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. | 15d ago |
| CVE-2026-77810 | 9.9 | critical | — | In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to proper | 15d ago |
| CVE-2026-63343 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-63125 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-62941 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-62940 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-62867 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-48769 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-48755 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-48753 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-48752 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-48751 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-48750 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-48749 | 9.9 | critical | — | Incus is a system container and virtual machine manager. | 15d ago |
| CVE-2026-77683 | 9.9 | critical | — | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. | 15d ago |
| CVE-2026-69851 | 9.9 | critical | microsoft / entra id | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges o | 16d ago |
| CVE-2026-68789 | 9.9 | critical | microsoft / azure sql database | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows | 16d ago |
| CVE-2026-68782 | 9.9 | critical | microsoft / azure sql database | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows | 16d ago |
| CVE-2026-63509 | 9.9 | critical | microsoft / fabric | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | 16d ago |
| CVE-2026-18835 | 9.9 | critical | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary com | 16d ago |
| CVE-2026-67567 | 9.9 | critical | — | A flaw was found in the multicloud-operators-subscription component. | 16d ago |
| CVE-2026-77148 | 9.9 | critical | — | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. | 16d ago |
| CVE-2026-77022 | 9.9 | critical | — | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. | 16d ago |
| CVE-2026-74018 | 9.9 | critical | — | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | 16d ago |
| CVE-2026-74016 | 9.9 | critical | — | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | 16d ago |
| CVE-2026-74014 | 9.9 | critical | — | Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | 16d ago |
| CVE-2026-73992 | 9.9 | critical | — | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | 16d ago |
| CVE-2026-76590 | 9.9 | critical | — | A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. | 17d ago |
| CVE-2026-76589 | 9.9 | critical | — | A vulnerability was found in TRENDnet TEW-755AP up to 20260702. | 17d ago |
| CVE-2026-76584 | 9.9 | critical | — | A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. | 17d ago |
| CVE-2026-55089 | 9.9 | critical | — | Etherpad is a real-time collaborative editor. | 17d ago |
| CVE-2026-70496 | 9.9 | critical | — | A flaw was found in search-v2-operator. | 17d ago |
| CVE-2026-20359 | 9.9 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering t | 17d ago |
| CVE-2026-20231 | 9.9 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload enginee | 17d ago |
| CVE-2026-16816 | 9.9 | critical | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary com | 17d ago |
| CVE-2026-15068 | 9.9 | critical | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary | 17d ago |
| CVE-2026-51366 | 9.9 | critical | — | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbit | 17d ago |
| CVE-2026-76004 | 9.9 | critical | — | A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 18d ago |
| CVE-2026-76003 | 9.9 | critical | — | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. | 18d ago |
| CVE-2026-75976 | 9.9 | critical | — | A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. | 18d ago |
| CVE-2026-73930 | 9.9 | critical | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-71059 | 9.9 | critical | oracle / bi publisher | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). | 18d ago |
| CVE-2026-70920 | 9.9 | critical | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-62608 | 9.9 | critical | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62588 | 9.9 | critical | oracle / siebel crm | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). | 18d ago |
| CVE-2026-62512 | 9.9 | critical | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 18d ago |
| CVE-2026-62452 | 9.9 | critical | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 18d ago |
| CVE-2026-61317 | 9.9 | critical | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 18d ago |
| CVE-2026-61248 | 9.9 | critical | oracle / internet directory | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | 18d ago |
| CVE-2026-61206 | 9.9 | critical | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 18d ago |