| CVE-2026-60220 | 9.3 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-65057 | 9.3 | — | — | — | — | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers t | 46d ago |
| CVE-2026-64825 | 9.3 | — | — | — | — | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers | 46d ago |
| CVE-2026-65049 | 9.3 | — | — | — | — | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerabil | 46d ago |
| CVE-2026-65048 | 9.3 | — | — | — | — | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scri | 46d ago |
| CVE-2026-39878 | 9.3 | — | — | — | — | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registrat | 47d ago |
| CVE-2026-64080 | 9.3 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks | 48d ago |
| CVE-2026-64034 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_ | 48d ago |
| CVE-2026-64018 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out- | 48d ago |
| CVE-2026-63940 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length ' | 48d ago |
| CVE-2026-63939 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of th | 48d ago |
| CVE-2026-63938 | 9.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against th | 48d ago |
| CVE-2026-15091 | 9.3 | — | — | — | ibm / engineering ai hub | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to i | 50d ago |
| CVE-2026-54496 | 9.3 | — | — | — | — | ZEBRA is a Zcash node written entirely in Rust. | 50d ago |
| CVE-2026-63089 | 9.3 | — | — | — | — | WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token gene | 51d ago |
| CVE-2026-52843 | 9.3 | — | — | — | — | Lightpanda is a headless browser designed for AI and automation. | 52d ago |
| CVE-2026-52842 | 9.3 | — | — | — | — | Lightpanda is a headless browser designed for AI and automation. | 52d ago |
| CVE-2026-61736 | 9.3 | — | — | — | — | LightRAG provides simple and fast retrieval-augmented generation. | 52d ago |
| CVE-2026-48334 | 9.3 | — | — | — | adobe / illustrator | Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code executio | 53d ago |
| CVE-2026-48325 | 9.3 | — | — | — | adobe / coldfusion | ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitr | 53d ago |
| CVE-2026-48321 | 9.3 | — | — | — | adobe / coldfusion | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. | 53d ago |
| CVE-2026-48356 | 9.3 | — | — | — | adobe / commerce | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result i | 53d ago |
| CVE-2026-49798 | 9.3 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-59515 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU | 55d ago |
| CVE-2026-57739exploited | 9.3 | 0.40% | 1/3 | +40d | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing N | 55d ago |
| CVE-2026-57726 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirk | 55d ago |
| CVE-2026-57714 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint La | 55d ago |
| CVE-2026-57707 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud | 55d ago |
| CVE-2026-57702 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Ve | 55d ago |
| CVE-2026-55879 | 9.3 | — | — | — | — | OpenReplay is a self-hosted session replay suite. | 57d ago |
| CVE-2026-15143 | 9.3 | — | — | — | — | A flaw was found in the file_type content detector of guardrails-detectors. | 57d ago |
| CVE-2026-15378 | 9.3 | — | — | — | — | A flaw was found in the `guardrails-detectors` component. | 58d ago |
| CVE-2026-2342 | 9.3 | — | — | — | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft I | 59d ago |
| CVE-2026-47646 | 9.3 | — | — | — | microsoft / dynamics 365 customer voice | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voic | 59d ago |
| CVE-2026-59702 | 9.3 | — | — | — | — | repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenti | 59d ago |
| CVE-2026-59706 | 9.3 | — | — | — | — | mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side req | 60d ago |
| CVE-2026-41106 | 9.3 | — | — | — | microsoft / 365 copilot | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate pri | 65d ago |
| CVE-2026-57683 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | 65d ago |
| CVE-2026-57679 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. | 65d ago |
| CVE-2026-55721 | 9.3 | — | — | — | — | Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl an | 67d ago |
| CVE-2026-14038 | 9.3 | — | — | — | google / chrome | Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remot | 67d ago |
| CVE-2026-11712 | 9.3 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administr | 67d ago |
| CVE-2026-11708 | 9.3 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administr | 67d ago |
| CVE-2026-48315 | 9.3 | — | — | — | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that co | 67d ago |
| CVE-2026-48313exploited | 9.3 | 3.0% | 1/3 | +32d | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 67d ago |
| CVE-2026-56070 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. | 71d ago |
| CVE-2026-56068 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. | 71d ago |
| CVE-2026-56067 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. | 71d ago |
| CVE-2026-56062 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. | 71d ago |
| CVE-2026-56036 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. | 71d ago |
| CVE-2026-56034 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. | 71d ago |
| CVE-2026-54831 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. | 71d ago |
| CVE-2026-54827 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. | 71d ago |
| CVE-2026-54825 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. | 71d ago |
| CVE-2026-54820 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. | 71d ago |
| CVE-2026-54849 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. | 72d ago |
| CVE-2026-54843 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. | 72d ago |
| CVE-2026-54836 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter a | 72d ago |
| CVE-2026-55450exploited | 9.3 | 1.2% | 1/3 | +47d | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-49871 | 9.3 | — | — | — | apache / apisix | Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. | 78d ago |