| CVE-2026-42849 | 9.3 | — | — | — | goauthentik / authentik | authentik is an open-source identity provider. | 95d ago |
| CVE-2026-42684 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job | 95d ago |
| CVE-2026-42672 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory | 96d ago |
| CVE-2026-44590 | 9.3 | — | — | — | — | Sherlock hunts down social media accounts by username across social networks. | 101d ago |
| CVE-2026-42761 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 A | 101d ago |
| CVE-2026-42755 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 T | 101d ago |
| CVE-2026-42747 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafres | 101d ago |
| CVE-2026-42740 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tai | 101d ago |
| CVE-2026-42727 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 A | 101d ago |
| CVE-2026-44451 | 9.3 | — | — | — | — | Lumiverse is a full-featured AI chat application. | 102d ago |
| CVE-2026-42774 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock J | 103d ago |
| CVE-2026-42773 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eM | 103d ago |
| CVE-2026-41090 | 9.3 | — | — | — | microsoft / 365 copilot | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an | 106d ago |
| CVE-2026-9264 | 9.3 | — | — | — | — | A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code executi | 107d ago |
| CVE-2026-39531 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory | 107d ago |
| CVE-2026-8950 | 9.3 | — | — | — | mozilla / firefox | Same-origin policy bypass in the Networking: HTTP component. | 109d ago |
| CVE-2026-44212 | 9.3 | — | — | — | — | PrestaShop is an open source e-commerce web application. | 114d ago |
| CVE-2025-27851 | 9.3 | — | — | — | garmin / empirbus wireless display unit firmware | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking | 115d ago |
| CVE-2026-44225 | 9.3 | — | — | — | — | Pulpy is a lightweight, cross-platform desktop application packager for web apps. | 116d ago |
| CVE-2026-34660 | 9.3 | — | — | — | adobe / connect desktop application | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability | 116d ago |
| CVE-2026-40402 | 9.3 | — | — | — | microsoft / windows 11 23h2 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40379 | 9.3 | — | — | — | microsoft / entra id | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to pe | 116d ago |
| CVE-2026-43900 | 9.3 | — | — | — | — | DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. | 117d ago |
| CVE-2026-32913 | 9.3 | — | — | — | openclaw / openclaw | OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards | 166d ago |
| CVE-2026-33502 | 9.3 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33136 | 9.3 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 169d ago |
| CVE-2026-33135 | 9.3 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 169d ago |
| CVE-2026-33134 | 9.3 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 169d ago |
| CVE-2026-32940 | 9.3 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 170d ago |
| CVE-2026-32754 | 9.3 | — | — | — | freescout / freescout | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. | 170d ago |
| CVE-2026-27413 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs P | 171d ago |
| CVE-2026-32301 | 9.3 | — | — | — | centrifugal / centrifugo | Centrifugo is an open-source scalable real-time messaging server. | 176d ago |
| CVE-2026-32096 | 9.3 | — | — | — | useplunk / plunk | Plunk is an open-source email platform built on top of AWS SES. | 178d ago |
| CVE-2026-72496 | 9.2 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if the ioremap f | 22d ago |
| CVE-2026-49445 | 9.2 | — | — | — | cilium / cilium | Cilium is a networking, observability, and security solution. | 52d ago |
| CVE-2026-50110 | 9.2 | — | — | — | — | Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a c | 67d ago |
| CVE-2026-86149 | 9.1 | — | — | — | — | A weakness has been identified in Tenda CP3 27.5.57.101. | 12h ago |
| CVE-2026-86148 | 9.1 | — | — | — | — | A security flaw has been discovered in Tenda CP3 27.5.57.101. | 12h ago |
| CVE-2026-86190 | 9.1 | — | — | — | — | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user | 21h ago |
| CVE-2026-52766 | 9.1 | — | — | — | — | YesWiki is a wiki system written in PHP. | 1d ago |
| CVE-2026-81939 | 9.1 | — | — | — | — | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processin | 1d ago |
| CVE-2026-78328 | 9.1 | — | — | — | — | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface | 1d ago |
| CVE-2026-78327 | 9.1 | — | — | — | — | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the | 1d ago |
| CVE-2026-75431 | 9.1 | — | — | — | — | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authenticati | 1d ago |
| CVE-2026-75160 | 9.1 | — | — | — | — | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /c | 1d ago |
| CVE-2026-85684 | 9.1 | — | — | — | — | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to s | 1d ago |
| CVE-2026-85667 | 9.1 | — | — | — | — | xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing una | 1d ago |
| CVE-2026-85184 | 9.1 | — | — | — | — | @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching agains | 2d ago |
| CVE-2026-85435 | 9.1 | — | — | — | — | MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, | 2d ago |
| CVE-2026-85434 | 9.1 | — | — | — | — | MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge rou | 2d ago |
| CVE-2026-85430 | 9.1 | — | — | — | — | MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP data | 2d ago |
| CVE-2026-62916 | 9.1 | — | — | — | — | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to | 2d ago |
| CVE-2026-85224 | 9.1 | — | — | — | — | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. | 2d ago |
| CVE-2026-85222 | 9.1 | — | — | — | — | A vulnerability has been found in D-Link DNS-340L 1.01B04. | 2d ago |
| CVE-2026-85043 | 9.1 | — | — | — | — | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system a | 2d ago |
| CVE-2026-85394 | 9.1 | — | — | — | — | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded | 2d ago |
| CVE-2026-58400zero day | 9.1 | 1.2% | 2/3 | 1d before | — | GeoNetwork is a catalog application to manage spatially referenced resources. | 2d ago |
| CVE-2026-66786 | 9.1 | — | — | — | — | A flaw was found in submariner. | 3d ago |
| CVE-2026-73475 | 9.1 | — | — | — | — | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. | 3d ago |
| CVE-2026-84699 | 9.1 | — | — | — | — | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password | 4d ago |