| CVE-2026-80603 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() o | 9d ago |
| CVE-2026-61800 | 9.1 | — | — | — | — | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud worklo | 9d ago |
| CVE-2026-50152 | 9.1 | — | — | — | — | Ceph is an open-source distributed storage platform providing object, block, and file storage. | 9d ago |
| CVE-2026-59283 | 9.1 | — | — | — | vmware / spring framework | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vuln | 9d ago |
| CVE-2026-37065 | 9.1 | — | — | — | — | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translati | 9d ago |
| CVE-2026-81098 | 9.1 | — | — | — | — | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. | 9d ago |
| CVE-2026-81094 | 9.1 | — | — | — | — | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator | 9d ago |
| CVE-2026-57499 | 9.1 | — | — | — | — | Liman is open source server management software. | 9d ago |
| CVE-2026-78274 | 9.1 | — | — | — | — | Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. | 9d ago |
| CVE-2026-75340 | 9.1 | — | — | — | — | The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2 | 10d ago |
| CVE-2026-75332 | 9.1 | — | — | — | — | Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). | 10d ago |
| CVE-2025-51679 | 9.1 | — | — | — | — | An issue was discovered in openRISC OR1200 commit 83ac6b. | 10d ago |
| CVE-2026-70419 | 9.1 | — | — | — | dell / cloud disaster recovery | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used | 10d ago |
| CVE-2026-75896 | 9.1 | — | — | — | — | Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk | 10d ago |
| CVE-2026-77542 | 9.1 | — | — | — | — | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulner | 10d ago |
| CVE-2026-77541 | 9.1 | — | — | — | — | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerab | 10d ago |
| CVE-2026-77540 | 9.1 | — | — | — | — | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulner | 10d ago |
| CVE-2026-77539 | 9.1 | — | — | — | — | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulner | 10d ago |
| CVE-2026-77535 | 9.1 | — | — | — | — | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulner | 10d ago |
| CVE-2026-59682 | 9.1 | — | — | — | — | Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. | 10d ago |
| CVE-2026-16645 | 9.1 | — | — | — | — | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forcef | 11d ago |
| CVE-2026-16644 | 9.1 | — | — | — | — | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. | 11d ago |
| CVE-2026-78655 | 9.1 | — | — | — | — | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an | 11d ago |
| CVE-2026-68525 | 9.1 | — | — | — | apache / tomcat | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a sec | 11d ago |
| CVE-2026-65182 | 9.1 | — | — | — | apache / tomcat | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypas | 11d ago |
| CVE-2026-79148 | 9.1 | — | — | — | google / chrome | Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social e | 11d ago |
| CVE-2026-79058 | 9.1 | — | — | — | google / chrome | Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr | 11d ago |
| CVE-2026-55640 | 9.1 | — | — | — | — | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. | 11d ago |
| CVE-2026-55536 | 9.1 | — | — | — | — | PraisonAI is a multi-agent teams system. | 11d ago |
| CVE-2026-75803 | 9.1 | — | — | — | — | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verify | 11d ago |
| CVE-2026-55976 | 9.1 | — | — | — | apache / hive | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authentic | 11d ago |
| CVE-2026-59769 | 9.1 | — | — | — | — | FA-50 all versions contain hard-coded credentials. | 12d ago |
| CVE-2026-76835 | 9.1 | — | — | — | — | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authenticat | 12d ago |
| CVE-2026-71933 | 9.1 | — | — | — | — | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. | 12d ago |
| CVE-2026-66906 | 9.1 | — | — | — | apache / camel | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. | 12d ago |
| CVE-2026-19874 | 9.1 | — | — | — | — | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper valid | 12d ago |
| CVE-2026-67602 | 9.1 | — | — | — | — | phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated a | 12d ago |
| CVE-2026-59568 | 9.1 | — | — | — | — | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an u | 12d ago |
| CVE-2026-59564 | 9.1 | — | — | — | — | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector | 12d ago |
| CVE-2026-74665 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic X | 14d ago |
| CVE-2026-75870 | 9.1 | — | — | — | — | Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is de | 14d ago |
| CVE-2026-75866 | 9.1 | — | — | — | — | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and g | 14d ago |
| CVE-2026-49849 | 9.1 | — | — | — | — | xShop is an open-source shop developed in Laravel. | 15d ago |
| CVE-2026-77776 | 9.1 | — | — | — | — | Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. | 15d ago |
| CVE-2026-77086 | 9.1 | — | — | — | — | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowi | 15d ago |
| CVE-2026-62440 | 9.1 | — | — | — | apache / cloudstack | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenan | 16d ago |
| CVE-2026-61398 | 9.1 | — | — | — | apache / cloudstack | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Passwor | 16d ago |
| CVE-2026-59085 | 9.1 | — | — | — | apache / cloudstack | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook de | 16d ago |
| CVE-2026-66309 | 9.1 | — | — | — | microsoft / azure sql database | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 16d ago |
| CVE-2026-71485 | 9.1 | — | — | — | — | Centrifugo is an open-source scalable real-time messaging server. | 16d ago |
| CVE-2026-73257 | 9.1 | — | — | — | — | Mongoose is an embedded web server and network library. | 16d ago |
| CVE-2026-73256 | 9.1 | — | — | — | — | Mongoose is an embedded web server and network library. | 16d ago |
| CVE-2026-16926 | 9.1 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to im | 16d ago |
| CVE-2026-66600 | 9.1 | — | — | — | — | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | 16d ago |
| CVE-2026-76404 | 9.1 | — | — | — | splunk / model context protocol server | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary co | 17d ago |
| CVE-2026-71470 | 9.1 | — | — | — | — | A flaw was found in the search-v2-operator. | 17d ago |
| CVE-2026-49441 | 9.1 | — | — | — | — | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 17d ago |
| CVE-2026-48162 | 9.1 | — | — | — | — | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 17d ago |
| CVE-2026-48024 | 9.1 | — | — | — | — | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 17d ago |
| CVE-2026-71960 | 9.1 | — | — | — | — | Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the | 17d ago |