| CVE-2026-15065 | 9.1 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions du | 17d ago |
| CVE-2026-73924 | 9.1 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73922 | 9.1 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73917 | 9.1 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73916 | 9.1 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73866 | 9.1 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73865 | 9.1 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-71102 | 9.1 | — | — | — | oracle / database server | Vulnerability in the Portable Clusterware component of Oracle Database Server. | 18d ago |
| CVE-2026-71036 | 9.1 | — | — | — | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-71026 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-71015 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-71014 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70997 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70994 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70984 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70981 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70979 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70978 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70977 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70976 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70884 | 9.1 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 18d ago |
| CVE-2026-70883 | 9.1 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 18d ago |
| CVE-2026-70876 | 9.1 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 18d ago |
| CVE-2026-70872 | 9.1 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 18d ago |
| CVE-2026-70862 | 9.1 | — | — | — | oracle / application testing suite | Vulnerability in Oracle Application Testing Suite. | 18d ago |
| CVE-2026-70854 | 9.1 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-70741 | 9.1 | — | — | — | oracle / hyperion financial reporting | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). | 18d ago |
| CVE-2026-70730 | 9.1 | — | — | — | oracle / hyperion profitability and cost management | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Depl | 18d ago |
| CVE-2026-70668 | 9.1 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62638 | 9.1 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62610 | 9.1 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-61034 | 9.1 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 18d ago |
| CVE-2026-61008 | 9.1 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 18d ago |
| CVE-2026-60754 | 9.1 | — | — | — | oracle / siebel apps - marketing | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). | 18d ago |
| CVE-2026-60737 | 9.1 | — | — | — | oracle / web services manager | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Secu | 18d ago |
| CVE-2026-60728 | 9.1 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). | 18d ago |
| CVE-2026-60591 | 9.1 | — | — | — | oracle / hospitality simphony | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS) | 18d ago |
| CVE-2026-52610 | 9.1 | — | — | — | — | An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to cre | 18d ago |
| CVE-2026-52723 | 9.1 | — | — | — | — | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's elec | 18d ago |
| CVE-2026-18963exploited | 9.1 | 3.2% | 1/3 | +7d | — | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for id | 18d ago |
| CVE-2026-73381 | 9.1 | — | — | — | — | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | 18d ago |
| CVE-2026-74986 | 9.1 | — | — | — | mozilla / firefox | Site isolation issue in the CSS Parsing and Computation component. | 18d ago |
| CVE-2026-74961 | 9.1 | — | — | — | mozilla / firefox | Side-channel in the Web Audio component. | 18d ago |
| CVE-2026-74959 | 9.1 | — | — | — | mozilla / firefox | Mitigation bypass in the Storage: Cache API component. | 18d ago |
| CVE-2026-74956 | 9.1 | — | — | — | mozilla / firefox | Same-origin policy bypass in the DOM: Service Workers component. | 18d ago |
| CVE-2026-74938 | 9.1 | — | — | — | mozilla / firefox | Mitigation bypass in the JavaScript: GC component. | 18d ago |
| CVE-2026-75837 | 9.1 | — | — | — | — | Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin. | 18d ago |
| CVE-2026-75094 | 9.1 | — | — | — | — | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. | 19d ago |
| CVE-2026-42162 | 9.1 | — | — | — | — | Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstance | 19d ago |
| CVE-2026-51977 | 9.1 | — | — | — | — | An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate atta | 19d ago |
| CVE-2026-75106 | 9.1 | — | — | — | — | OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default sa | 19d ago |
| CVE-2026-71472 | 9.1 | — | — | — | — | A flaw was found in acm-search-v2-rhel9. | 19d ago |
| CVE-2026-51346 | 9.1 | — | — | — | — | SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execu | 19d ago |
| CVE-2026-75045 | 9.1 | — | — | — | — | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download | 19d ago |
| CVE-2026-71479 | 9.1 | — | — | — | — | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 19d ago |
| CVE-2026-64859 | 9.1 | — | — | — | — | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 19d ago |
| CVE-2026-74790 | 9.1 | — | — | — | — | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing re | 20d ago |
| CVE-2026-19725 | 9.1 | — | — | — | — | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an | 21d ago |
| CVE-2026-19714 | 9.1 | — | — | — | — | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it | 21d ago |
| CVE-2026-18316 | 9.1 | — | — | — | — | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing | 21d ago |