| CVE-2026-14524 | 9.1 | — | — | — | — | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p | 21d ago |
| CVE-2026-18855 | 9.1 | — | — | — | — | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid | 21d ago |
| CVE-2026-74521 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare ClientGUIDs Cli | 21d ago |
| CVE-2026-74476 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_list skbs before running XD | 21d ago |
| CVE-2026-73194 | 9.1 | — | — | — | — | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that se | 21d ago |
| CVE-2026-74287 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded address parameter leng | 22d ago |
| CVE-2026-72348 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6tables: mark malformed IPv6 exte | 22d ago |
| CVE-2026-72320 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catchall element ha | 22d ago |
| CVE-2026-72296 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be pullable in i | 22d ago |
| CVE-2026-72188 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: sanitize MFT references returned from nt | 22d ago |
| CVE-2026-72186 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: make system files immutable to prevent c | 22d ago |
| CVE-2026-68457 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutati | 22d ago |
| CVE-2026-14484 | 9.1 | — | — | — | — | The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file de | 22d ago |
| CVE-2026-49457 | 9.1 | — | — | — | — | erlang_quic is a pure Erlang QUIC implementation. | 22d ago |
| CVE-2026-72850 | 9.1 | — | — | — | — | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files | 23d ago |
| CVE-2026-19297 | 9.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts | 23d ago |
| CVE-2026-73567 | 9.1 | — | — | — | — | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. | 23d ago |
| CVE-2026-58508 | 9.1 | — | — | — | — | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | 23d ago |
| CVE-2026-58443 | 9.1 | — | — | — | — | Public-only repository tokens can update private PR head branches | 23d ago |
| CVE-2026-58433 | 9.1 | — | — | — | — | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | 23d ago |
| CVE-2026-56750 | 9.1 | — | — | — | — | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | 23d ago |
| CVE-2026-55982 | 9.1 | — | — | — | — | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | 23d ago |
| CVE-2026-13051 | 9.1 | — | — | — | — | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispa | 23d ago |
| CVE-2022-4993 | 9.1 | — | — | — | — | HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion | 23d ago |
| CVE-2026-53791 | 9.1 | — | — | — | samba / rsync | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attacke | 23d ago |
| CVE-2026-59504 | 9.1 | — | — | — | — | : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP | 23d ago |
| CVE-2026-59503 | 9.1 | — | — | — | — | : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unau | 23d ago |
| CVE-2026-73501 | 9.1 | — | — | — | — | kin-openapi is a Go project for handling OpenAPI files. | 24d ago |
| CVE-2025-59324 | 9.1 | — | — | — | — | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encrypti | 24d ago |
| CVE-2026-16538 | 9.1 | — | — | — | — | The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wall | 25d ago |
| CVE-2026-68431 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform | 25d ago |
| CVE-2026-67568 | 9.1 | — | — | — | — | The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles fr | 25d ago |
| CVE-2026-71290 | 9.1 | — | — | — | apache / httpclient | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. | 25d ago |
| CVE-2026-66145 | 9.1 | — | — | — | — | An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier v | 25d ago |
| CVE-2026-71362exploited | 9.1 | 25.1% | 1/3 | +23d | — | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. | 25d ago |
| CVE-2026-69223 | 9.1 | — | — | — | apache / allura | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). | 25d ago |
| CVE-2026-73069 | 9.1 | — | — | — | — | Twenty is an open-source CRM (customer relationship management) platform. | 25d ago |
| CVE-2026-72748 | 9.1 | — | — | — | — | AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint | 25d ago |
| CVE-2026-19516 | 9.1 | — | — | — | — | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and th | 26d ago |
| CVE-2026-13716 | 9.1 | — | — | — | craftycontrol / crafty controller | Path traversal in server import and admin file upload in Crafty Controller. | 26d ago |
| CVE-2026-44758 | 9.1 | — | — | — | — | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially c | 26d ago |
| CVE-2026-18412 | 9.1 | — | — | — | — | OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. | 26d ago |
| CVE-2026-68343 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsume | 26d ago |
| CVE-2026-68083 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_p | 26d ago |
| CVE-2026-72575 | 9.1 | — | — | — | — | An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read | 26d ago |
| CVE-2026-72569 | 9.1 | — | — | — | — | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacke | 26d ago |
| CVE-2026-19053 | 9.1 | — | — | — | — | The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it i | 27d ago |
| CVE-2026-18473 | 9.1 | — | — | — | — | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using | 28d ago |
| CVE-2026-48170 | 9.1 | — | — | — | — | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a | 29d ago |
| CVE-2026-48039 | 9.1 | — | — | — | — | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. | 29d ago |
| CVE-2026-71560 | 9.1 | — | — | — | apache / fory | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. | 29d ago |
| CVE-2026-16038 | 9.1 | — | — | — | — | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking | 30d ago |
| CVE-2026-68823 | 9.1 | — | — | — | microsoft / azure confidential ledger | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code ov | 30d ago |
| CVE-2026-53984 | 9.1 | — | — | — | — | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulner | 30d ago |
| CVE-2026-3418 | 9.1 | — | — | — | — | The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or | 30d ago |
| CVE-2026-66709 | 9.1 | — | — | — | — | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | 30d ago |
| CVE-2026-54489 | 9.1 | — | — | — | dell / virtual storage integrator | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Inf | 30d ago |
| CVE-2026-53976 | 9.1 | — | — | — | — | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/sta | 30d ago |
| CVE-2026-34191 | 9.1 | — | — | — | apache / apr-util | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Porta | 30d ago |
| CVE-2026-32327 | 9.1 | — | — | — | apache / apr-util | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which p | 30d ago |