| CVE-2026-65583 | 9.1 | — | — | — | apache / cxf | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required cla | 30d ago |
| CVE-2026-63687 | 9.1 | — | — | — | apache / cxf | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map | 30d ago |
| CVE-2026-61466 | 9.1 | — | — | — | apache / cxf | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scop | 30d ago |
| CVE-2026-16054 | 9.1 | — | — | — | — | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthentica | 31d ago |
| CVE-2026-12713 | 9.1 | — | — | — | — | The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before u | 31d ago |
| CVE-2026-17556 | 9.1 | — | — | — | github / enterprise server | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker | 31d ago |
| CVE-2026-20310 | 9.1 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN enginee | 31d ago |
| CVE-2026-9190 | 9.1 | — | — | — | progress / marklogic server | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0. | 31d ago |
| CVE-2026-7557 | 9.1 | — | — | — | progress / marklogic server | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress Mar | 31d ago |
| CVE-2026-60053 | 9.1 | — | — | — | apache / answer | Insufficient Session Expiration vulnerability in Apache Answer. | 31d ago |
| CVE-2026-71277 | 9.1 | — | — | — | — | rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization | 31d ago |
| CVE-2026-71263 | 9.1 | — | — | — | — | The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp. | 31d ago |
| CVE-2026-71238 | 9.1 | — | — | — | — | DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read | 31d ago |
| CVE-2026-44945 | 9.1 | — | — | — | — | A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.g | 31d ago |
| CVE-2026-10059 | 9.1 | — | — | — | — | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. | 31d ago |
| CVE-2026-71213 | 9.1 | — | — | — | — | Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt cou | 32d ago |
| CVE-2026-5581 | 9.1 | — | — | — | — | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in | 32d ago |
| CVE-2026-4431 | 9.1 | — | — | — | — | The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c | 32d ago |
| CVE-2026-15360 | 9.1 | — | — | — | — | The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it | 32d ago |
| CVE-2026-15210 | 9.1 | — | — | — | — | The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP | 32d ago |
| CVE-2026-45537 | 9.1 | — | — | — | — | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 32d ago |
| CVE-2026-45100 | 9.1 | — | — | — | — | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. | 32d ago |
| CVE-2026-67979 | 9.1 | — | — | — | — | Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 all | 32d ago |
| CVE-2026-69110 | 9.1 | — | — | — | — | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote at | 32d ago |
| CVE-2026-10050 | 9.1 | — | — | — | eclipse / jetty | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. | 32d ago |
| CVE-2026-14804 | 9.1 | — | — | — | — | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. | 32d ago |
| CVE-2026-18754 | 9.1 | — | — | — | — | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS term | 33d ago |
| CVE-2026-18753 | 9.1 | — | — | — | — | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS term | 33d ago |
| CVE-2026-68980 | 9.1 | — | — | — | apache / nifi | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts | 33d ago |
| CVE-2026-48031 | 9.1 | — | — | — | — | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. | 33d ago |
| CVE-2026-39932 | 9.1 | — | — | — | open-emr / openemr | OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (libr | 33d ago |
| CVE-2026-18248 | 9.1 | — | — | — | fastify / fastify\/aws-lambda | @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambd | 33d ago |
| CVE-2026-9487 | 9.1 | — | — | — | xml\ / \ | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. | 33d ago |
| CVE-2026-9390 | 9.1 | — | — | — | xml\ / \ | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. | 33d ago |
| CVE-2026-16534 | 9.1 | — | — | — | — | The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignme | 34d ago |
| CVE-2026-16532 | 9.1 | — | — | — | — | The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before | 34d ago |
| CVE-2026-14557 | 9.1 | — | — | — | — | The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication t | 34d ago |
| CVE-2026-12965 | 9.1 | — | — | — | — | The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX actio | 34d ago |
| CVE-2026-58062 | 9.1 | — | — | — | bouncycastle / bc-java | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. | 34d ago |
| CVE-2026-8763 | 9.1 | — | — | — | bouncycastle / bc-java | In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. | 34d ago |
| CVE-2026-59650 | 9.1 | — | — | — | bouncycastle / bc-java | In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. | 34d ago |
| CVE-2026-13596 | 9.1 | — | — | — | — | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied pa | 36d ago |
| CVE-2026-3141 | 9.1 | — | — | — | — | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability | 36d ago |
| CVE-2026-16503 | 9.1 | — | — | — | — | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all inter | 36d ago |
| CVE-2026-52539 | 9.1 | — | — | — | — | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. | 37d ago |
| CVE-2026-13379 | 9.1 | — | — | — | openvpn / openvpn | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DN | 37d ago |
| CVE-2026-54363 | 9.1 | — | — | — | — | CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers | 37d ago |
| CVE-2026-44092 | 9.1 | — | — | — | — | An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does no | 38d ago |
| CVE-2026-44091 | 9.1 | — | — | — | — | An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new con | 38d ago |
| CVE-2026-17666 | 9.1 | — | — | — | google / chrome | Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged netwo | 38d ago |
| CVE-2026-14488 | 9.1 | — | — | — | — | The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher | 38d ago |
| CVE-2026-63230 | 9.1 | — | — | — | — | A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to | 39d ago |
| CVE-2026-63229 | 9.1 | — | — | — | — | A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a | 39d ago |
| CVE-2026-64863 | 9.1 | — | — | — | — | goshs is a feature-rich single-binary file server for red teamers and developers. | 39d ago |
| CVE-2026-62325 | 9.1 | — | — | — | — | goshs is a feature-rich single-binary file server for red teamers and developers. | 39d ago |
| CVE-2026-14959 | 9.1 | — | — | — | ibm / aspera faspex | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code d | 39d ago |
| CVE-2026-14958 | 9.1 | — | — | — | ibm / aspera faspex | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code d | 39d ago |
| CVE-2026-64551 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length befor | 40d ago |
| CVE-2026-17552 | 9.1 | — | — | — | — | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI co | 40d ago |
| CVE-2026-17191 | 9.1 | — | — | — | — | An input validation vulnerability exists in an API component of the orchestrator. | 40d ago |