| CVE-2025-50455 | 9.1 | — | — | — | — | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis | 40d ago |
| CVE-2026-58662 | 9.1 | — | — | — | apache / thrift | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings | 40d ago |
| CVE-2026-58023 | 9.1 | — | — | — | apache / thrift | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. | 40d ago |
| CVE-2026-48144 | 9.1 | — | — | — | apache / thrift | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. | 40d ago |
| CVE-2026-13597 | 9.1 | — | — | — | — | The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature chec | 41d ago |
| CVE-2026-13332 | 9.1 | — | — | — | — | The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX | 41d ago |
| CVE-2026-64450 | 9.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap | 42d ago |
| CVE-2026-64393 | 9.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SM | 42d ago |
| CVE-2026-64392 | 9.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-cl | 42d ago |
| CVE-2026-64320 | 9.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in | 42d ago |
| CVE-2026-64319 | 9.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bou | 42d ago |
| CVE-2026-64269 | 9.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chun | 42d ago |
| CVE-2026-64257 | 9.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in | 42d ago |
| CVE-2026-48021 | 9.1 | — | — | — | — | In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the | 43d ago |
| CVE-2026-12877 | 9.1 | — | — | — | — | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape u | 44d ago |
| CVE-2026-56160 | 9.1 | — | — | — | microsoft / azure red hat openshift | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a | 44d ago |
| CVE-2026-65701 | 9.1 | — | — | — | — | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-so | 44d ago |
| CVE-2026-15617 | 9.1 | — | — | — | — | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and | 44d ago |
| CVE-2026-15616 | 9.1 | — | — | — | — | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor re | 44d ago |
| CVE-2026-15612 | 9.1 | — | — | — | — | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authenti | 44d ago |
| CVE-2026-15611 | 9.1 | — | — | — | — | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permiss | 44d ago |
| CVE-2026-65907 | 9.1 | — | — | — | — | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | 44d ago |
| CVE-2026-65461 | 9.1 | — | — | — | — | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | 44d ago |
| CVE-2026-65455 | 9.1 | — | — | — | — | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | 44d ago |
| CVE-2026-27064 | 9.1 | — | — | — | — | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | 44d ago |
| CVE-2026-64798 | 9.1 | — | — | — | — | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys wer | 45d ago |
| CVE-2026-64793 | 9.1 | — | — | — | — | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhe | 45d ago |
| CVE-2026-46738 | 9.1 | — | — | — | dell / powerprotect data manager | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability | 45d ago |
| CVE-2026-40712 | 9.1 | — | — | — | dell / powerprotect data manager | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability | 45d ago |
| CVE-2026-62144 | 9.1 | — | — | — | — | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management all | 45d ago |
| CVE-2026-62546 | 9.1 | — | — | — | oracle / applications framework | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). | 46d ago |
| CVE-2026-61244 | 9.1 | — | — | — | oracle / peoplesoft enterprise fin manufacturing argentina | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Ma | 46d ago |
| CVE-2026-61238 | 9.1 | — | — | — | oracle / peoplesoft enterprise fin common objects | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: e | 46d ago |
| CVE-2026-61235 | 9.1 | — | — | — | oracle / peoplesoft enterprise hcm global payroll switzerland | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: | 46d ago |
| CVE-2026-61197 | 9.1 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 46d ago |
| CVE-2026-61184 | 9.1 | — | — | — | oracle / agile product lifecycle management for process | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (compone | 46d ago |
| CVE-2026-61171 | 9.1 | — | — | — | oracle / agile product lifecycle management | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). | 46d ago |
| CVE-2026-61156 | 9.1 | — | — | — | oracle / commerce guided search platform services | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge) | 46d ago |
| CVE-2026-61155 | 9.1 | — | — | — | oracle / commerce guided search platform services | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge) | 46d ago |
| CVE-2026-61153 | 9.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 46d ago |
| CVE-2026-61130 | 9.1 | — | — | — | oracle / commerce platform | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework) | 46d ago |
| CVE-2026-61059 | 9.1 | — | — | — | oracle / peoplesoft enterprise scm order management | Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security) | 46d ago |
| CVE-2026-60649 | 9.1 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Manageme | 46d ago |
| CVE-2026-60606 | 9.1 | — | — | — | oracle / peoplesoft enterprise cc common application objects | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: | 46d ago |
| CVE-2026-60567 | 9.1 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 46d ago |
| CVE-2026-60438 | 9.1 | — | — | — | oracle / http server | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). | 46d ago |
| CVE-2026-60326 | 9.1 | — | — | — | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 46d ago |
| CVE-2026-60267 | 9.1 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-60208 | 9.1 | — | — | — | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-60168 | 9.1 | — | — | — | oracle / hospitality simphony | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS) | 46d ago |
| CVE-2026-47731 | 9.1 | — | — | — | — | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python | 46d ago |
| CVE-2026-47040 | 9.1 | — | — | — | oracle / database server | Vulnerability in the Oracle Net Services component of Oracle Database Server. | 46d ago |
| CVE-2026-46989 | 9.1 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI F | 46d ago |
| CVE-2026-59145 | 9.1 | — | — | — | — | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and a | 46d ago |
| CVE-2026-59142 | 9.1 | — | — | — | — | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset an | 46d ago |
| CVE-2026-59141 | 9.1 | — | — | — | — | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena i | 46d ago |
| CVE-2026-59140 | 9.1 | — | — | — | — | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in | 46d ago |
| CVE-2026-59139 | 9.1 | — | — | — | — | Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and | 46d ago |
| CVE-2026-16439 | 9.1 | — | — | — | eclipse / openj9 | In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. | 46d ago |
| CVE-2026-28321 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and wr | 46d ago |