| CVE-2026-28317 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privile | 46d ago |
| CVE-2026-28316 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privile | 46d ago |
| CVE-2026-28314 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeov | 46d ago |
| CVE-2026-28313 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hi | 46d ago |
| CVE-2026-28312 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by a privilege escalation vulnerability. | 46d ago |
| CVE-2026-28310 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escala | 46d ago |
| CVE-2026-28309 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to creat | 46d ago |
| CVE-2026-28308 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote | 46d ago |
| CVE-2026-28307 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevat | 46d ago |
| CVE-2026-28306 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevat | 46d ago |
| CVE-2026-28305 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote | 46d ago |
| CVE-2026-28304 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitra | 46d ago |
| CVE-2026-28302 | 9.1 | — | — | — | solarwinds / serv-u | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privile | 46d ago |
| CVE-2026-16406 | 9.1 | — | — | — | mozilla / firefox | Mitigation bypass in the Networking component. | 46d ago |
| CVE-2026-16394 | 9.1 | — | — | — | mozilla / firefox | Mitigation bypass in the DOM: Security component. | 46d ago |
| CVE-2026-16393 | 9.1 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics: WebGPU component. | 46d ago |
| CVE-2026-16392 | 9.1 | — | — | — | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 46d ago |
| CVE-2026-16390 | 9.1 | — | — | — | mozilla / firefox | Mitigation bypass in the Enterprise Policies component. | 46d ago |
| CVE-2026-16381 | 9.1 | — | — | — | mozilla / firefox | Same-origin policy bypass in the Networking: DNS component. | 46d ago |
| CVE-2026-16380 | 9.1 | — | — | — | mozilla / firefox | Mitigation bypass in the Networking component. | 46d ago |
| CVE-2026-16370 | 9.1 | — | — | — | mozilla / firefox | Mitigation bypass in the DOM: Networking component. | 46d ago |
| CVE-2026-16364 | 9.1 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: Playback component. | 46d ago |
| CVE-2026-16359 | 9.1 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: GMP component. | 46d ago |
| CVE-2026-64609 | 9.1 | — | — | — | apache / fory | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. | 46d ago |
| CVE-2026-62415 | 9.1 | — | — | — | — | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension | 46d ago |
| CVE-2026-44231 | 9.1 | — | — | — | bestpractical / request tracker | RT is an open source, enterprise-grade issue and ticket tracking system. | 47d ago |
| CVE-2026-62414 | 9.1 | — | — | — | — | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Bu | 47d ago |
| CVE-2026-13147 | 9.1 | — | — | — | — | The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, a | 48d ago |
| CVE-2026-63992 | 9.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in ipt | 48d ago |
| CVE-2026-52199 | 9.1 | — | — | — | — | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the | 50d ago |
| CVE-2026-42168 | 9.1 | — | — | — | — | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Pa | 50d ago |
| CVE-2025-51677 | 9.1 | — | — | — | — | An issue was discovered in openRISC OR1200 commit 83ac6b. | 50d ago |
| CVE-2026-12694 | 9.1 | — | — | — | — | Missing Authorization vulnerability in Vimesoft Inc. | 50d ago |
| CVE-2024-23564 | 9.1 | — | — | — | — | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application ca | 50d ago |
| CVE-2026-62241 | 9.1 | — | — | — | mohibshaikh / clawvet | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-chang | 51d ago |
| CVE-2026-57075 | 9.1 | — | — | — | — | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_ | 51d ago |
| CVE-2026-57074 | 9.1 | — | — | — | — | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. | 51d ago |
| CVE-2026-57073 | 9.1 | — | — | — | — | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. | 51d ago |
| CVE-2026-46621 | 9.1 | — | — | — | spaceapplications / yamcs | Yamcs is a mission control framework. | 51d ago |
| CVE-2026-45568 | 9.1 | — | — | — | netfoundry / zrok | zrok is software for sharing web services, files, and network resources. | 51d ago |
| CVE-2026-44632 | 9.1 | — | — | — | spaceapplications / yamcs | Yamcs is a mission control framework. | 51d ago |
| CVE-2026-14890 | 9.1 | — | — | — | lmsys / sglang | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface | 51d ago |
| CVE-2026-26718 | 9.1 | — | — | — | — | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows | 52d ago |
| CVE-2026-53512 | 9.1 | — | — | — | better-auth / better auth | Better Auth is an authentication and authorization library for TypeScript. | 52d ago |
| CVE-2026-43637 | 9.1 | — | — | — | — | Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary fi | 52d ago |
| CVE-2026-48807 | 9.1 | — | — | — | symfony / twig | Twig is a template language for PHP. | 53d ago |
| CVE-2026-48806 | 9.1 | — | — | — | symfony / twig | Twig is a template language for PHP. | 53d ago |
| CVE-2026-48805 | 9.1 | — | — | — | symfony / twig | Twig is a template language for PHP. | 53d ago |
| CVE-2026-45363 | 9.1 | — | — | — | — | ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. | 53d ago |
| CVE-2026-53486 | 9.1 | — | — | — | — | The decompress package for Node.js extracts archives. | 53d ago |
| CVE-2026-52101 | 9.1 | — | — | — | — | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive informatio | 53d ago |
| CVE-2026-48324 | 9.1 | — | — | — | adobe / coldfusion | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 53d ago |
| CVE-2026-48319 | 9.1 | — | — | — | adobe / coldfusion | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner | 53d ago |
| CVE-2026-48358 | 9.1 | — | — | — | adobe / commerce | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitr | 53d ago |
| CVE-2026-45069 | 9.1 | — | — | — | sensiolabs / symfony | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 53d ago |
| CVE-2026-45063 | 9.1 | — | — | — | sensiolabs / symfony | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 53d ago |
| CVE-2026-55040exploited | 9.1 | 39.7% | 4/4 | +29d | microsoft / sharepoint server | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature ov | 53d ago |
| CVE-2026-15747 | 9.1 | — | — | — | — | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a | 53d ago |
| CVE-2026-54058 | 9.1 | — | — | — | python / pillow | Pillow is a Python imaging library. | 53d ago |
| CVE-2026-60082 | 9.1 | — | — | — | — | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. | 53d ago |