| CVE-2026-61066 | 9.9 | critical | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 18d ago |
| CVE-2026-61021 | 9.9 | critical | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 18d ago |
| CVE-2026-61003 | 9.9 | critical | oracle / managed file transfer | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Serv | 18d ago |
| CVE-2026-60995 | 9.9 | critical | oracle / identity manager connector | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | 18d ago |
| CVE-2026-60990 | 9.9 | critical | oracle / identity manager connector | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | 18d ago |
| CVE-2026-60916 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 18d ago |
| CVE-2026-60730 | 9.9 | critical | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). | 18d ago |
| CVE-2026-60720 | 9.9 | critical | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 18d ago |
| CVE-2026-60702 | 9.9 | critical | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | 18d ago |
| CVE-2026-75877 | 9.9 | critical | — | A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. | 18d ago |
| CVE-2026-55166 | 9.9 | critical | — | Lemur manages TLS certificate creation. | 18d ago |
| CVE-2026-66627 | 9.9 | critical | — | Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. | 18d ago |
| CVE-2026-32474 | 9.9 | critical | — | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | 18d ago |
| CVE-2026-32463 | 9.9 | critical | — | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | 18d ago |
| CVE-2026-32444 | 9.9 | critical | — | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | 18d ago |
| CVE-2026-75851 | 9.9 | critical | — | ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated | 18d ago |
| CVE-2026-75843 | 9.9 | critical | — | ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginT | 18d ago |
| CVE-2026-66795 | 9.9 | critical | — | A flaw was found in the managedcluster-import-controller. | 19d ago |
| CVE-2026-65974 | 9.9 | critical | — | ERPNext is a free and open source Enterprise Resource Planning tool. | 19d ago |
| CVE-2026-47686 | 9.9 | critical | — | vm2 is an open source vm/sandbox for Node.js. | 19d ago |
| CVE-2026-66792 | 9.9 | critical | — | A flaw was found in the multicloud-operators-subscription component. | 19d ago |
| CVE-2026-19961 | 9.9 | critical | — | A vulnerability was detected in Edimax EW-7478APC 1.04. | 20d ago |
| CVE-2026-19959 | 9.9 | critical | — | A weakness has been identified in Edimax EW-7478APC 1.04. | 20d ago |
| CVE-2026-72493 | 9.9 | critical | — | In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() check in enqueu | 21d ago |
| CVE-2026-17186 | 9.9 | critical | ibm / db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to impro | 22d ago |
| CVE-2026-19682 | 9.9 | critical | tenable / security center | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit | 22d ago |
| CVE-2026-19681 | 9.9 | critical | tenable / security center | An authenticated command injection vulnerability exists in Security Center related to file upload processing. | 22d ago |
| CVE-2026-19626 | 9.9 | critical | tenable / security center | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. | 22d ago |
| CVE-2026-72842 | 9.9 | critical | — | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to ac | 23d ago |
| CVE-2026-72841 | 9.9 | critical | — | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticate | 23d ago |
| CVE-2026-73656 | 9.9 | critical | — | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. | 23d ago |
| CVE-2026-73602 | 9.9 | critical | flowiseai / flowise | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticat | 23d ago |
| CVE-2026-66898 | 9.9 | critical | — | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and | 24d ago |
| CVE-2026-73269 | 9.9 | critical | — | A flaw was found in the cluster-curator-controller component. | 24d ago |
| CVE-2026-73268 | 9.9 | critical | — | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). | 24d ago |
| CVE-2026-72508 | 9.9 | critical | — | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) | 24d ago |
| CVE-2026-63300 | 9.9 | critical | — | An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows a | 24d ago |
| CVE-2026-63299 | 9.9 | critical | — | An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume | 24d ago |
| CVE-2026-63298 | 9.9 | critical | — | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allow | 24d ago |
| CVE-2026-63297 | 9.9 | critical | — | An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authentic | 24d ago |
| CVE-2026-63296 | 9.9 | critical | — | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restriction | 24d ago |
| CVE-2026-63294 | 9.9 | critical | — | A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. | 24d ago |
| CVE-2026-63293 | 9.9 | critical | canonical / lxd | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on th | 24d ago |
| CVE-2026-62420 | 9.9 | critical | — | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security re | 24d ago |
| CVE-2026-19656 | 9.9 | critical | scada-lts / scada-lts | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (in | 24d ago |
| CVE-2026-16860 | 9.9 | critical | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncon | 24d ago |
| CVE-2026-73294 | 9.9 | critical | — | Semaphore UI is a web interface for managing DevOps tools. | 24d ago |
| CVE-2026-73263 | 9.9 | critical | — | Prowler is a cloud security platform. | 24d ago |
| CVE-2026-72526 | 9.9 | critical | — | A flaw was found in the multicloud-integrations component. | 25d ago |
| CVE-2026-48765 | 9.9 | critical | — | TypeBot is a chatbot builder tool. | 25d ago |
| CVE-2026-72765 | 9.9 | critical | n8n / n8n | n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. | 25d ago |
| CVE-2026-72603 | 9.9 | critical | — | An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute | 25d ago |
| CVE-2026-72911 | 9.9 | critical | — | ERPNext is a free and open source Enterprise Resource Planning tool. | 26d ago |
| CVE-2026-18948 | 9.9 | critical | — | A flaw was found in Feast. | 26d ago |
| CVE-2026-14450 | 9.9 | critical | — | A flaw was found in the MaaS API. | 26d ago |
| CVE-2026-72902 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72901 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72886 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72882 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72880 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |