| CVE-2026-15265 | 9.1 | — | — | — | tenable / nessus agent | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write | 53d ago |
| CVE-2026-58319 | 9.1 | — | — | — | apache / doris | Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. | 53d ago |
| CVE-2026-3014 | 9.1 | — | — | — | — | Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnera | 53d ago |
| CVE-2026-59084 | 9.1 | — | — | — | apache / tomcat | Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure t | 53d ago |
| CVE-2026-59083 | 9.1 | — | — | — | apache / tomcat | Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security c | 53d ago |
| CVE-2026-44761 | 9.1 | — | — | — | — | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating fro | 54d ago |
| CVE-2026-27690 | 9.1 | — | — | — | — | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a speciall | 54d ago |
| CVE-2026-58102 | 9.1 | — | — | — | jonasbn / crypt\ | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extensi | 54d ago |
| CVE-2026-62327 | 9.1 | — | — | — | — | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote | 54d ago |
| CVE-2026-51541 | 9.1 | — | — | — | opener project / opener | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed expli | 54d ago |
| CVE-2026-51538 | 9.1 | — | — | — | opener project / opener | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling | 54d ago |
| CVE-2026-51537 | 9.1 | — | — | — | opener project / opener | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of Forw | 54d ago |
| CVE-2026-51536 | 9.1 | — | — | — | opener project / opener | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the lengt | 54d ago |
| CVE-2026-58409 | 9.1 | — | — | — | — | ChurchCRM is an open-source church management system. | 54d ago |
| CVE-2026-13221 | 9.1 | — | — | — | perl / perl | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more tha | 54d ago |
| CVE-2026-40469 | 9.1 | — | — | — | fossies / gawk | Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). | 54d ago |
| CVE-2026-40468 | 9.1 | — | — | — | fossies / gawk | Integer overflow vulnerability has been found in "builtin.c" program file of gawk. | 54d ago |
| CVE-2026-41041 | 9.1 | — | — | — | apache / gravitino | URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. | 54d ago |
| CVE-2026-57830 | 9.1 | — | — | — | ollyo / helix ultimate | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla | 54d ago |
| CVE-2026-11964 | 9.1 | — | — | — | — | The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming paym | 55d ago |
| CVE-2026-56260 | 9.1 | — | — | — | kidocode / crawl4ai | Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /p | 55d ago |
| CVE-2026-15089 | 9.1 | — | — | — | — | Vulnerability in Drupal Commerce guest registration. | 57d ago |
| CVE-2026-57158 | 9.1 | — | — | — | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 57d ago |
| CVE-2026-51119 | 9.1 | — | — | — | — | An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppU | 57d ago |
| CVE-2026-61444 | 9.1 | — | — | — | — | PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file par | 57d ago |
| CVE-2026-56688 | 9.1 | — | — | — | dell / powerflex manager | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used i | 57d ago |
| CVE-2026-40005 | 9.1 | — | — | — | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. | 57d ago |
| CVE-2026-15300 | 9.1 | — | — | — | — | The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters | 58d ago |
| CVE-2026-58122 | 9.1 | — | — | — | — | Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote at | 58d ago |
| CVE-2026-59826 | 9.1 | — | — | — | metabase / metabase | Metabase is an open-source business intelligence and embedded analytics tool. | 58d ago |
| CVE-2026-51597 | 9.1 | — | — | — | — | MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authe | 58d ago |
| CVE-2026-14261 | 9.1 | — | — | — | — | A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstall | 58d ago |
| CVE-2026-47826 | 9.1 | — | — | — | cloudfoundry / bosh cli | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files an | 59d ago |
| CVE-2026-55471 | 9.1 | — | — | — | hapifhir / hl7 fhir core | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. | 59d ago |
| CVE-2026-9074 | 9.1 | — | — | — | ibm / api connect | IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection v | 59d ago |
| CVE-2026-54061 | 9.1 | — | — | — | — | Dgraph is an open source distributed GraphQL database. | 59d ago |
| CVE-2026-41042 | 9.1 | — | — | — | — | Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrar | 59d ago |
| CVE-2026-14487 | 9.1 | — | — | — | — | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa | 60d ago |
| CVE-2026-14740 | 9.1 | — | — | — | perl / dbi | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. | 60d ago |
| CVE-2026-46354 | 9.1 | — | — | — | coder / coder | Coder allows organizations to provision remote development environments via Terraform. | 60d ago |
| CVE-2026-58473 | 9.1 | — | — | — | — | Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to ove | 60d ago |
| CVE-2026-5268 | 9.1 | — | — | — | — | An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena produc | 61d ago |
| CVE-2025-53830 | 9.1 | — | — | — | — | Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ow | 61d ago |
| CVE-2025-53827 | 9.1 | — | — | — | — | ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud | 61d ago |
| CVE-2026-48205 | 9.1 | — | — | — | apache / camel | Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. | 61d ago |
| CVE-2026-48203 | 9.1 | — | — | — | apache / camel | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input | 61d ago |
| CVE-2026-40047 | 9.1 | — | — | — | apache / camel | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel D | 61d ago |
| CVE-2026-24013 | 9.1 | — | — | — | apache / iotdb | Authentication Bypass by Spoofing vulnerability in Apache IoTDB. | 61d ago |
| CVE-2026-6382 | 9.1 | — | — | — | — | The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager | 61d ago |
| CVE-2026-26247 | 9.1 | — | — | — | — | Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, | 64d ago |
| CVE-2026-26232 | 9.1 | — | — | — | — | Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior | 64d ago |
| CVE-2026-25718 | 9.1 | — | — | — | — | Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template pr | 64d ago |
| CVE-2026-22547 | 9.1 | — | — | — | — | Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited | 64d ago |
| CVE-2026-20706 | 9.1 | — | — | — | — | Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the w | 64d ago |
| CVE-2026-56015 | 9.1 | — | — | — | — | Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. | 64d ago |
| CVE-2026-8927 | 9.1 | — | — | — | haxx / curl | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl | 65d ago |
| CVE-2026-8926 | 9.1 | — | — | — | haxx / curl | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(w | 65d ago |
| CVE-2026-8924 | 9.1 | — | — | — | haxx / curl | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public | 65d ago |
| CVE-2026-11564 | 9.1 | — | — | — | haxx / curl | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them ma | 65d ago |
| CVE-2026-9725 | 9.1 | — | — | — | — | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File De | 65d ago |