| CVE-2026-38971 | 9.1 | critical | ardupilot / arduplane | ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial | 65d ago |
| CVE-2026-59099 | 9.1 | critical | — | Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attack | 65d ago |
| CVE-2026-54400 | 9.1 | critical | ui / unifi access | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerab | 65d ago |
| CVE-2026-27436 | 9.1 | critical | — | Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. | 65d ago |
| CVE-2026-23537 | 9.1 | critical | — | A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthe | 66d ago |
| CVE-2026-14198 | 9.1 | critical | fastify / fastify\/middie | @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matc | 66d ago |
| CVE-2026-7839 | 9.1 | critical | uvnc / ultravnc | UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. | 67d ago |
| CVE-2026-6070 | 9.1 | critical | — | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions | 67d ago |
| CVE-2026-56278 | 9.1 | critical | flowiseai / flowise | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for t | 67d ago |
| CVE-2026-13872 | 9.1 | critical | google / chrome | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 al | 67d ago |
| CVE-2026-13852 | 9.1 | critical | google / chrome | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 al | 67d ago |
| CVE-2026-13851 | 9.1 | critical | google / chrome | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 al | 67d ago |
| CVE-2026-7874 | 9.1 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a | 67d ago |
| CVE-2026-7663 | 9.1 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resource | 67d ago |
| CVE-2026-58172 | 9.1 | critical | — | Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denie | 67d ago |
| CVE-2026-58166 | 9.1 | critical | — | OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauth | 67d ago |
| CVE-2026-6556 | 9.1 | critical | fastify / fastify\/express | @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path | 67d ago |
| CVE-2026-55276 | 9.1 | critical | apache / tomcat | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty aut | 68d ago |
| CVE-2026-53434 | 9.1 | critical | apache / tomcat | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based c | 68d ago |
| CVE-2026-39868 | 9.1 | critical | apple / ipados | This issue was addressed with improved input validation. | 68d ago |
| CVE-2026-37637 | 9.1 | critical | — | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php | 68d ago |
| CVE-2026-11720 | 9.1 | critical | google / mcp toolbox for databases | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. | 68d ago |
| CVE-2026-57658 | 9.1 | critical | — | Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. | 71d ago |
| CVE-2025-64152 | 9.1 | critical | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. | 71d ago |
| CVE-2025-55017 | 9.1 | critical | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. | 71d ago |
| CVE-2025-71327 | 9.1 | critical | flowiseai / flowise | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that | 72d ago |
| CVE-2026-56445 | 9.1 | critical | — | The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in | 72d ago |
| CVE-2026-54089 | 9.1 | critical | — | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within | 72d ago |
| CVE-2026-6094 | 9.1 | critical | wolfssl / wolfssl | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. | 72d ago |
| CVE-2026-53225 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lo | 72d ago |
| CVE-2026-53224 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address | 72d ago |
| CVE-2026-53186 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the rece | 72d ago |
| CVE-2026-55455 | 9.1 | critical | appsmith / appsmith | Appsmith is a platform to build admin panels, internal tools, and dashboards. | 73d ago |
| CVE-2026-45689 | 9.1 | critical | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. | 73d ago |
| CVE-2026-45688 | 9.1 | critical | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. | 73d ago |
| CVE-2026-53043 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match | 73d ago |
| CVE-2026-52999 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds re | 73d ago |
| CVE-2026-52958 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in | 73d ago |
| CVE-2026-56111 | 9.1 | critical | — | Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an o | 73d ago |
| CVE-2026-56237 | 9.1 | critical | — | Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. | 73d ago |
| CVE-2026-12851 | 9.1 | critical | — | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4 | 74d ago |
| CVE-2026-12850 | 9.1 | critical | — | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4 | 74d ago |
| CVE-2026-12849 | 9.1 | critical | — | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4 | 74d ago |
| CVE-2026-12486 | 9.1 | critical | — | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4 | 74d ago |
| CVE-2026-54316 | 9.1 | critical | anthropic / claude code | Claude Code is an agentic coding tool. | 74d ago |
| CVE-2026-9733 | 9.1 | critical | — | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. | 74d ago |
| CVE-2026-48746 | 9.1 | critical | vllm / vllm | vLLM is an inference and serving engine for large language models (LLMs). | 75d ago |
| CVE-2026-56348 | 9.1 | critical | n8n / n8n | n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/optio | 75d ago |
| CVE-2026-48509 | 9.1 | critical | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 75d ago |
| CVE-2026-12628 | 9.1 | critical | ibm / storage protect | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8. | 75d ago |
| CVE-2026-11373 | 9.1 | critical | — | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. | 75d ago |
| CVE-2026-9265 | 9.1 | critical | — | Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. | 78d ago |
| CVE-2026-56081 | 9.1 | critical | — | Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account | 78d ago |
| CVE-2026-9142 | 9.1 | critical | ni / instrumentstudio | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and | 78d ago |
| CVE-2026-49230 | 9.1 | critical | apache / apisix | Improper Validation of Integrity Check Value vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-48137 | 9.1 | critical | ni / instrumentstudio | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allo | 78d ago |
| CVE-2026-44087 | 9.1 | critical | apache / apisix | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. | 78d ago |
| CVE-2026-39999 | 9.1 | critical | apache / apisix | Authentication Bypass by Spoofing vulnerability in Apache APISIX. | 78d ago |
| CVE-2025-62821 | 9.1 | critical | microsoft / heif image extension | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can retu | 78d ago |
| CVE-2026-8713 | 9.1 | critical | — | The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p | 79d ago |