| CVE-2026-49454 | 9.1 | critical | — | Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. | 79d ago |
| CVE-2026-11718 | 9.1 | critical | google / mcp toolbox for databases | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of | 79d ago |
| CVE-2026-11717 | 9.1 | critical | google / mcp toolbox for databases | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of | 79d ago |
| CVE-2026-54388 | 9.1 | critical | — | Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length hea | 80d ago |
| CVE-2026-54387 | 9.1 | critical | — | Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Enco | 80d ago |
| CVE-2026-48814 | 9.1 | critical | — | Network-AI is a TypeScript/Node.js multi-agent orchestrator. | 80d ago |
| CVE-2026-55196 | 9.1 | critical | — | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints tha | 80d ago |
| CVE-2026-3894 | 9.1 | critical | rti / connext professional | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue af | 80d ago |
| CVE-2026-30803 | 9.1 | critical | rti / connext micro | Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers | 80d ago |
| CVE-2026-20266 | 9.1 | critical | splunk / ai toolkit | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS com | 80d ago |
| CVE-2026-36418 | 9.1 | critical | — | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator ex | 80d ago |
| CVE-2026-20181 | 9.1 | critical | cisco / identity services engine | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary comman | 80d ago |
| CVE-2026-49268 | 9.1 | critical | apache / shiro | A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapR | 80d ago |
| CVE-2026-50203 | 9.1 | critical | apache / apache-airflow-providers-sftp | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malici | 80d ago |
| CVE-2026-32967 | 9.1 | critical | apache / dolphinscheduler | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. | 80d ago |
| CVE-2026-24611 | 9.1 | critical | — | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. | 80d ago |
| CVE-2026-46949 | 9.1 | critical | oracle / advanced outbound telephony | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Op | 80d ago |
| CVE-2026-46946 | 9.1 | critical | oracle / isupport | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | 80d ago |
| CVE-2026-46945 | 9.1 | critical | oracle / isupport | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | 80d ago |
| CVE-2026-46944 | 9.1 | critical | oracle / isupport | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | 80d ago |
| CVE-2026-46930 | 9.1 | critical | oracle / in-memory cost management for discrete industries | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite ( | 80d ago |
| CVE-2026-46910 | 9.1 | critical | oracle / jd edwards enterpriseone tools | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastruc | 80d ago |
| CVE-2026-46896 | 9.1 | critical | oracle / enterprise command center framework | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Cor | 80d ago |
| CVE-2026-46892 | 9.1 | critical | oracle / jd edwards enterpriseone human resources management | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: | 80d ago |
| CVE-2026-46875 | 9.1 | critical | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Depl | 80d ago |
| CVE-2026-46858 | 9.1 | critical | oracle / application performance management | Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JAD | 80d ago |
| CVE-2026-46809 | 9.1 | critical | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 80d ago |
| CVE-2026-46784 | 9.1 | critical | oracle / webcenter content | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). | 80d ago |
| CVE-2026-46777 | 9.1 | critical | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 80d ago |
| CVE-2026-35298 | 9.1 | critical | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). | 80d ago |
| CVE-2026-35270 | 9.1 | critical | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 80d ago |
| CVE-2026-22313 | 9.1 | critical | — | The device has a webserver that exposes a REST API authenticated with a token on the management network. | 81d ago |
| CVE-2026-53776 | 9.1 | critical | — | Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expirat | 81d ago |
| CVE-2026-12316 | 9.1 | critical | mozilla / firefox | Mitigation bypass in the DOM: Security component. | 81d ago |
| CVE-2026-12315 | 9.1 | critical | mozilla / firefox | Mitigation bypass in the DOM: Security component. | 81d ago |
| CVE-2026-12304 | 9.1 | critical | mozilla / firefox | Same-origin policy bypass in the Networking: Cookies component. | 81d ago |
| CVE-2026-12205 | 9.1 | critical | — | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. | 82d ago |
| CVE-2026-48714 | 9.1 | critical | i18next / i18next-http-middleware | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also fo | 82d ago |
| CVE-2026-48713 | 9.1 | critical | i18next / i18next-fs-backend | Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist | 82d ago |
| CVE-2026-12087 | 9.1 | critical | — | Socket versions before 2.041 for Perl have an out-of-bounds heap read. | 82d ago |
| CVE-2026-11832 | 9.1 | critical | — | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. | 82d ago |
| CVE-2026-48881 | 9.1 | critical | — | Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. | 82d ago |
| CVE-2026-39465 | 9.1 | critical | — | Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions. | 82d ago |
| CVE-2026-50887 | 9.1 | critical | — | A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows | 82d ago |
| CVE-2026-50886 | 9.1 | critical | — | Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to sca | 82d ago |
| CVE-2026-49952 | 9.1 | critical | — | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauth | 82d ago |
| CVE-2026-45390 | 9.1 | critical | — | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current workin | 82d ago |
| CVE-2026-45388 | 9.1 | critical | — | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the s | 82d ago |
| CVE-2026-30121 | 9.1 | critical | remotion / remotion | remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability. | 82d ago |
| CVE-2026-53609 | 9.1 | critical | — | ApostropheCMS is an open-source Node.js content management system. | 85d ago |
| CVE-2026-53519 | 9.1 | critical | — | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. | 85d ago |
| CVE-2026-44172 | 9.1 | critical | mariadb / mariadb | MariaDB server is a community developed fork of MySQL server. | 85d ago |
| CVE-2026-50091 | 9.1 | critical | aqara / home | Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) | 85d ago |
| CVE-2026-50083 | 9.1 | critical | aqara / iam\/sso gateway | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of | 85d ago |
| CVE-2026-50627 | 9.1 | critical | apache / cxf | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT acce | 85d ago |
| CVE-2026-45177 | 9.1 | critical | paloaltonetworks / idira secrets manager edge | Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authenti | 86d ago |
| CVE-2026-9648 | 9.1 | critical | — | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept | 86d ago |
| CVE-2026-0274 | 9.1 | critical | paloaltonetworks / cortex xsiam commvaultsecurityiq marketplace | An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cor | 87d ago |
| CVE-2026-50638 | 9.1 | critical | pevans / metrics\ | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. | 87d ago |
| CVE-2026-53469 | 9.1 | critical | kebev2v / migration assessment | A flaw was found in migration-planner. | 87d ago |