| CVE-2026-45550 | 9.1 | critical | — | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. | 87d ago |
| CVE-2026-9067 | 9.1 | critical | — | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its fron | 87d ago |
| CVE-2026-26241 | 9.1 | critical | qnap / file station | A buffer overflow vulnerability has been reported to affect File Station 5. | 88d ago |
| CVE-2026-26240 | 9.1 | critical | qnap / file station | A buffer overflow vulnerability has been reported to affect File Station 5. | 88d ago |
| CVE-2026-36727 | 9.1 | critical | — | An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to | 88d ago |
| CVE-2026-49840 | 9.1 | critical | freeswitch / freeswitch | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switch | 88d ago |
| CVE-2026-45602 | 9.1 | critical | microsoft / windows 10 1607 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | 88d ago |
| CVE-2026-34182 | 9.1 | critical | openssl / openssl | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the | 88d ago |
| CVE-2025-10263 | 9.1 | critical | — | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cor | 88d ago |
| CVE-2009-10007 | 9.1 | critical | — | Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. | 88d ago |
| CVE-2026-46440 | 9.1 | critical | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-42535 | 9.1 | critical | apache / http server | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipu | 89d ago |
| CVE-2026-36500 | 9.1 | critical | — | An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a direc | 92d ago |
| CVE-2026-9270 | 9.1 | critical | binary / datadog\ | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. | 92d ago |
| CVE-2026-48579 | 9.1 | critical | microsoft / exchange online | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a | 93d ago |
| CVE-2026-11153 | 9.1 | critical | google / chrome | Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to lea | 93d ago |
| CVE-2026-48040 | 9.1 | critical | netty / netty-incubator-codec-ohttp | The netty incubator codec.bhttp is a java language binary http parser. | 93d ago |
| CVE-2026-50076 | 9.1 | critical | apache / fory | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 | 93d ago |
| CVE-2026-50225 | 9.1 | critical | acer / connect m6e 5g firmware | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated sys | 93d ago |
| CVE-2026-46266 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop | 94d ago |
| CVE-2026-46244 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff des | 94d ago |
| CVE-2026-8644 | 9.1 | critical | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | 96d ago |
| CVE-2026-22872 | 9.1 | critical | projectcapsule / capsule | Capsule is a multi-tenancy and policy-based framework for Kubernetes. | 96d ago |
| CVE-2026-42682 | 9.1 | critical | — | Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Contr | 96d ago |
| CVE-2026-42252 | 9.1 | critical | apache / airflow | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags" | 96d ago |
| CVE-2026-48188 | 9.1 | critical | otrs / otrs | An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an u | 97d ago |
| CVE-2026-9051 | 9.1 | critical | — | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allo | 99d ago |
| CVE-2026-44650 | 9.1 | critical | — | SillyTavern is a locally installed user interface that allows users to interact with text generation large languag | 99d ago |
| CVE-2026-5386 | 9.1 | critical | — | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. | 99d ago |
| CVE-2026-4290 | 9.1 | critical | — | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/trave | 99d ago |
| CVE-2025-41268 | 9.1 | critical | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 | 99d ago |
| CVE-2026-46819 | 9.1 | critical | oracle / e-business suite | Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal | 100d ago |
| CVE-2026-45787 | 9.1 | critical | electerm project / electerm | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. | 100d ago |
| CVE-2026-9098 | 9.1 | critical | — | In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed S | 100d ago |
| CVE-2026-9092 | 9.1 | critical | — | Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable acc | 100d ago |
| CVE-2026-9090 | 9.1 | critical | — | Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by su | 100d ago |
| CVE-2026-46185 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_ | 100d ago |
| CVE-2026-46155 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_com | 100d ago |
| CVE-2026-46119 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth | 100d ago |
| CVE-2026-7876 | 9.1 | critical | ibm / aspera high-speed transfer server for cloud pak for integration | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. | 101d ago |
| CVE-2026-46043 | 9.1 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload | 101d ago |
| CVE-2026-49002 | 9.1 | critical | — | Access control failure means that an application does not effectively check user access permissions, so that unaut | 101d ago |
| CVE-2026-8450 | 9.1 | critical | — | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). | 102d ago |
| CVE-2026-44449 | 9.1 | critical | — | Lumiverse is a full-featured AI chat application. | 102d ago |
| CVE-2026-44444 | 9.1 | critical | — | Lumiverse is a full-featured AI chat application. | 102d ago |
| CVE-2026-42496 | 9.1 | critical | archive\ / \ | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extractio | 103d ago |
| CVE-2026-33843 | 9.1 | critical | microsoft / entra id | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unautho | 106d ago |
| CVE-2026-42508 | 9.1 | critical | golang / crypto | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. | 107d ago |
| CVE-2026-39834 | 9.1 | critical | golang / crypto | When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal pa | 107d ago |
| CVE-2026-39833 | 9.1 | critical | golang / crypto | The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but nev | 107d ago |
| CVE-2026-39832 | 9.1 | critical | golang / crypto | When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not se | 107d ago |
| CVE-2026-39831 | 9.1 | critical | golang / crypto | The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.co | 107d ago |
| CVE-2026-39830 | 9.1 | critical | golang / crypto | A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the conn | 107d ago |
| CVE-2026-33000 | 9.1 | critical | ui / unifi os server | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulner | 107d ago |
| CVE-2026-5433 | 9.1 | critical | — | Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. | 107d ago |
| CVE-2026-47372 | 9.1 | critical | — | Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. | 108d ago |
| CVE-2026-8598 | 9.1 | critical | — | An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. | 108d ago |
| CVE-2026-8602 | 9.1 | critical | scadabr / scadabr | In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticat | 109d ago |
| CVE-2026-31071 | 9.1 | critical | — | API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. | 109d ago |
| CVE-2026-2586 | 9.1 | critical | eclipse / glassfish | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. | 109d ago |