| CVE-2026-8948 | 9.1 | critical | mozilla / firefox | Same-origin policy bypass in the DOM: Networking component. | 109d ago |
| CVE-2026-41919 | 9.1 | critical | apache / ofbiz | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz | 109d ago |
| CVE-2026-31986 | 9.1 | critical | apache / ofbiz | Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. | 109d ago |
| CVE-2026-45230 | 9.1 | critical | — | DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesT | 110d ago |
| CVE-2023-24215 | 9.1 | critical | — | Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated att | 110d ago |
| CVE-2026-41947 | 9.1 | critical | dify / dify | Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users t | 110d ago |
| CVE-2026-7302 | 9.1 | critical | lmsys / sglang | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an | 110d ago |
| CVE-2026-44551 | 9.1 | critical | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 113d ago |
| CVE-2026-45010 | 9.1 | critical | — | phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the / | 113d ago |
| CVE-2026-41258 | 9.1 | critical | — | OpenMRS is an open source electronic medical record system platform. | 113d ago |
| CVE-2026-8634 | 9.1 | critical | — | Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access | 114d ago |
| CVE-2026-44542 | 9.1 | critical | gtsteffaniak / filebrowser quantum | FileBrowser Quantum is a free, self-hosted, web-based file manager. | 114d ago |
| CVE-2026-42555 | 9.1 | critical | — | Valtimo is an open-source business process automation platform. | 114d ago |
| CVE-2026-6512 | 9.1 | critical | — | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, | 114d ago |
| CVE-2026-45158 | 9.1 | critical | opnsense / opnsense | OPNsense is a FreeBSD based firewall and routing platform. | 115d ago |
| CVE-2026-44194 | 9.1 | critical | opnsense / opnsense | OPNsense is a FreeBSD based firewall and routing platform. | 115d ago |
| CVE-2026-44193 | 9.1 | critical | opnsense / opnsense | OPNsense is a FreeBSD based firewall and routing platform. | 115d ago |
| CVE-2026-45714 | 9.1 | critical | — | CubeCart is an ecommerce software solution. | 115d ago |
| CVE-2026-45053 | 9.1 | critical | — | CubeCart is an ecommerce software solution. | 115d ago |
| CVE-2026-44377 | 9.1 | critical | — | CubeCart is an ecommerce software solution. | 115d ago |
| CVE-2026-44351 | 9.1 | critical | — | fast-jwt provides fast JSON Web Token (JWT) implementation. | 115d ago |
| CVE-2026-42032 | 9.1 | critical | okfn / ckan | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. | 115d ago |
| CVE-2026-0258 | 9.1 | critical | paloaltonetworks / pan-os | A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® softwa | 115d ago |
| CVE-2026-0257exploited | 9.1 | critical | paloaltonetworks / pan-os | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® softwar | 115d ago |
| CVE-2026-44007 | 9.1 | critical | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-41225 | 9.1 | critical | f5 / big-ip access policy manager | A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manage | 115d ago |
| CVE-2025-11159 | 9.1 | critical | hitachi / vantara pentaho data integration and analytics | Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which | 115d ago |
| CVE-2026-42889 | 9.1 | critical | — | Relay adds real-time collaboration to Obsidian. | 116d ago |
| CVE-2026-44196 | 9.1 | critical | — | Pingvin Share X is a secure and easy self-hosted file sharing platform. | 116d ago |
| CVE-2026-42833 | 9.1 | critical | microsoft / dynamics 365 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an author | 116d ago |
| CVE-2026-41103 | 9.1 | critical | microsoft / confluence saml sso | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an u | 116d ago |
| CVE-2026-33117 | 9.1 | critical | microsoft / azure sdk for java | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verificatio | 116d ago |
| CVE-2026-31242 | 9.1 | critical | mem0 / mem0 | The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessib | 116d ago |
| CVE-2026-29204 | 9.1 | critical | — | Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using | 116d ago |
| CVE-2026-43515 | 9.1 | critical | apache / tomcat | Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension | 116d ago |
| CVE-2026-31216 | 9.1 | critical | nexent / nexent | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its | 116d ago |
| CVE-2026-31215 | 9.1 | critical | nexent / nexent | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticS | 116d ago |
| CVE-2026-30805 | 9.1 | critical | artica / pandora fms | Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. | 116d ago |
| CVE-2026-45091 | 9.1 | critical | — | sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. | 116d ago |
| CVE-2026-41551 | 9.1 | critical | — | A vulnerability has been identified in ROS# (All versions < V2.2.2). | 116d ago |
| CVE-2026-25787 | 9.1 | critical | — | Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control | 116d ago |
| CVE-2026-25786 | 9.1 | critical | — | Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters | 116d ago |
| CVE-2026-22924 | 9.1 | critical | siemens / simatic cn 4100 firmware | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). | 116d ago |
| CVE-2025-40949 | 9.1 | critical | siemens / ruggedcom rox mx5000 firmware | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All | 116d ago |
| CVE-2026-42608 | 9.1 | critical | getgrav / grav | Grav is a file-based Web platform. | 117d ago |
| CVE-2026-42607 | 9.1 | critical | — | Grav is a file-based Web platform. | 117d ago |
| CVE-2026-6104 | 9.1 | critical | php / php | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte i | 118d ago |
| CVE-2026-33409 | 9.1 | critical | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 165d ago |
| CVE-2026-33407 | 9.1 | critical | wallosapp / wallos | Wallos is an open-source, self-hostable personal subscription tracker. | 165d ago |
| CVE-2026-33340 | 9.1 | critical | lollms / lollms web ui | LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. | 165d ago |
| CVE-2026-4724 | 9.1 | critical | mozilla / firefox | Undefined behavior in the Audio/Video component. | 165d ago |
| CVE-2026-4716 | 9.1 | critical | mozilla / firefox | Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. | 165d ago |
| CVE-2026-4715 | 9.1 | critical | mozilla / firefox | Uninitialized memory in the Graphics: Canvas2D component. | 165d ago |
| CVE-2026-33475 | 9.1 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 165d ago |
| CVE-2026-4753 | 9.1 | critical | — | Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72. | 165d ago |
| CVE-2026-4750 | 9.1 | critical | — | Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0. | 165d ago |
| CVE-2026-4283 | 9.1 | critical | — | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up | 166d ago |
| CVE-2026-33286 | 9.1 | critical | graphiti / graphiti | Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. | 166d ago |
| CVE-2026-33202 | 9.1 | critical | rubyonrails / rails | Active Storage allows users to attach cloud and local files in Rails applications. | 166d ago |
| CVE-2025-60949 | 9.1 | critical | csprousers / csweb | Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. | 166d ago |