| CVE-2026-33351 | 9.1 | critical | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33297 | 9.1 | critical | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-4599 | 9.1 | critical | kjur / jsrsasign | Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing | 166d ago |
| CVE-2026-24060 | 9.1 | critical | — | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, interce | 169d ago |
| CVE-2026-33210 | 9.1 | critical | ruby-lang / json | Ruby JSON is a JSON implementation for Ruby. | 169d ago |
| CVE-2026-33186 | 9.1 | critical | grpc / grpc | gRPC-Go is the Go language implementation of gRPC. | 169d ago |
| CVE-2025-59383 | 9.1 | critical | qnap / media streaming add-on | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. | 169d ago |
| CVE-2026-33024 | 9.1 | critical | wwbn / avideo-encoder | AVideo is a video-sharing Platform. | 170d ago |
| CVE-2026-32817 | 9.1 | critical | admidio / admidio | Admidio is an open-source user management solution. | 170d ago |
| CVE-2026-29103 | 9.1 | critical | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-22732 | 9.1 | critical | vmware / spring security | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possi | 170d ago |
| CVE-2026-32238 | 9.1 | critical | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-27067 | 9.1 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows | 170d ago |
| CVE-2025-15031 | 9.1 | critical | lfprojects / mlflow | A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of | 171d ago |
| CVE-2026-32698 | 9.1 | critical | openproject / openproject | OpenProject is an open-source, web-based project management software. | 171d ago |
| CVE-2026-31967 | 9.1 | critical | htslib / htslib | HTSlib is a library for reading and writing bioinformatics file formats. | 171d ago |
| CVE-2026-31966 | 9.1 | critical | htslib / htslib | HTSlib is a library for reading and writing bioinformatics file formats. | 171d ago |
| CVE-2026-32633 | 9.1 | critical | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 171d ago |
| CVE-2026-30704 | 9.1 | critical | — | The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessibl | 171d ago |
| CVE-2026-30701 | 9.1 | critical | — | The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disc | 171d ago |
| CVE-2026-32298 | 9.1 | critical | angeet / es3 kvm firmware | The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an | 172d ago |
| CVE-2026-25770 | 9.1 | critical | wazuh / wazuh | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 172d ago |
| CVE-2026-25769 | 9.1 | critical | wazuh / wazuh | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 172d ago |
| CVE-2026-25534 | 9.1 | critical | — | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for cl | 172d ago |
| CVE-2026-4177 | 9.1 | critical | toddr / yaml\ | YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity | 173d ago |
| CVE-2025-69808 | 9.1 | critical | p2r3 / bareiron | An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sen | 173d ago |
| CVE-2026-27962 | 9.1 | critical | authlib / authlib | Authlib is a Python library which builds OAuth and OpenID Connect servers. | 173d ago |
| CVE-2026-23489 | 9.1 | critical | teclib-edition / fields | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. | 173d ago |
| CVE-2026-32367 | 9.1 | critical | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dia | 176d ago |
| CVE-2026-31886 | 9.1 | critical | dagu / dagu | Dagu is a workflow engine with a built-in Web user interface. | 176d ago |
| CVE-2026-25818 | 9.1 | critical | — | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmw | 176d ago |
| CVE-2026-21671 | 9.1 | critical | veeam / veeam backup \& replication | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution | 177d ago |
| CVE-2026-32133 | 9.1 | critical | 2fauth / 2fauth | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. | 178d ago |
| CVE-2026-27478 | 9.1 | critical | unitycatalog / unitycatalog | Unity Catalog is an open, multi-modal Catalog for data and AI. | 178d ago |
| CVE-2026-31862 | 9.1 | critical | cloudcli / cloud cli | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. | 178d ago |
| CVE-2026-84803 | 9 | critical | — | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete ex | 3d ago |
| CVE-2026-84324 | 9 | critical | google / chrome | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary cod | 4d ago |
| CVE-2026-75604 | 9 | critical | — | Next.js is a React framework for building full-stack web applications. | 4d ago |
| CVE-2026-73701 | 9 | critical | arubanetworks / fabric composer | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking | 4d ago |
| CVE-2026-73700 | 9 | critical | arubanetworks / fabric composer | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticat | 4d ago |
| CVE-2026-79687 | 9 | critical | — | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. | 4d ago |
| CVE-2026-84200 | 9 | critical | — | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. | 4d ago |
| CVE-2026-40541 | 9 | critical | — | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract d | 8d ago |
| CVE-2026-77551 | 9 | critical | — | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control | 10d ago |
| CVE-2026-77549 | 9 | critical | — | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization | 10d ago |
| CVE-2026-77545 | 9 | critical | — | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active | 10d ago |
| CVE-2026-62674 | 9 | critical | — | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. | 15d ago |
| CVE-2026-32475 | 9 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Fi | 17d ago |
| CVE-2026-72530exploited | 9 | critical | trueconf / trueconf server | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3. | 17d ago |
| CVE-2026-18937 | 9 | critical | — | The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user i | 17d ago |
| CVE-2026-70980 | 9 | critical | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-62988 | 9 | critical | — | Froxlor is open source server administration software. | 18d ago |
| CVE-2026-61029 | 9 | critical | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 18d ago |
| CVE-2026-75625 | 9 | critical | — | Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committin | 18d ago |
| CVE-2026-75130 | 9 | critical | — | Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instru | 18d ago |
| CVE-2026-14564 | 9 | critical | — | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd | 19d ago |
| CVE-2026-74800 | 9 | critical | — | SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary fi | 19d ago |
| CVE-2026-73053 | 9 | critical | — | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fail | 21d ago |
| CVE-2026-73052 | 9 | critical | — | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into o | 21d ago |
| CVE-2026-73050 | 9 | critical | — | SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowin | 21d ago |