| CVE-2026-73044 | 9 | critical | — | SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scr | 21d ago |
| CVE-2026-73043 | 9 | critical | — | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, | 21d ago |
| CVE-2026-73042 | 9 | critical | — | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values | 21d ago |
| CVE-2026-73041 | 9 | critical | — | SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotatio | 21d ago |
| CVE-2026-72279 | 9 | critical | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-only PFN when map | 21d ago |
| CVE-2026-73842 | 9 | critical | — | OpenChoreo is a complete, open-source developer platform for Kubernetes. | 23d ago |
| CVE-2026-71471 | 9 | critical | — | A flaw was found in acm-search-v2-rhel9. | 24d ago |
| CVE-2026-48381 | 9 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 25d ago |
| CVE-2026-71851 | 9 | critical | — | crypto-js is a JavaScript library of crypto standards. | 29d ago |
| CVE-2025-14561 | 9 | critical | — | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. | 30d ago |
| CVE-2026-70426 | 9 | critical | — | In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, | 31d ago |
| CVE-2026-20267 | 9 | critical | cisco / ios xe | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee | 31d ago |
| CVE-2026-10090 | 9 | critical | — | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advan | 31d ago |
| CVE-2026-17351 | 9 | critical | pgadmin / pgadmin 4 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_ | 36d ago |
| CVE-2026-18245 | 9 | critical | amazon / amplify codegen ui | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote aut | 37d ago |
| CVE-2026-14602 | 9 | critical | — | The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied inp | 37d ago |
| CVE-2026-14289 | 9 | critical | — | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its reques | 40d ago |
| CVE-2026-16723 | 9 | critical | — | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. | 44d ago |
| CVE-2026-61223 | 9 | critical | oracle / communications converged application server | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (componen | 46d ago |
| CVE-2026-61204 | 9 | critical | oracle / peoplesoft enterprise fin program management | Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primave | 46d ago |
| CVE-2026-61201 | 9 | critical | oracle / peoplesoft enterprise crm common objects | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Obje | 46d ago |
| CVE-2026-61174 | 9 | critical | oracle / product lifecycle analytics | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Is | 46d ago |
| CVE-2026-60424 | 9 | critical | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 46d ago |
| CVE-2026-60249 | 9 | critical | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-35198 | 9 | critical | — | HeyForm is an open-source form builder. | 47d ago |
| CVE-2026-12701 | 9 | critical | — | A path traversal vulnerability was found in pulpcore. | 47d ago |
| CVE-2026-64106 | 9 | critical | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with | 48d ago |
| CVE-2026-11386 | 9 | critical | — | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-t | 51d ago |
| CVE-2026-62378 | 9 | critical | — | RustFS Console is a web management console for the RustFS distributed file system. | 52d ago |
| CVE-2026-48327 | 9 | critical | adobe / coldfusion | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution i | 53d ago |
| CVE-2026-57898 | 9 | critical | — | In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB | 53d ago |
| CVE-2026-54527 | 9 | critical | jupyter / jupyterlab-git | JupyterLab Git is a Git extension for JupyterLab. | 59d ago |
| CVE-2026-4375 | 9 | critical | — | The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be us | 60d ago |
| CVE-2026-58289 | 9 | critical | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 64d ago |
| CVE-2026-55116 | 9 | critical | ui / unifi connect | A malicious actor with access to the network and under certain network configurations could exploit an Improper Ac | 65d ago |
| CVE-2026-57623 | 9 | critical | — | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | 65d ago |
| CVE-2025-23351 | 9 | critical | — | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual fun | 66d ago |
| CVE-2025-23350 | 9 | critical | — | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual fun | 66d ago |
| CVE-2026-10539 | 9 | critical | — | A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. | 66d ago |
| CVE-2026-54636 | 9 | critical | dokku / dokku | Dokku is a docker-powered PaaS. | 71d ago |
| CVE-2026-45408 | 9 | critical | dokku / dokku | Dokku is a docker-powered PaaS. | 71d ago |
| CVE-2026-45406 | 9 | critical | dokku / dokku | Dokku is a docker-powered PaaS. | 71d ago |
| CVE-2026-45405 | 9 | critical | dokku / dokku | Dokku is a docker-powered PaaS. | 71d ago |
| CVE-2026-55570 | 9 | critical | — | SiYuan is an open-source personal knowledge management system. | 73d ago |
| CVE-2026-54157 | 9 | critical | — | LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. | 74d ago |
| CVE-2026-44792 | 9 | critical | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-11374 | 9 | critical | — | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets gen | 74d ago |
| CVE-2026-12249 | 9 | critical | — | An issue was discovered in Canonical ADSys upstream versions through v0.16.2. | 75d ago |
| CVE-2026-12046 | 9 | critical | pgadmin / pgadmin 4 | Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /s | 79d ago |
| CVE-2026-12045 | 9 | critical | pgadmin / pgadmin 4 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content t | 79d ago |
| CVE-2026-52705 | 9 | critical | — | Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. | 80d ago |
| CVE-2026-46872 | 9 | critical | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Inst | 80d ago |
| CVE-2026-35320 | 9 | critical | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 80d ago |
| CVE-2026-41005 | 9 | critical | — | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for | 86d ago |
| CVE-2026-40128 | 9 | critical | — | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP | 89d ago |
| CVE-2026-11393 | 9 | critical | — | Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 m | 89d ago |
| CVE-2026-45750 | 9 | critical | termix / termix | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 92d ago |
| CVE-2026-45746 | 9 | critical | termix / termix | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 92d ago |
| CVE-2026-36748 | 9 | critical | — | RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user prof | 94d ago |
| CVE-2026-9319 | 9 | critical | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserializati | 96d ago |