| CVE-2026-9311 | 9 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of securi | 130d ago |
| CVE-2026-45630 | 9 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 133d ago |
| CVE-2026-9891 | 9 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised | 134d ago |
| CVE-2026-9881 | 9 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a use | 134d ago |
| CVE-2026-46833 | 9 | — | — | — | oracle / database server | Vulnerability in the Net Service component of Oracle Database Server. | 134d ago |
| CVE-2026-4408 | 9 | — | — | — | redhat / openshift container platform | A flaw was found in Samba. | 135d ago |
| CVE-2026-32999 | 9 | — | — | — | — | Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant | 135d ago |
| CVE-2026-48150 | 9 | — | — | — | — | Budibase is an open-source low-code platform. | 135d ago |
| CVE-2026-45721 | 9 | — | — | — | — | Algernon is a small self-contained pure-Go web server. | 136d ago |
| CVE-2026-4480exploited | 9 | 13.9% | 1/3 | +55d | redhat / openshift container platform | A flaw was found in the Samba printing subsystem. | 136d ago |
| CVE-2026-2651 | 9 | — | — | — | lfprojects / mlflow | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints whe | 138d ago |
| CVE-2026-22314 | 9 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component | 142d ago |
| CVE-2026-45375 | 9 | — | — | — | — | SiYuan is an open-source personal knowledge management system. | 148d ago |
| CVE-2026-42457 | 9 | — | — | — | — | vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing | 148d ago |
| CVE-2026-41901 | 9 | — | — | — | — | Thymeleaf is a server-side Java template engine for web and standalone environments. | 150d ago |
| CVE-2026-44221 | 9 | — | — | — | — | ArcadeDB is a Multi-Model DBMS. | 150d ago |
| CVE-2026-33067 | 9 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 204d ago |
| CVE-2026-33066 | 9 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 204d ago |
| CVE-2026-32891 | 9 | — | — | — | openvessl / anchorr | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a | 204d ago |
| CVE-2026-32751 | 9 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 204d ago |
| CVE-2026-27540zero day | 9 | 1.6% | 1/3 | 27d before | — | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. | 205d ago |
| CVE-2026-32703 | 9 | — | — | — | openproject / openproject | OpenProject is an open-source, web-based project management software. | 205d ago |
| CVE-2026-3564zero day | 9 | 0.28% | 1/3 | same day | — | A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authent | 206d ago |
| CVE-2026-32635 | 9 | — | — | — | angular / angular cli | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and | 207d ago |
| CVE-2026-48019 | 8.9 | — | — | — | — | Laravel is a web application framework. | 35d ago |
| CVE-2026-82654 | 8.9 | — | — | — | — | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb | 40d ago |
| CVE-2026-82653 | 8.9 | — | — | — | — | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped packa | 40d ago |
| CVE-2025-30156 | 8.9 | — | — | — | — | Ceph is an open-source distributed storage platform providing object, block, and file storage. | 43d ago |
| CVE-2026-30864 | 8.9 | — | — | — | — | Combodo iTop is a web-based IT service management tool. | 46d ago |
| CVE-2026-19200 | 8.9 | — | — | — | — | The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. | 47d ago |
| CVE-2026-77638 | 8.9 | — | — | — | — | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could ma | 50d ago |
| CVE-2026-18193 | 8.9 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validat | 57d ago |
| CVE-2026-73570exploited | 8.9 | 71.7% | 3/3 | +4d | synacor / zimbra collaboration suite | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra | 57d ago |
| CVE-2026-18099 | 8.9 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to i | 58d ago |
| CVE-2026-57858 | 8.9 | — | — | — | — | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPag | 58d ago |
| CVE-2026-58154 | 8.9 | — | — | — | apache / traffic server | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. | 73d ago |
| CVE-2026-16496 | 8.9 | — | — | — | — | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stat | 73d ago |
| CVE-2024-58355 | 8.9 | — | — | — | — | Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. | 78d ago |
| CVE-2024-58353 | 8.9 | — | — | — | — | Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publi | 78d ago |
| CVE-2026-15416 | 8.9 | — | — | — | — | A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthen | 88d ago |
| CVE-2026-58424 | 8.9 | — | — | — | — | Permanent Fork PR Workflow Approval Gate Bypass | 98d ago |
| CVE-2026-52798 | 8.9 | — | — | — | — | Gogs is an open source self-hosted Git service. | 107d ago |
| CVE-2026-43984 | 8.9 | — | — | — | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. | 127d ago |
| CVE-2026-42611 | 8.9 | — | — | — | getgrav / grav | Grav is a file-based Web platform. | 151d ago |
| CVE-2026-31889 | 8.9 | — | — | — | shopware / shopware | Shopware is an open commerce platform. | 212d ago |
| CVE-2025-9049 | 8.8 | — | — | — | — | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to | 34d ago |
| CVE-2026-86177 | 8.8 | — | — | — | — | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing | 34d ago |
| CVE-2026-86169 | 8.8 | — | — | — | — | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remo | 34d ago |
| CVE-2026-81543 | 8.8 | — | — | — | — | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions | 35d ago |
| CVE-2026-19887 | 8.8 | — | — | — | — | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu | 35d ago |
| CVE-2026-52775 | 8.8 | — | — | — | — | YesWiki is a wiki system written in PHP. | 35d ago |
| CVE-2026-77393 | 8.8 | — | — | — | — | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any au | 35d ago |
| CVE-2026-82712 | 8.8 | — | — | — | — | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerabi | 35d ago |
| CVE-2026-82538 | 8.8 | — | — | — | — | ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table w | 35d ago |
| CVE-2026-18486 | 8.8 | — | — | — | — | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sen | 35d ago |
| CVE-2026-19298 | 8.8 | — | — | — | — | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to | 35d ago |
| CVE-2026-85623 | 8.8 | — | — | — | — | goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection | 35d ago |
| CVE-2026-85607 | 8.8 | — | — | — | — | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, mess | 35d ago |
| CVE-2026-18198 | 8.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Informat | 35d ago |
| CVE-2026-85617 | 8.8 | — | — | — | — | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that | 35d ago |