| CVE-2026-9311 | 9 | critical | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of securi | 96d ago |
| CVE-2026-45630 | 9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 99d ago |
| CVE-2026-9891 | 9 | critical | google / chrome | Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised | 100d ago |
| CVE-2026-9881 | 9 | critical | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a use | 100d ago |
| CVE-2026-46833 | 9 | critical | oracle / database server | Vulnerability in the Net Service component of Oracle Database Server. | 100d ago |
| CVE-2026-4408 | 9 | critical | redhat / openshift container platform | A flaw was found in Samba. | 100d ago |
| CVE-2026-32999 | 9 | critical | — | Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant | 100d ago |
| CVE-2026-48150 | 9 | critical | — | Budibase is an open-source low-code platform. | 101d ago |
| CVE-2026-45721 | 9 | critical | — | Algernon is a small self-contained pure-Go web server. | 102d ago |
| CVE-2026-4480 | 9 | critical | redhat / openshift container platform | A flaw was found in the Samba printing subsystem. | 102d ago |
| CVE-2026-2651 | 9 | critical | lfprojects / mlflow | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints whe | 103d ago |
| CVE-2026-22314 | 9 | critical | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component | 108d ago |
| CVE-2026-45375 | 9 | critical | — | SiYuan is an open-source personal knowledge management system. | 114d ago |
| CVE-2026-42457 | 9 | critical | — | vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing | 114d ago |
| CVE-2026-41901 | 9 | critical | — | Thymeleaf is a server-side Java template engine for web and standalone environments. | 116d ago |
| CVE-2026-44221 | 9 | critical | — | ArcadeDB is a Multi-Model DBMS. | 116d ago |
| CVE-2026-33067 | 9 | critical | b3log / siyuan | SiYuan is a personal knowledge management system. | 169d ago |
| CVE-2026-33066 | 9 | critical | b3log / siyuan | SiYuan is a personal knowledge management system. | 169d ago |
| CVE-2026-32891 | 9 | critical | openvessl / anchorr | Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a | 170d ago |
| CVE-2026-32751 | 9 | critical | b3log / siyuan | SiYuan is a personal knowledge management system. | 170d ago |
| CVE-2026-27540 | 9 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. | 170d ago |
| CVE-2026-32703 | 9 | critical | openproject / openproject | OpenProject is an open-source, web-based project management software. | 171d ago |
| CVE-2026-3564 | 9 | critical | — | A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authent | 172d ago |
| CVE-2026-32635 | 9 | critical | angular / angular cli | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and | 173d ago |
| CVE-2025-67041 | 7.2 | critical | lantronix / eds3016ps1ns firmware | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. | 178d ago |
| CVE-2025-67035 | 7.2 | critical | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 178d ago |
| CVE-2025-70082 | 2.7 | critical | lantronix / eds3016ps1ns firmware | An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive info | 178d ago |