| CVE-2026-72876 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72872 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72869 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72868 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72867 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72865 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72864 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72863 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72862 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72740 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72738 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72736 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72735 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72733 | 9.9 | critical | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-64637 | 9.9 | critical | — | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obta | 29d ago |
| CVE-2026-62830 | 9.9 | critical | microsoft / azure sre agent | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-59115 | 9.9 | critical | microsoft / entra provisioning service | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileg | 30d ago |
| CVE-2026-50515 | 9.9 | critical | microsoft / azure service bus | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a networ | 30d ago |
| CVE-2026-50481 | 9.9 | critical | microsoft / azure active directory | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate p | 30d ago |
| CVE-2026-67622 | 9.9 | critical | — | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integrat | 30d ago |
| CVE-2026-48086 | 9.9 | critical | — | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. | 30d ago |
| CVE-2026-65548 | 9.9 | critical | — | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | 30d ago |
| CVE-2026-70615 | 9.9 | critical | — | boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged use | 31d ago |
| CVE-2026-20304 | 9.9 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN enginee | 31d ago |
| CVE-2026-20303 | 9.9 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN enginee | 31d ago |
| CVE-2026-9193 | 9.9 | critical | progress / marklogic server | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 | 31d ago |
| CVE-2026-8709 | 9.9 | critical | progress / marklogic server | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Serve | 31d ago |
| CVE-2026-7329 | 9.9 | critical | progress / marklogic server | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress Mark | 31d ago |
| CVE-2026-71268 | 9.9 | critical | — | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Te | 31d ago |
| CVE-2026-48326 | 9.9 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 33d ago |
| CVE-2026-67330 | 9.9 | critical | — | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through < | 35d ago |
| CVE-2026-52855 | 9.9 | critical | — | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. | 36d ago |
| CVE-2026-17566 | 9.9 | critical | pgadmin / pgadmin 4 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL qu | 36d ago |
| CVE-2026-12946 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to | 37d ago |
| CVE-2026-13435 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbo | 37d ago |
| CVE-2026-58046 | 9.9 | critical | — | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL | 38d ago |
| CVE-2026-54680 | 9.9 | critical | — | Logging operator automates the deployment and configuration of Kubernetes logging pipelines. | 38d ago |
| CVE-2026-63234 | 9.9 | critical | — | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to injec | 38d ago |
| CVE-2026-63233 | 9.9 | critical | — | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to injec | 38d ago |
| CVE-2026-63232 | 9.9 | critical | — | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to injec | 38d ago |
| CVE-2026-63227 | 9.9 | critical | — | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload | 38d ago |
| CVE-2026-48030 | 9.9 | critical | — | Pheditor is a single-file editor and file manager written in PHP. | 40d ago |
| CVE-2026-54120 | 9.9 | critical | microsoft / surface management services | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | 44d ago |
| CVE-2026-50517 | 9.9 | critical | microsoft / 365 copilot | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | 44d ago |
| CVE-2026-63732 | 9.9 | critical | — | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that a | 44d ago |
| CVE-2024-58354 | 9.9 | critical | — | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHu | 44d ago |
| CVE-2026-47724 | 9.9 | critical | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. | 44d ago |
| CVE-2026-15630 | 9.9 | critical | — | A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources | 44d ago |
| CVE-2026-47752 | 9.9 | critical | — | Tugtainer is a self-hosted app for automating updates of Docker containers. | 44d ago |
| CVE-2026-44210 | 9.9 | critical | katacontainers / kata containers | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (V | 44d ago |
| CVE-2026-59543 | 9.9 | critical | — | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | 44d ago |
| CVE-2026-60369 | 9.9 | critical | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-61242 | 9.9 | critical | oracle / peoplesoft enterprise fin common objects | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: S | 46d ago |
| CVE-2026-61239 | 9.9 | critical | oracle / peoplesoft enterprise fin common objects | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: e | 46d ago |
| CVE-2026-61237 | 9.9 | critical | oracle / peoplesoft enterprise fin common objects | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: I | 46d ago |
| CVE-2026-61211 | 9.9 | critical | oracle / database server | Vulnerability in the RDBMS component of Oracle Database Server. | 46d ago |
| CVE-2026-61209 | 9.9 | critical | oracle / peoplesoft in-memory project discovery | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Disco | 46d ago |
| CVE-2026-61146 | 9.9 | critical | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 46d ago |
| CVE-2026-61076 | 9.9 | critical | oracle / peoplesoft enterprise hcm talent acquisition manager | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: | 46d ago |
| CVE-2026-61072 | 9.9 | critical | oracle / peoplesoft enterprise fin staffing front office brazil | Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (componen | 46d ago |