| CVE-2026-61041 | 9.9 | critical | oracle / demantra demand management | Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security | 46d ago |
| CVE-2026-60719 | 9.9 | critical | oracle / bi publisher | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). | 46d ago |
| CVE-2026-60711 | 9.9 | critical | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 46d ago |
| CVE-2026-60663 | 9.9 | critical | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Manageme | 46d ago |
| CVE-2026-60627 | 9.9 | critical | oracle / jd edwards enterpriseone tools | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security | 46d ago |
| CVE-2026-60568 | 9.9 | critical | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 46d ago |
| CVE-2026-60565 | 9.9 | critical | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 46d ago |
| CVE-2026-60562 | 9.9 | critical | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 46d ago |
| CVE-2026-60561 | 9.9 | critical | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 46d ago |
| CVE-2026-60552 | 9.9 | critical | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 46d ago |
| CVE-2026-60547 | 9.9 | critical | oracle / managed file transfer | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Serv | 46d ago |
| CVE-2026-60542 | 9.9 | critical | oracle / business process management suite | Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Huma | 46d ago |
| CVE-2026-60537 | 9.9 | critical | oracle / managed file transfer | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Serv | 46d ago |
| CVE-2026-60531 | 9.9 | critical | oracle / identity manager connector | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-60524 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60461 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60459 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60458 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60457 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60456 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60447 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60445 | 9.9 | critical | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 46d ago |
| CVE-2026-60429 | 9.9 | critical | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 46d ago |
| CVE-2026-60422 | 9.9 | critical | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 46d ago |
| CVE-2026-60402 | 9.9 | critical | oracle / timesten in-memory database | Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kuberne | 46d ago |
| CVE-2026-60381 | 9.9 | critical | oracle / service delivery platform | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | 46d ago |
| CVE-2026-60377 | 9.9 | critical | oracle / service delivery platform | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | 46d ago |
| CVE-2026-60361 | 9.9 | critical | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 46d ago |
| CVE-2026-60333 | 9.9 | critical | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 46d ago |
| CVE-2026-60206 | 9.9 | critical | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-64879 | 9.9 | critical | tenable / security center | A filename supplied during file upload is not properly sanitized before being used in system command execution, al | 46d ago |
| CVE-2026-64878 | 9.9 | critical | tenable / security center | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resu | 46d ago |
| CVE-2026-47392 | 9.9 | critical | — | PraisonAI is a multi-agent teams system. | 46d ago |
| CVE-2026-54051 | 9.9 | critical | — | Network-AI is a TypeScript/Node.js multi-agent orchestrator. | 47d ago |
| CVE-2026-51027 | 9.9 | critical | — | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component | 47d ago |
| CVE-2026-8859 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locat | 50d ago |
| CVE-2026-8635 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly ma | 50d ago |
| CVE-2026-8481 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation | 50d ago |
| CVE-2026-8476 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based cach | 50d ago |
| CVE-2026-9135 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32 | 50d ago |
| CVE-2026-54526 | 9.9 | critical | argoproj / argo workflows | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. | 51d ago |
| CVE-2026-46512 | 9.9 | critical | — | Frogman provides headless PBX control through MCP and HTTP API. | 51d ago |
| CVE-2026-52891 | 9.9 | critical | — | Wekan is open source kanban built with Meteor. | 52d ago |
| CVE-2026-54052 | 9.9 | critical | n8n-mcp / n8n-mcp | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. | 52d ago |
| CVE-2026-44986 | 9.9 | critical | — | Penpot is an open-source design tool for design and code collaboration. | 52d ago |
| CVE-2026-48322 | 9.9 | critical | adobe / coldfusion | ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could re | 53d ago |
| CVE-2026-48318 | 9.9 | critical | adobe / coldfusion | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner | 53d ago |
| CVE-2026-57092 | 9.9 | critical | microsoft / windows 10 1607 | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | 53d ago |
| CVE-2026-44747 | 9.9 | critical | — | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory manage | 54d ago |
| CVE-2026-57710 | 9.9 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allo | 54d ago |
| CVE-2026-57401 | 9.9 | critical | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force S | 54d ago |
| CVE-2026-61445 | 9.9 | critical | — | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder compone | 56d ago |
| CVE-2026-14480 | 9.9 | critical | — | OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑uploa | 57d ago |
| CVE-2026-55500 | 9.9 | critical | — | 9Router is an AI router & token saver. | 57d ago |
| CVE-2026-0284 | 9.9 | critical | paloaltonetworks / pan-os | An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software | 58d ago |
| CVE-2026-59827 | 9.9 | critical | metabase / metabase | Metabase is an open-source business intelligence and embedded analytics tool. | 58d ago |
| CVE-2026-56843 | 9.9 | critical | — | Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated | 60d ago |
| CVE-2026-34048 | 9.9 | critical | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34047 | 9.9 | critical | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34037 | 9.9 | critical | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |