| CVE-2026-83711 | 10 | critical | — | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized at | 2d ago |
| CVE-2026-70352 | 10 | critical | — | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privi | 2d ago |
| CVE-2026-85061 | 10 | critical | — | MapLibre GL JS is an interactive vector tile map library for web browsers. | 2d ago |
| CVE-2026-4357 | 10 | critical | — | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, a | 3d ago |
| CVE-2026-83548exploited | 10 | critical | sonicwall / sma8200v | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended | 4d ago |
| CVE-2026-76658 | 10 | critical | arubanetworks / fabric composer | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauth | 4d ago |
| CVE-2026-76657 | 10 | critical | arubanetworks / fabric composer | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an | 4d ago |
| CVE-2026-82971 | 10 | critical | — | A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. | 5d ago |
| CVE-2026-81780 | 10 | critical | — | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | 5d ago |
| CVE-2026-81779 | 10 | critical | — | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Soft | 5d ago |
| CVE-2026-82970 | 10 | critical | — | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & | 5d ago |
| CVE-2026-82695 | 10 | critical | — | A security flaw has been discovered in Tenda AC18 15.03.05.19. | 5d ago |
| CVE-2026-82694 | 10 | critical | — | A vulnerability was identified in Tenda AC1206 15.03.06.23. | 5d ago |
| CVE-2026-82693 | 10 | critical | — | A vulnerability was determined in Tenda AC1206 15.03.06.23. | 5d ago |
| CVE-2026-82542 | 10 | critical | — | A weakness has been identified in Tenda HG10 300001138. | 6d ago |
| CVE-2026-82456 | 10 | critical | — | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring ca | 7d ago |
| CVE-2026-54745 | 10 | critical | — | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. | 8d ago |
| CVE-2026-82222 | 10 | critical | — | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. | 8d ago |
| CVE-2026-81735 | 10 | critical | — | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host | 9d ago |
| CVE-2026-81096 | 10 | critical | — | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authe | 9d ago |
| CVE-2026-77554 | 10 | critical | — | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni | 10d ago |
| CVE-2026-77550 | 10 | critical | — | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerabil | 10d ago |
| CVE-2026-77537 | 10 | critical | — | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni | 10d ago |
| CVE-2026-79911 | 10 | critical | — | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. | 11d ago |
| CVE-2026-76197 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ( | 11d ago |
| CVE-2026-76195 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ( | 11d ago |
| CVE-2026-76193 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i | 11d ago |
| CVE-2026-78167 | 10 | critical | — | A weakness has been identified in EFM ipTIME T16000M 14.20.2. | 13d ago |
| CVE-2026-74705 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel se | 14d ago |
| CVE-2026-74612 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag | 14d ago |
| CVE-2026-77946 | 10 | critical | — | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. | 14d ago |
| CVE-2026-61539 | 10 | critical | — | Xinference is an inference API for running open-source, speech, and multimodal models. | 15d ago |
| CVE-2026-69502 | 10 | critical | microsoft / azure sql database | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges ove | 15d ago |
| CVE-2026-69836 | 10 | critical | microsoft / entra id | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a net | 16d ago |
| CVE-2026-69555 | 10 | critical | microsoft / azure arc | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 16d ago |
| CVE-2026-65816 | 10 | critical | microsoft / azure web apps | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges o | 16d ago |
| CVE-2026-65801 | 10 | critical | microsoft / exchange online | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privile | 16d ago |
| CVE-2026-65770 | 10 | critical | microsoft / azure managed instance for apache cassandra | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for A | 16d ago |
| CVE-2026-22306 | 10 | critical | — | Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext | 17d ago |
| CVE-2026-20358 | 10 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering t | 17d ago |
| CVE-2026-20357 | 10 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering t | 17d ago |
| CVE-2026-20317 | 10 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload enginee | 17d ago |
| CVE-2026-20315 | 10 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload enginee | 17d ago |
| CVE-2026-20030 | 10 | critical | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering t | 17d ago |
| CVE-2026-18051 | 10 | critical | — | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cac | 17d ago |
| CVE-2026-76008 | 10 | critical | — | A flaw has been found in Comfast CF-N1-S 2.6.0.1. | 18d ago |
| CVE-2026-70921 | 10 | critical | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-70880 | 10 | critical | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 18d ago |
| CVE-2026-61241 | 10 | critical | oracle / internet directory | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | 18d ago |
| CVE-2026-75784 | 10 | critical | — | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. | 18d ago |
| CVE-2026-73343 | 10 | critical | — | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | 18d ago |
| CVE-2026-75874 | 10 | critical | mozilla / firefox | Sandbox escape in the Remote Settings Client component. | 18d ago |
| CVE-2026-74843 | 10 | critical | — | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. | 19d ago |
| CVE-2026-19977 | 10 | critical | — | A vulnerability was detected in EFM ipTIME A3004T 14.19.0. | 20d ago |
| CVE-2026-74475 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortc | 21d ago |
| CVE-2026-74309 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in int | 21d ago |
| CVE-2026-74280 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup usi | 21d ago |
| CVE-2026-74279 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wro | 21d ago |
| CVE-2026-72421 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/m | 21d ago |
| CVE-2026-72408 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() | 21d ago |