| CVE-2026-48019 | 8.9 | high | — | Laravel is a web application framework. | 1d ago |
| CVE-2026-82654 | 8.9 | high | — | SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb | 6d ago |
| CVE-2026-82653 | 8.9 | high | — | SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped packa | 6d ago |
| CVE-2025-30156 | 8.9 | high | — | Ceph is an open-source distributed storage platform providing object, block, and file storage. | 9d ago |
| CVE-2026-30864 | 8.9 | high | — | Combodo iTop is a web-based IT service management tool. | 12d ago |
| CVE-2026-19200 | 8.9 | high | — | The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. | 12d ago |
| CVE-2026-77638 | 8.9 | high | — | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could ma | 16d ago |
| CVE-2026-18193 | 8.9 | high | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validat | 23d ago |
| CVE-2026-73570exploited | 8.9 | high | synacor / zimbra collaboration suite | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra | 23d ago |
| CVE-2026-18099 | 8.9 | high | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to i | 24d ago |
| CVE-2026-57858 | 8.9 | high | — | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPag | 24d ago |
| CVE-2026-58154 | 8.9 | high | apache / traffic server | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. | 38d ago |
| CVE-2026-16496 | 8.9 | high | — | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stat | 39d ago |
| CVE-2024-58355 | 8.9 | high | — | Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. | 44d ago |
| CVE-2024-58353 | 8.9 | high | — | Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publi | 44d ago |
| CVE-2026-15416 | 8.9 | high | — | A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthen | 53d ago |
| CVE-2026-58424 | 8.9 | high | — | Permanent Fork PR Workflow Approval Gate Bypass | 64d ago |
| CVE-2026-52798 | 8.9 | high | — | Gogs is an open source self-hosted Git service. | 73d ago |
| CVE-2026-43984 | 8.9 | high | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. | 93d ago |
| CVE-2026-42611 | 8.9 | high | getgrav / grav | Grav is a file-based Web platform. | 117d ago |
| CVE-2026-31889 | 8.9 | high | shopware / shopware | Shopware is an open commerce platform. | 178d ago |
| CVE-2025-9049 | 8.8 | high | — | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to | 15h ago |
| CVE-2026-86177 | 8.8 | high | — | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing | 16h ago |
| CVE-2026-86169 | 8.8 | high | — | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remo | 16h ago |
| CVE-2026-81543 | 8.8 | high | — | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions | 19h ago |
| CVE-2026-19887 | 8.8 | high | — | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu | 20h ago |
| CVE-2026-52775 | 8.8 | high | — | YesWiki is a wiki system written in PHP. | 1d ago |
| CVE-2026-77393 | 8.8 | high | — | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any au | 1d ago |
| CVE-2026-82712 | 8.8 | high | — | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerabi | 1d ago |
| CVE-2026-82538 | 8.8 | high | — | ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table w | 1d ago |
| CVE-2026-18486 | 8.8 | high | — | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sen | 1d ago |
| CVE-2026-19298 | 8.8 | high | — | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to | 1d ago |
| CVE-2026-85623 | 8.8 | high | — | goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection | 1d ago |
| CVE-2026-85607 | 8.8 | high | — | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, mess | 1d ago |
| CVE-2026-18198 | 8.8 | high | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Informat | 1d ago |
| CVE-2026-85617 | 8.8 | high | — | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that | 1d ago |
| CVE-2026-85610 | 8.8 | high | — | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project member | 1d ago |
| CVE-2026-85604 | 8.8 | high | — | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort f | 1d ago |
| CVE-2026-85540 | 8.8 | high | — | DreamMaker developed by Interinfo has a SQL Injection vulnerability. | 1d ago |
| CVE-2026-85094 | 8.8 | high | — | The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a priv | 1d ago |
| CVE-2026-85452 | 8.8 | high | — | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where | 2d ago |
| CVE-2026-85053 | 8.8 | high | — | Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to ex | 2d ago |
| CVE-2026-85051 | 8.8 | high | — | Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitra | 2d ago |
| CVE-2026-85049 | 8.8 | high | — | Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code | 2d ago |
| CVE-2026-85046exploited | 8.8 | high | google / chrome | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code i | 2d ago |
| CVE-2026-84752 | 8.8 | high | — | Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. | 2d ago |
| CVE-2026-71963 | 8.8 | high | — | Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that a | 2d ago |
| CVE-2026-85176 | 8.8 | high | — | DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and writ | 2d ago |
| CVE-2026-85110 | 8.8 | high | — | A vulnerability was identified in Tenda HG10 300001138. | 2d ago |
| CVE-2026-85175 | 8.8 | high | — | SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (k | 2d ago |
| CVE-2026-85174 | 8.8 | high | — | SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text s | 2d ago |
| CVE-2026-80734 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping flags for cach | 2d ago |
| CVE-2026-20280 | 8.8 | high | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software en | 3d ago |
| CVE-2026-20278 | 8.8 | high | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software enginee | 3d ago |
| CVE-2026-20275 | 8.8 | high | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software enginee | 3d ago |
| CVE-2026-84673 | 8.8 | high | — | Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance con | 3d ago |
| CVE-2026-84672 | 8.8 | high | — | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissi | 3d ago |
| CVE-2026-84671 | 8.8 | high | — | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the J | 3d ago |
| CVE-2026-84670 | 8.8 | high | — | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated | 3d ago |
| CVE-2026-84669 | 8.8 | high | — | A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permiss | 3d ago |