VulnFeed
Showing 5839 of 5839 CVEs modified in the last 7 days
CVE-2026-71398
CRITICAL 10

Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

CVE-2026-61962
CRITICAL 10

WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability

CVE-2026-59500
CRITICAL 10

Priority - CWE-287: Improper Authentication

CVE-2026-48362
CRITICAL 10

ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

CVE-2026-45618
CRITICAL 10

LiquidJS is Vulnerable to Remote Code Execution

CVE-2026-27544
CRITICAL 10

WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability

CVE-2026-27302
CRITICAL 10

Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

CVE-2026-15413
CRITICAL 10

Link Factory - Backdoor

CVE-2026-8985
CRITICAL 10

Unauthenticated Command Injection

CVE-2026-8984
CRITICAL 10

Unauthenticated RCE

CVE-2026-72911
CRITICAL 9.9

ERPNext: Possibility of server-side template injection due to missing validation

CVE-2026-72901
CRITICAL 9.9

Dokploy: Remote Code Execution via volume-backup

CVE-2026-72882
CRITICAL 9.9

Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers

CVE-2026-72872
CRITICAL 9.9

Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`

CVE-2026-72867
CRITICAL 9.9

Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)

CVE-2026-72862
CRITICAL 9.9

Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE

CVE-2026-72508
CRITICAL 9.9

Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)

CVE-2026-66898
CRITICAL 9.9

Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE

CVE-2026-63300
CRITICAL 9.9

Cross-project instance move bypasses all project restrictions allowing host command execution

CVE-2026-63298
CRITICAL 9.9

LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration

CVE-2026-63297
CRITICAL 9.9

Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge

CVE-2026-63296
CRITICAL 9.9

Project restriction bypass via instance migration config override

CVE-2026-63294
CRITICAL 9.9

Root RCE via image backup.yaml symlink

CVE-2026-63293
CRITICAL 9.9

Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root

CVE-2026-16860
CRITICAL 9.9

IBM i is Affected By Remote Code Execution Vulnerability []

CVE-2026-7374
CRITICAL 9.9

Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability

CVE-2026-73649
CRITICAL 9.8

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix)

CVE-2026-73240
CRITICAL 9.8

Apache Allura: Git command injection

CVE-2026-66691
CRITICAL 9.8

WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability

CVE-2026-66465
CRITICAL 9.8

WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability

CVE-2026-66453
CRITICAL 9.8

WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability

CVE-2026-66424
CRITICAL 9.8

WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability

CVE-2026-64162
CRITICAL 9.8

idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()

CVE-2026-64136
CRITICAL 9.8

smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()

CVE-2026-64132
CRITICAL 9.8

ipv6: ioam: refresh hdr pointer before ioam6_event()

CVE-2026-64125
CRITICAL 9.8

net: bcmgenet: keep RBUF EEE/PM disabled

CVE-2026-64122
CRITICAL 9.8

net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover

CVE-2026-61967
CRITICAL 9.8

WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability

CVE-2026-59310
CRITICAL 9.8

vCenter directory-traversal vulnerability

CVE-2026-49827
CRITICAL 9.8

WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)

CVE-2026-49819
CRITICAL 9.8

UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd

CVE-2026-46670
CRITICAL 9.8

YesWiki: Unauthenticated SQL Injection

CVE-2026-28185
CRITICAL 9.8

WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability

CVE-2026-28149
CRITICAL 9.8

WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability

CVE-2026-28148
CRITICAL 9.8

WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability

CVE-2026-28008
CRITICAL 9.8

WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability

CVE-2026-26035
CRITICAL 9.8

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

CVE-2026-18749
CRITICAL 9.8

CVE-2026-18749

CVE-2026-17218
CRITICAL 9.8

IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon []

CVE-2026-17083
CRITICAL 9.8

IBM i is Affected By Multiple Vulnerabilities in the Debug Server

CVE-2026-16956
CRITICAL 9.8

IBM Db2 Mirror for i is vulnerable to OS command injection []

CVE-2026-16770
CRITICAL 9.8

PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document

CVE-2026-16766
CRITICAL 9.8

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options

CVE-2026-14182
CRITICAL 9.8

Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass

CVE-2025-59326
CRITICAL 9.8

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.

CVE-2025-59321
CRITICAL 9.8

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.

CVE-2018-20753
CRITICAL 9.8

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

CVE-2018-19949
CRITICAL 9.8

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE-2018-19323
CRITICAL 9.8

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVE-2018-11138
CRITICAL 9.8

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

CVE-2018-7602
CRITICAL 9.8

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

CVE-2017-18362
CRITICAL 9.8

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

CVE-2017-12149
CRITICAL 9.8

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

CVE-2026-73644
CRITICAL 9.6

OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant

CVE-2026-72877
CRITICAL 9.6

Dokploy: Command Injection via dockerImage in buildRemoteDocker

CVE-2026-72737
CRITICAL 9.6

Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups

CVE-2026-71193
CRITICAL 9.6

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.

CVE-2026-49481
CRITICAL 9.6

UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd

CVE-2026-47705
CRITICAL 9.6

TypeBot vulnerable to CSV injection in result export

CVE-2026-39821
CRITICAL 9.6

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVE-2026-17276
CRITICAL 9.6

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2026-19001
CRITICAL 9.5

MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names

CVE-2026-8986
CRITICAL 9.5

Command Injection via Malicious OCPP Server

CVE-2026-73653
CRITICAL 9.4

Vitest: Browser Mode provider commands bypass the file-access permission gate

CVE-2026-73483
CRITICAL 9.4

Flowise before 3.1.3 Sandbox Escape via Puppeteer

CVE-2026-73296
CRITICAL 9.4

Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure

CVE-2026-50561
CRITICAL 9.4

Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse

CVE-2026-8987
CRITICAL 9.4

Authenticated Heap Overflow

CVE-2025-71392
CRITICAL 9.4

SurrealDB before 2.2.2 SurrealQL Injection via export

CVE-2026-73533
CRITICAL 9.3

Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build

CVE-2026-73532
CRITICAL 9.3

Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build

CVE-2026-73519
CRITICAL 9.3

WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret

CVE-2026-73090
CRITICAL 9.3

PeerTube: Cross-origin remote video takeover via Update activity

CVE-2026-73080
CRITICAL 9.3

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

CVE-2026-73034
CRITICAL 9.3

DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header

CVE-2026-70306
CRITICAL 9.3

Microsoft Office SharePoint Spoofing Vulnerability

CVE-2026-67614
CRITICAL 9.3

CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal

CVE-2026-66478
CRITICAL 9.3

WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability

CVE-2026-66472
CRITICAL 9.3

WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability

CVE-2026-66458
CRITICAL 9.3

WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability

CVE-2026-66446
CRITICAL 9.3

WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability

CVE-2026-66436
CRITICAL 9.3

WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability

CVE-2026-61969
CRITICAL 9.3

WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability

CVE-2026-61966
CRITICAL 9.3

WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability

CVE-2026-59507
CRITICAL 9.3

Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

CVE-2026-59506
CRITICAL 9.3

Priority – CWE-306: Missing Authentication for Critical Function

CVE-2026-57858
CRITICAL 9.3

Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID

CVE-2026-48046
CRITICAL 9.3

Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler

CVE-2026-44990
CRITICAL 9.3

Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

CVE-2026-28142
CRITICAL 9.3

WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability

CVE-2026-28001
CRITICAL 9.3

WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability

CVE-2026-14973
CRITICAL 9.3

Path Traversal in IBM Desktop App

CVE-2025-41769
CRITICAL 9.3

Unauthenticated Buffer Overflow in PROFINET Service

CVE-2025-31114
CRITICAL 9.3

Fooocus webui vulnerable to Remote Code Execution

CVE-2026-73608
CRITICAL 9.2

SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget

CVE-2026-70460
CRITICAL 9.2

rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink

CVE-2026-67285
CRITICAL 9.2

Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0

CVE-2026-53790
CRITICAL 9.2

rsync < 3.5.0 Command Injection via Multiple Code Paths

CVE-2026-73567
CRITICAL 9.1

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

CVE-2026-73501
CRITICAL 9.1

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

CVE-2026-71290
CRITICAL 9.1

Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)

CVE-2026-70452
CRITICAL 9.1

rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure

CVE-2026-64269
CRITICAL 9.1

RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg

CVE-2026-59504
CRITICAL 9.1

Priority – CWE-602: Client-Side Enforcement of Server-Side Security

CVE-2026-59503
CRITICAL 9.1

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor

CVE-2026-55040
CRITICAL 9.1

Microsoft SharePoint Server Security Feature Bypass Vulnerability

CVE-2026-53793
CRITICAL 9.1

rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode

CVE-2026-53791
CRITICAL 9.1

rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header

CVE-2026-42508
CRITICAL 9.1

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

CVE-2026-39830
CRITICAL 9.1

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

CVE-2026-33186
CRITICAL 9.1

gRPC-Go has an authorization bypass via missing leading slash in :path

CVE-2026-6100
CRITICAL 9.1

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

CVE-2025-59324
CRITICAL 9.1

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

CVE-2026-73602
CRITICAL 9

Flowise before 3.1.3 Sandbox Escape to RCE

CVE-2026-73601
CRITICAL 9

Flowise before 3.1.3 Remote Code Execution via Custom MCP

CVE-2026-73487
CRITICAL 9

Flowise before 3.1.3 Prompt Injection RCE via CSV Agent

CVE-2026-73486
CRITICAL 9

Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV

CVE-2026-73485
CRITICAL 9

Flowise before 3.1.3 Remote Code Execution via Airtable Agent

CVE-2026-71471
CRITICAL 9

Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image

CVE-2024-58366
CRITICAL 9

SurrealDB before 1.1.1 Format String via Scripting Functions

CVE-2026-73570
HIGH 8.9

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

CVE-2026-73224
HIGH 8.8

Electerm check folder size function may get attacked by unsafe folder name

CVE-2026-73222
HIGH 8.8

Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)

CVE-2026-70461
HIGH 8.8

rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry

CVE-2026-70458
HIGH 8.8

rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling

CVE-2026-70456
HIGH 8.8

rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()

CVE-2026-70326
HIGH 8.8

Microsoft SharePoint Server Elevation of Privilege Vulnerability

CVE-2026-70324
HIGH 8.8

Microsoft SharePoint Elevation of Privilege Vulnerability

CVE-2026-70321
HIGH 8.8

Microsoft SharePoint Remote Code Execution Vulnerability

CVE-2026-69106
HIGH 8.8

Potential cache poisoning in JFrog Artifactory

CVE-2026-67587
HIGH 8.8

Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget

CVE-2026-66808
HIGH 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2026-66805
HIGH 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2026-65807
HIGH 8.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-65665
HIGH 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2026-65663
HIGH 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2026-65658
HIGH 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2026-64921
HIGH 8.8

Microsoft SharePoint Server Elevation of Privilege Vulnerability

CVE-2026-64280
HIGH 8.8

fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()

CVE-2026-64124
HIGH 8.8

net: devmem: reject dma-buf bind with non-page-aligned size or SG length

CVE-2026-62869
HIGH 8.8

Azure Entra ID Spoofing Vulnerability

CVE-2026-62824
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-62822
HIGH 8.8

Windows GDI+ Remote Code Execution Vulnerability

CVE-2026-62800
HIGH 8.8

Windows SMBv3 Server Remote Code Execution Vulnerability

CVE-2026-62795
HIGH 8.8

Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability

CVE-2026-62790
HIGH 8.8

Windows SMBv3 Server Remote Code Execution Vulnerability

CVE-2026-62785
HIGH 8.8

Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability

CVE-2026-62784
HIGH 8.8

Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability

CVE-2026-60924
HIGH 8.8

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-59133
HIGH 8.8

Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability

CVE-2026-49473
HIGH 8.8

@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation

CVE-2026-49179
HIGH 8.8

Windows Active Directory Domain Services Remote Code Execution Vulnerability

CVE-2026-39852
HIGH 8.8

Quarkus authorization bypass via semicolon path normalization inconsistency

CVE-2026-34184
HIGH 8.8

Missing Authorization inAlanWeb SCADA

CVE-2026-28176
HIGH 8.8

WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability

CVE-2026-28161
HIGH 8.8

WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability

CVE-2026-19560
HIGH 8.8

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-19559
HIGH 8.8

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-19556
HIGH 8.8

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-19385
HIGH 8.8

PostgreSQL pg_dump heap buffer overflow executes arbitrary code

CVE-2026-19293
HIGH 8.8

SMP security request

CVE-2026-19292
HIGH 8.8

Bluetooth re-pairing with legitimate device can use lower security level

CVE-2026-19291
HIGH 8.8

Bluetooth re-pairing can use a lower security level than previous

CVE-2026-19004
HIGH 8.8

MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters

CVE-2026-19002
HIGH 8.8

Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver

CVE-2026-18713
HIGH 8.8

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2026-18669
HIGH 8.8

IBM i is Affected By A Privilege Escalation Vulnerability []

CVE-2026-18408
HIGH 8.8

PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client

CVE-2026-17642
HIGH 8.8

IBM i is Affected By Remote Code Execution Vulnerabilities [, ]

CVE-2026-17417
HIGH 8.8

IBM i is Affected By Remote Code Execution Vulnerabilities [, ]

CVE-2026-17110
HIGH 8.8

IBM i is Affected By Multiple Vulnerabilities in SQL

CVE-2026-17082
HIGH 8.8

IBM i is Affected By Multiple Vulnerabilities in the Debug Server

CVE-2026-16906
HIGH 8.8

IBM i is Affected By Multiple Vulnerabilities in Domain Name System

CVE-2026-16856
HIGH 8.8

IBM i is Affected By Multiple Vulnerabilities in Domain Name System

CVE-2026-16239
HIGH 8.8

PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code

CVE-2026-16238
HIGH 8.8

PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code

CVE-2026-16101
HIGH 8.8

forced re-pairing with already bonded device

CVE-2026-15742
HIGH 8.8

PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound

CVE-2026-15741
HIGH 8.8

PostgreSQL expression deparse allows SQL injection via EXTRACT argument

CVE-2026-14680
HIGH 8.8

PostgreSQL type confusion via "internal" arguments

CVE-2026-14677
HIGH 8.8

PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound

CVE-2026-14676
HIGH 8.8

PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code

CVE-2026-14671
HIGH 8.8

PostgreSQL refint plan cache type confusion executes arbitrary code

CVE-2026-14670
HIGH 8.8

PostgreSQL plperl tied object heap buffer overflow executes arbitrary code

CVE-2026-14669
HIGH 8.8

PostgreSQL to_char heap buffer overflow executes arbitrary code

CVE-2026-14664
HIGH 8.8

PostgreSQL regexp heap buffer overflow executes arbitrary code

CVE-2026-14662
HIGH 8.8

PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound

CVE-2026-13361
HIGH 8.8

IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution

CVE-2026-13105
HIGH 8.8

IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities

CVE-2026-12263
HIGH 8.8

Authentication Bypass

CVE-2026-11840
HIGH 8.8

SQL Injection

CVE-2026-3298
HIGH 8.8

Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes

CVE-2022-49159
HIGH 8.8

scsi: qla2xxx: Implement ref count for SRB

CVE-2026-73625
HIGH 8.7

GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling

CVE-2026-73622
HIGH 8.7

GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()

CVE-2026-73618
HIGH 8.7

Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter

CVE-2026-73615
HIGH 8.7

Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch

CVE-2026-73614
HIGH 8.7

Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation

CVE-2026-73569
HIGH 8.7

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

CVE-2026-73564
HIGH 8.7

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

CVE-2026-73514
HIGH 8.7

PostGIS address_standardizer Out-of-Bounds Write via standardize_address()

CVE-2026-73500
HIGH 8.7

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

CVE-2026-73413
HIGH 8.7

Shescape: Quadratic-time denial of service in flag-protection

CVE-2026-70464
HIGH 8.7

rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall

CVE-2026-70455
HIGH 8.7

rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion

CVE-2026-70453
HIGH 8.7

rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()

CVE-2026-60941
HIGH 8.7

Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. While the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).

CVE-2026-59109
HIGH 8.7

Zalktis: SQL injection via partner-controlled fields in imported e-invoices

CVE-2026-55402
HIGH 8.7

CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.

CVE-2026-49478
HIGH 8.7

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

CVE-2026-48059
HIGH 8.7

Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

CVE-2026-47691
HIGH 8.7

Netty has Insufficient Bailiwick Validation for NS Records

CVE-2026-47662
HIGH 8.7

Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLs

CVE-2026-46385
HIGH 8.7

iskorotkov/avro: CPU Exhaustion in Avro Decoder

CVE-2026-46384
HIGH 8.7

iskorotkov/avro: Integer Overflow in Avro Decoder

CVE-2026-46382
HIGH 8.7

Meeting Room Booking System has server-side request forgery in import functionality

CVE-2026-45674
HIGH 8.7

Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

CVE-2026-44494
HIGH 8.7

Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

CVE-2026-35469
HIGH 8.7

SpdyStream: DOS on CRI

CVE-2026-34185
HIGH 8.7

SQL Injection in AlanWeb SCADA

CVE-2026-29063
HIGH 8.7

Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable

CVE-2026-29036
HIGH 8.7

cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding

CVE-2026-21273
HIGH 8.7

ColdFusion | Improper Input Validation (CWE-20)

CVE-2026-18428
HIGH 8.7

SQL Query Validation Bypass in OpenSearch Direct Query

CVE-2026-15308
HIGH 8.7

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

CVE-2026-15217
HIGH 8.7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

CVE-2026-15216
HIGH 8.7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

CVE-2026-14863
HIGH 8.7

FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection

CVE-2026-12004
HIGH 8.7

Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

CVE-2024-58374
HIGH 8.7

Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree

CVE-2024-58368
HIGH 8.7

SurrealDB before 1.1.0 Denial of Service via HTTP Headers

CVE-2019-25765
HIGH 8.7

ASP-CMS SQL Injection via commentList.asp id Parameter

CVE-2026-73670
HIGH 8.6

CMS Admin SQL Injection via db_data.php table_name Parameter

CVE-2026-73612
HIGH 8.6

File Browser before v2.63.22 Authorization Bypass via Recursive Operations

CVE-2026-73484
HIGH 8.6

Flowise before 3.1.3 Sandbox Escape via Pandas Methods

CVE-2026-73247
HIGH 8.6

Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

CVE-2026-72741
HIGH 8.6

Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access

CVE-2026-70463
HIGH 8.6

rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing

CVE-2026-59505
HIGH 8.6

Priority - CWE-284: Improper Access Control

CVE-2026-59499
HIGH 8.6

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2026-53783
HIGH 8.6

rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync

CVE-2026-48441
HIGH 8.6

Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

CVE-2026-48397
HIGH 8.6

Lightroom Classic | Deserialization of Untrusted Data (CWE-502)

CVE-2026-44578
HIGH 8.6

Next.js: Server-side request forgery in applications using WebSocket upgrades

CVE-2026-44492
HIGH 8.6

Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

CVE-2026-19734
HIGH 8.6

IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking

CVE-2026-19311
HIGH 8.6

Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin

CVE-2026-18952
HIGH 8.6

Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin

CVE-2026-8989
HIGH 8.6

Open Recovery Mode

CVE-2026-8988
HIGH 8.6

Access to Bootloader

CVE-2025-61732
HIGH 8.6

Potential code smuggling via doc comments in cmd/cgo

CVE-2026-73072
HIGH 8.5

Vim: Heap Buffer Overflow when Loading a Spell File

CVE-2026-71473
HIGH 8.5

Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spoke

CVE-2026-66658
HIGH 8.5

WordPress Reviewer plugin <= 3.14.2 - SQL Injection vulnerability

CVE-2026-66430
HIGH 8.5

WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Injection vulnerability

CVE-2026-63425
HIGH 8.5

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.

CVE-2026-63423
HIGH 8.5

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

CVE-2026-53803
HIGH 8.5

rsync < 3.5.0 Symlink Following Arbitrary File Overwrite

CVE-2026-28184
HIGH 8.5

WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability

CVE-2026-28168
HIGH 8.5

WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability

CVE-2026-28156
HIGH 8.5

WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability

CVE-2026-28002
HIGH 8.5

WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability

CVE-2026-19228
HIGH 8.5

Authorization Bypass Through User-Controlled Key in GitLab

CVE-2026-17418
HIGH 8.5

IBM i is Affected By Multiple Vulnerabilities in SQL

CVE-2026-17107
HIGH 8.5

Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster

CVE-2026-16033
HIGH 8.5

Arbitrary file read+write on host via templates/ symlink in malicious image

CVE-2026-15423
HIGH 8.5

Incorrect Authorization in GitLab

CVE-2026-73629
HIGH 8.4

Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses

CVE-2026-67986
HIGH 8.4

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.

CVE-2026-64247
HIGH 8.4

KVM: x86: hyper-v: Bound the bank index when querying sparse banks

CVE-2026-64118
HIGH 8.4

qed: fix double free in qed_cxt_tables_alloc()

CVE-2026-53802
HIGH 8.4

rsync < 3.5.0 Arbitrary File Read via Symlink Following

CVE-2026-53784
HIGH 8.4

rsync < 3.5.0 Path Traversal via Symlink Module Root

CVE-2026-34635
HIGH 8.4

ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)

CVE-2026-19003
HIGH 8.4

MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings

CVE-2026-10534
HIGH 8.4

IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser

CVE-2025-59323
HIGH 8.4

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.

CVE-2026-73241
HIGH 8.3

FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)

CVE-2026-70457
HIGH 8.3

rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()

CVE-2026-56179
HIGH 8.3

Windows Network Address Translation (NAT) Spoofing Vulnerability

CVE-2026-53415
HIGH 8.3

Zoom Clients - Use After Free

CVE-2026-19557
HIGH 8.3

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-18235
HIGH 8.3

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2026-17095
HIGH 8.3

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2026-13433
HIGH 8.3

IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities

CVE-2026-73650
HIGH 8.2

SVGO: removeScripts plugin leaves some executable scripts intact

CVE-2026-72922
HIGH 8.2

AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification

CVE-2026-64954
HIGH 8.2

Velociraptor collect_client() Permissions Bypass

CVE-2026-64287
HIGH 8.2

KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU

CVE-2026-64286
HIGH 8.2

KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU

CVE-2026-59501
HIGH 8.2

Priority – CWE-284: Improper Access Control

CVE-2026-53801
HIGH 8.2

rsync < 3.5.0 Symlink Race Condition Directory Traversal

CVE-2026-48771
HIGH 8.2

ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database Configuration

CVE-2026-44487
HIGH 8.2

Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

CVE-2026-41604
HIGH 8.2

Apache Thrift: Swift Range crash in skip()

CVE-2026-33810
HIGH 8.2

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVE-2026-21279
HIGH 8.2

ColdFusion | Improper Input Validation (CWE-20)

CVE-2026-18945
HIGH 8.2

WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation

CVE-2026-17220
HIGH 8.2

IBM i is Affected By Multiple Vulnerabilities in Host Servers

CVE-2026-14679
HIGH 8.2

PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory

CVE-2026-11972
HIGH 8.2

tarfile opened in streaming mode mishandles EOF

CVE-2026-10543
HIGH 8.2

IBM® Db2® is vulnerable to privilege escalation with a specially crafted query

CVE-2026-9669
HIGH 8.2

bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

CVE-2026-4740
HIGH 8.2

Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation

CVE-2026-73227
HIGH 8.1

electerm's RDP clipboard file download may parse unsafe file name

CVE-2026-72921
HIGH 8.1

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

CVE-2026-70468
HIGH 8.1

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

CVE-2026-70465
HIGH 8.1

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.

CVE-2026-69105
HIGH 8.1

Potential package cache integrity issue in JFrog Artifactory

CVE-2026-66657
HIGH 8.1

WordPress Biagiotti Core plugin <= 2.1.1 - Local File Inclusion vulnerability

CVE-2026-66656
HIGH 8.1

WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability

CVE-2026-66653
HIGH 8.1

WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability

CVE-2026-66450
HIGH 8.1

WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability

CVE-2026-64176
HIGH 8.1

wifi: iwlwifi: mvm: fix driver-set TX rates on old devices

CVE-2026-63520
HIGH 8.1

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2026-62889
HIGH 8.1

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

CVE-2026-62792
HIGH 8.1

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2026-62781
HIGH 8.1

RPC Runtime Library Remote Code Execution Vulnerability

CVE-2026-61979
HIGH 8.1

WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability

CVE-2026-60904
HIGH 8.1

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVE-2026-54513
HIGH 8.1

jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

CVE-2026-48440
HIGH 8.1

ColdFusion | Heap-based Buffer Overflow (CWE-122)

CVE-2026-44574
HIGH 8.1

Next.js: Middleware / Proxy bypass through dynamic route parameter injection

CVE-2026-44249
HIGH 8.1

Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking

CVE-2026-28186
HIGH 8.1

WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability

CVE-2026-27543
HIGH 8.1

WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability

CVE-2026-24791
HIGH 8.1

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

CVE-2026-19091
HIGH 8.1

GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision

CVE-2026-18499
HIGH 8.1

IBM WebSphere Application Server Liberty is affected by a privilege escalation

CVE-2026-17197
HIGH 8.1

IBM i is Affected By Multiple Vulnerabilities in Host Servers

CVE-2026-16904
HIGH 8.1

IBM i is Affected By improper privilege management in Navigator for i

CVE-2026-15560
HIGH 8.1

Openjdk-orb: unauthed class loading via iiop in eap

CVE-2026-14668
HIGH 8.1

PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read

CVE-2026-13267
HIGH 8.1

Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

CVE-2026-12359
HIGH 8.1

Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

CVE-2026-6464
HIGH 8.1

PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands

CVE-2026-65937
HIGH 8

WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI

CVE-2026-62911
HIGH 8

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2026-22029
HIGH 8

React Router vulnerable to XSS via Open Redirects

CVE-2018-19943
HIGH 8

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

CVE-2026-73505
HIGH 7.8

Oh My Posh: Arbitrary command execution via template injection in the path segment

CVE-2026-73234
HIGH 7.8

FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore()

CVE-2026-73231
HIGH 7.8

Faker: helpers.fake exploitable into arbritary code execution

CVE-2026-68817
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68816
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68815
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68814
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68812
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68811
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68810
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68807
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68806
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68805
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68804
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68803
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68801
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68800
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68796
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68795
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68794
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-68793
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2026-65775
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-65773
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-64903
HIGH 7.8

Microsoft Office Remote Code Execution Vulnerability

CVE-2026-64898
HIGH 7.8

Microsoft Office Remote Code Execution Vulnerability

CVE-2026-64279
HIGH 7.8

i2c: core: fix adapter deregistration race

CVE-2026-64277
HIGH 7.8

Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count

CVE-2026-64276
HIGH 7.8

Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count

CVE-2026-64274
HIGH 7.8

Input: goodix - clamp the device-reported contact count

CVE-2026-64273
HIGH 7.8

Input: iforce - bound the device-reported force-feedback effect index

CVE-2026-64272
HIGH 7.8

Input: mms114 - fix touch indexing for MMS134S and MMS136

CVE-2026-64271
HIGH 7.8

Input: touchwin - reset the packet index on every complete packet

CVE-2026-64270
HIGH 7.8

Input: mms114 - reject an oversized device packet size

CVE-2026-64249
HIGH 7.8

fpga: region: fix use-after-free in child_regions_with_firmware()

CVE-2026-64246
HIGH 7.8

power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()

CVE-2026-64242
HIGH 7.8

usb: gadget: net2280: Fix double free in probe error path

CVE-2026-64239
HIGH 7.8

mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()

CVE-2026-64226
HIGH 7.8

sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path

CVE-2026-64137
HIGH 7.8

smb: client: require net admin for CIFS SWN netlink

CVE-2026-64134
HIGH 7.8

ALSA: pcm: Don't setup bogus iov_iter for silencing

CVE-2026-64133
HIGH 7.8

ALSA: asihpi: Fix potential OOB array access at reading cache

CVE-2026-64123
HIGH 7.8

net: hsr: defer node table free until after RCU readers

CVE-2026-63532
HIGH 7.8

Microsoft Office Remote Code Execution Vulnerability

CVE-2026-63527
HIGH 7.8

Microsoft Office Word Remote Code Execution Vulnerability

CVE-2026-63525
HIGH 7.8

Microsoft Office Word Remote Code Execution Vulnerability

CVE-2026-63519
HIGH 7.8

Microsoft Office Graphics Component Remote Code Execution Vulnerability

CVE-2026-62894
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-62888
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-62885
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-62880
HIGH 7.8

Windows NTFS Elevation of Privilege Vulnerability

CVE-2026-62877
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-62876
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-62871
HIGH 7.8

.NET Elevation of Privilege Vulnerability

CVE-2026-62832
HIGH 7.8

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2026-62811
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-62799
HIGH 7.8

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2026-62797
HIGH 7.8

Windows NTFS Elevation of Privilege Vulnerability

CVE-2026-62783
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2026-62779
HIGH 7.8

Windows Schannel Elevation of Privilege Vulnerability

CVE-2026-62777
HIGH 7.8

Windows License Manager Elevation of Privilege Vulnerability

CVE-2026-62772
HIGH 7.8

Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability

CVE-2026-62771
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-62770
HIGH 7.8

Windows Shell Elevation of Privilege Vulnerability

CVE-2026-62758
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2026-62755
HIGH 7.8

Windows DHCP Client Elevation of Privilege Vulnerability

CVE-2026-62754
HIGH 7.8

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2026-62752
HIGH 7.8

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2026-62751
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-62747
HIGH 7.8

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-62741
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-62739
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-62737
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-62736
HIGH 7.8

Windows DHCP Client Elevation of Privilege Vulnerability

CVE-2026-62735
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-62733
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-62722
HIGH 7.8

Windows Bind Filter Driver Elevation of Privilege Vulnerability

CVE-2026-62721
HIGH 7.8

Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability

CVE-2026-62719
HIGH 7.8

Windows Message Queuing Elevation of Privilege Vulnerability

CVE-2026-62717
HIGH 7.8

Windows Message Queuing Elevation of Privilege Vulnerability

CVE-2026-62713
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-62712
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-62711
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-62710
HIGH 7.8

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-62707
HIGH 7.8

Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability

CVE-2026-62701
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-62700
HIGH 7.8

Windows NTFS Elevation of Privilege Vulnerability

CVE-2026-62698
HIGH 7.8

Microsoft Digest Authentication Elevation of Privilege Vulnerability

CVE-2026-62696
HIGH 7.8

Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

CVE-2026-62695
HIGH 7.8

Windows Storage Elevation of Privilege Vulnerability

CVE-2026-62692
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-62688
HIGH 7.8

Windows MIDI Service Module Elevation of Privileges Vulnerability

CVE-2026-61937
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-61934
HIGH 7.8

Windows Bind Filter Driver Elevation of Privilege Vulnerability

CVE-2026-61932
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-61930
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-61926
HIGH 7.8

Windows USB Driver Elevation of Privilege Vulnerability

CVE-2026-61923
HIGH 7.8

Windows Display Enhancement Service Elevation of Privilege Vulnerability

CVE-2026-61367
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-61365
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-61364
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-61359
HIGH 7.8

Windows Storage Elevation of Privilege Vulnerability

CVE-2026-61358
HIGH 7.8

Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability

CVE-2026-61357
HIGH 7.8

Application Information Services Elevation of Privilege Vulnerability

CVE-2026-61356
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-61355
HIGH 7.8

Windows Sensor Data Service Elevation of Privilege Vulnerability

CVE-2026-61353
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-61349
HIGH 7.8

Windows Work Folder Service Elevation of Privilege Vulnerability

CVE-2026-59917
HIGH 7.8

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.

CVE-2026-59916
HIGH 7.8

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.

CVE-2026-59914
HIGH 7.8

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.

CVE-2026-54228
HIGH 7.8

Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directories

CVE-2026-53202
HIGH 7.8

accel/ivpu: Fix signed integer truncation in IPC receive

CVE-2026-48410
HIGH 7.8

Lightroom Classic | Out-of-bounds Write (CWE-787)

CVE-2026-48409
HIGH 7.8

Lightroom Classic | Out-of-bounds Write (CWE-787)

CVE-2026-48408
HIGH 7.8

Lightroom Classic | Out-of-bounds Write (CWE-787)

CVE-2026-48407
HIGH 7.8

Lightroom Classic | Out-of-bounds Write (CWE-787)

CVE-2026-48406
HIGH 7.8

Lightroom Classic | Out-of-bounds Write (CWE-787)

CVE-2026-48405
HIGH 7.8

Lightroom Classic | Out-of-bounds Write (CWE-787)

CVE-2026-48404
HIGH 7.8

Lightroom Classic | Out-of-bounds Write (CWE-787)

CVE-2026-47940
HIGH 7.8

Lightroom Classic | Integer Overflow or Wraparound (CWE-190)

CVE-2026-46731
HIGH 7.8

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.

CVE-2026-42976
HIGH 7.8

Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

CVE-2026-25652
HIGH 7.8

ColdFusion | Incorrect Authorization (CWE-863)

CVE-2026-18071
HIGH 7.8

IBM i is Affected By An Improper Management Vulnerability in HTTP Server []

CVE-2026-14478
HIGH 7.8

Incorrect Permission Assignment in Autodesk Installer Named Pipes

CVE-2026-11940
HIGH 7.8

tarfile extraction filter bypass allows escaping the destination directory

CVE-2025-6020
HIGH 7.8

Linux-pam: linux-pam directory traversal

CVE-2022-49179
HIGH 7.8

block, bfq: don't move oom_bfqq

CVE-2022-49176
HIGH 7.8

bfq: fix use-after-free in bfq_dispatch_request

CVE-2022-49170
HIGH 7.8

f2fs: fix to do sanity check on curseg->alloc_type

CVE-2022-49129
HIGH 7.8

mt76: mt7921: fix crash when startup fails.

CVE-2022-49044
HIGH 7.8

dm integrity: fix memory corruption when tag_size is less than digest size

CVE-2022-48979
HIGH 7.8

drm/amd/display: fix array index out of bound error in DCN32 DML

CVE-2022-48670
HIGH 7.8

peci: cpu: Fix use-after-free in adev_release()

CVE-2018-20250
HIGH 7.8

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

CVE-2018-19322
HIGH 7.8

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

CVE-2018-19321
HIGH 7.8

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

CVE-2018-19320
HIGH 7.8

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

CVE-2018-15982
HIGH 7.8

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2018-8453
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2026-73623
HIGH 7.7

GitPython before 3.1.54 Remote Code Execution via --template

CVE-2026-73498
HIGH 7.7

MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment

CVE-2026-73218
HIGH 7.7

Cursor: Sandbox escape via launching privileged containers

CVE-2026-72777
HIGH 7.7

Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url

CVE-2026-66878
HIGH 7.7

Multicloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltration

CVE-2026-66661
HIGH 7.7

WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability

CVE-2026-65582
HIGH 7.7

WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability

CVE-2026-48447
HIGH 7.7

Lightroom Classic | Incorrect Authorization (CWE-863)

CVE-2026-48385
HIGH 7.7

ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

CVE-2026-16863
HIGH 7.7

IBM i is Affected By Out-of-Bounds Read Vulnerability []

CVE-2026-16627
HIGH 7.7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

CVE-2026-14866
HIGH 7.7

IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities

CVE-2026-9804
HIGH 7.7

Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read

CVE-2026-8247
HIGH 7.7

WatchGuard Firebox admd Out of Bounds Write Vulnerability

CVE-2026-73611
HIGH 7.6

File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass

CVE-2026-73509
HIGH 7.6

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

CVE-2026-73346
HIGH 7.6

WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability

CVE-2026-73083
HIGH 7.6

Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading

CVE-2026-70454
HIGH 7.6

rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode

CVE-2026-65935
HIGH 7.6

Bypassing passkey entry in legacy pairing

CVE-2026-56208
HIGH 7.6

Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode

CVE-2026-48415
HIGH 7.6

Adobe Commerce | Incorrect Authorization (CWE-863)

CVE-2026-46701
HIGH 7.6

Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

CVE-2026-16907
HIGH 7.6

IBM i is Affected By Multiple Vulnerabilities in the Debug Server

CVE-2026-73643
HIGH 7.5

js-yaml: Exponential parsing time in the flow collections leads to denial of service

CVE-2026-73568
HIGH 7.5

py-libp2p: yamux connection DoS via oversized data frame

CVE-2026-73566
HIGH 7.5

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

CVE-2026-73561
HIGH 7.5

Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

CVE-2026-73507
HIGH 7.5

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

CVE-2026-73493
HIGH 7.5

http4s-blaze-server: Unbounded WebSocket message aggregation

CVE-2026-73418
HIGH 7.5

NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

CVE-2026-73406
HIGH 7.5

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

CVE-2026-73246
HIGH 7.5

Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials

CVE-2026-73188
HIGH 7.5

WordPress KiviCare plugin <= 4.5.1 - Sensitive Data Exposure vulnerability

CVE-2026-73089
HIGH 7.5

Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM

CVE-2026-73088
HIGH 7.5

Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)

CVE-2026-68968
HIGH 7.5

Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id

CVE-2026-67991
HIGH 7.5

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.

CVE-2026-67579
HIGH 7.5

Filter expression injection via forged keyset pagination cursor in Ash

CVE-2026-66469
HIGH 7.5

WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnerability

CVE-2026-66466
HIGH 7.5

WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability

CVE-2026-66463
HIGH 7.5

WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability

CVE-2026-66462
HIGH 7.5

WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure vulnerability

CVE-2026-66461
HIGH 7.5

WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypass vulnerability

CVE-2026-66443
HIGH 7.5

WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability

CVE-2026-66441
HIGH 7.5

WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability

CVE-2026-66432
HIGH 7.5

WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability

CVE-2026-66431
HIGH 7.5

WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability

CVE-2026-65370
HIGH 7.5

ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.

CVE-2026-64281
HIGH 7.5

svcrdma: wake sq waiters when the transport closes

CVE-2026-64175
HIGH 7.5

wifi: iwlwifi: mld: stop TX during firmware restart

CVE-2026-62295
HIGH 7.5

HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service

CVE-2026-61984
HIGH 7.5

WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability

CVE-2026-61980
HIGH 7.5

WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability

CVE-2026-61363
HIGH 7.5

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-61352
HIGH 7.5

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-59692
HIGH 7.5

Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback

CVE-2026-59134
HIGH 7.5

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-50559
HIGH 7.5

Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

CVE-2026-48804
HIGH 7.5

python-socketio: Binary attachment accumulation can cause denial of service

CVE-2026-48802
HIGH 7.5

python-engineio has unbound thread allocation that can cause denial of service

CVE-2026-48702
HIGH 7.5

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

CVE-2026-48416
HIGH 7.5

Adobe Commerce | Incorrect Authorization (CWE-863)

CVE-2026-48386
HIGH 7.5

ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)

CVE-2026-47717
HIGH 7.5

FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations

CVE-2026-45416
HIGH 7.5

Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes

CVE-2026-45109
HIGH 7.5

Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes

CVE-2026-44893
HIGH 7.5

Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length

CVE-2026-44579
HIGH 7.5

Next.js: Denial of Service via connection exhaustion in applications using Cache Components

CVE-2026-44575
HIGH 7.5

Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes

CVE-2026-44573
HIGH 7.5

Next.js: Middleware / Proxy bypass in Pages Router applications using i18n

CVE-2026-44496
HIGH 7.5

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

CVE-2026-44488
HIGH 7.5

Axios: Allocation of Resources Without Limits or Throttling in axios

CVE-2026-44486
HIGH 7.5

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

CVE-2026-42587
HIGH 7.5

Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS

CVE-2026-42579
HIGH 7.5

Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)

CVE-2026-42499
HIGH 7.5

Quadratic string concatenation in consumePhrase in net/mail

CVE-2026-42154
HIGH 7.5

Prometheus: remote read endpoint allows denial of service via crafted snappy payload

CVE-2026-42151
HIGH 7.5

Prometheus Azure AD remote write OAuth client secret exposed via config API

CVE-2026-42018
HIGH 7.5

Anonymous user token generation exposure in JFrog Artifactory

CVE-2026-40984
HIGH 7.5

Micrometer HTTP server instrumentations DoS vulnerability

CVE-2026-40983
HIGH 7.5

Micrometer gRPC server instrumentation DoS vulnerability

CVE-2026-39829
HIGH 7.5

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

CVE-2026-39820
HIGH 7.5

Quadratic string concatentation in consumeComment in net/mail

CVE-2026-34986
HIGH 7.5

Go JOSE affect by a panic in JWE decryption

CVE-2026-33814
HIGH 7.5

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

CVE-2026-33811
HIGH 7.5

Crash when handling long CNAME response in net

CVE-2026-32286
HIGH 7.5

Denial of service in github.com/jackc/pgproto3/v2

CVE-2026-32283
HIGH 7.5

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

CVE-2026-32280
HIGH 7.5

Unexpected work during chain building in crypto/x509

CVE-2026-28157
HIGH 7.5

WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability

CVE-2026-27538
HIGH 7.5

WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability

CVE-2026-27345
HIGH 7.5

WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Access Control vulnerability

CVE-2026-27137
HIGH 7.5

Incorrect enforcement of email constraints in crypto/x509

CVE-2026-25679
HIGH 7.5

Incorrect parsing of IPv6 host literals in net/url

CVE-2026-25639
HIGH 7.5

Axios affected by Denial of Service via __proto__ Key in mergeConfig

CVE-2026-21728
HIGH 7.5

Tempo query limit results in unbounded memory allocation

CVE-2026-19654
HIGH 7.5

Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

CVE-2026-19558
HIGH 7.5

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2026-19484
HIGH 7.5

@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary

CVE-2026-19481
HIGH 7.5

@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header

CVE-2026-18358
HIGH 7.5

Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service

CVE-2026-17613
HIGH 7.5

CVE-2026-17613

CVE-2026-17271
HIGH 7.5

IBM i is Affected By Multiple Vulnerabilities in the Debug Server

CVE-2026-17022
HIGH 7.5

Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard

CVE-2026-16931
HIGH 7.5

IBM i is Affected By A Denial of Service Vulnerability []

CVE-2026-15562
HIGH 7.5

Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service

CVE-2026-14456
HIGH 7.5

Unbounded Memory Growth in QUIC Server Incoming Channel Queue

CVE-2026-13676
HIGH 7.5

fast-uri vulnerable to host confusion via failed IDN canonicalization

CVE-2026-6322
HIGH 7.5

fast-uri vulnerable to host confusion via percent-encoded authority delimiters

CVE-2025-61726
HIGH 7.5

Memory exhaustion in query parameter parsing in net/url

CVE-2025-59327
HIGH 7.5

In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

CVE-2025-59322
HIGH 7.5

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.

CVE-2025-31098
HIGH 7.5

WordPress DeBounce Email Validator plugin <= 5.7 - Local File Inclusion Vulnerability

CVE-2025-2240
HIGH 7.5

Smallrye-fault-tolerance: smallrye fault tolerance

CVE-2024-12085
HIGH 7.5

Rsync: info leak via uninitialized stack contents

CVE-2018-8174
HIGH 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2017-10271
HIGH 7.5

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2026-73495
HIGH 7.4

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

CVE-2026-49857
HIGH 7.4

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

CVE-2026-42033
HIGH 7.4

Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

CVE-2026-28189
HIGH 7.4

WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion vulnerability

CVE-2026-15563
HIGH 7.4

Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos

CVE-2026-11923
HIGH 7.4

Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

CVE-2026-70355
HIGH 7.3

Microsoft SharePoint Server Elevation of Privilege Vulnerability

CVE-2026-64126
HIGH 7.3

Bluetooth: MGMT: validate Add Extended Advertising Data length

CVE-2026-62914
HIGH 7.3

Microsoft Exchange Server Spoofing Vulnerability

CVE-2026-59086
HIGH 7.3

A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.

CVE-2026-42584
HIGH 7.3

Netty: HttpClientCodec response desynchronization

CVE-2026-41605
HIGH 7.3

Apache Thrift: Swift Compact Protocol integer overflow

CVE-2026-39883
HIGH 7.3

OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijacking

CVE-2026-28188
HIGH 7.3

WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability

CVE-2026-15994
HIGH 7.3

During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.

CVE-2026-12912
HIGH 7.3

Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image

CVE-2026-11980
HIGH 7.3

Code execution in IBM Desktop App

CVE-2026-6387
HIGH 7.3

A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.

CVE-2026-73624
HIGH 7.2

GitPython before 3.1.54 Arbitrary File Overwrite via diff

CVE-2026-73620
HIGH 7.2

GitPython before 3.1.57 Arbitrary File Overwrite and Read

CVE-2026-73613
HIGH 7.2

filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink

CVE-2026-73515
HIGH 7.2

PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer

CVE-2026-73482
HIGH 7.2

phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php

CVE-2026-68752
HIGH 7.2

Project Resource Managers may escalate privileges in JFrog Artifactory

CVE-2026-66704
HIGH 7.2

WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerability

CVE-2026-66256
HIGH 7.2

Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)

CVE-2026-60926
HIGH 7.2

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-60925
HIGH 7.2

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-53799
HIGH 7.2

rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application

CVE-2026-53795
HIGH 7.2

rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest

CVE-2026-47299
HIGH 7.2

Azure Monitor Agent Elevation of Privilege Vulnerability

CVE-2026-42043
HIGH 7.2

Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

CVE-2026-27380
HIGH 7.2

WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerability

CVE-2026-18146
HIGH 7.2

Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values

CVE-2026-12618
HIGH 7.2

Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

CVE-2026-12005
HIGH 7.2

Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access

CVE-2026-6471
HIGH 7.2

PostgreSQL logical decoding can dlopen arbitrary file

CVE-2026-73652
HIGH 7.1

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

CVE-2026-73619
HIGH 7.1

GitPython before 3.1.57 Arbitrary File Read via Repo.archive()

CVE-2026-73617
HIGH 7.1

Budibase before 3.40.0 NoSQL Injection via MongoDB datasource

CVE-2026-73616
HIGH 7.1

OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference

CVE-2026-73604
HIGH 7.1

Flowise before 3.1.3 Credential Exposure via API

CVE-2026-73291
HIGH 7.1

Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag

CVE-2026-73266
HIGH 7.1

Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join

CVE-2026-73215
HIGH 7.1

The coturn server can end in a state where it does not accept more requests with "even-port" enabled.

CVE-2026-72786
HIGH 7.1

Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset

CVE-2026-70462
HIGH 7.1

rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT

CVE-2026-69117
HIGH 7.1

NetBox 4.5.8 ORM Injection via WritableNestedSerializer

CVE-2026-66700
HIGH 7.1

WordPress Smart Online Order for Clover plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66698
HIGH 7.1

WordPress SureDash plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66697
HIGH 7.1

WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66655
HIGH 7.1

WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2026-66468
HIGH 7.1

WordPress Local Delivery Drivers for WooCommerce plugin <= 3.0.0 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66449
HIGH 7.1

WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66429
HIGH 7.1

WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66426
HIGH 7.1

WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66060
HIGH 7.1

Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers

CVE-2026-65934
HIGH 7.1

BT122 plaintext pause encryption request causes DOS

CVE-2026-65580
HIGH 7.1

WordPress Agrion theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

CVE-2026-64284
HIGH 7.1

KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits

CVE-2026-64172
HIGH 7.1

KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)

CVE-2026-64121
HIGH 7.1

net: ifb: report ethtool stats over num_tx_queues

CVE-2026-61974
HIGH 7.1

WordPress Mang Board WP plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability

CVE-2026-61965
HIGH 7.1

WordPress GeekyBot plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability

CVE-2026-61960
HIGH 7.1

WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerability

CVE-2026-60908
HIGH 7.1

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Installed Base accessible data as well as unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

CVE-2026-59691
HIGH 7.1

Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer

CVE-2026-58484
HIGH 7.1

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

CVE-2026-58416
HIGH 7.1

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

CVE-2026-53792
HIGH 7.1

rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block

CVE-2026-53789
HIGH 7.1

rsync < 3.5.0 Arbitrary File Deletion via Malicious File List

CVE-2026-48495
HIGH 7.1

TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots

CVE-2026-45808
HIGH 7.1

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

CVE-2026-28187
HIGH 7.1

WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 17.211.0 - Cross Site Scripting (XSS) vulnerability

CVE-2026-28175
HIGH 7.1

WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site Scripting (XSS) vulnerability

CVE-2026-28173
HIGH 7.1

WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vulnerability

CVE-2026-28170
HIGH 7.1

WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability

CVE-2026-28158
HIGH 7.1

WordPress Do Lasso plugin <= 358 - Cross Site Scripting (XSS) vulnerability

CVE-2026-28154
HIGH 7.1

WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnerability

CVE-2026-28004
HIGH 7.1

WordPress Business Directory plugin <= 6.4.25 - Cross Site Scripting (XSS) vulnerability

CVE-2026-28003
HIGH 7.1

WordPress Maspik – Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS) vulnerability

CVE-2026-27539
HIGH 7.1

WordPress Welcart e-Commerce plugin <= 2.11.31 - Cross Site Scripting (XSS) vulnerability

CVE-2026-27536
HIGH 7.1

WordPress MailChimp Subscribe Forms plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability

CVE-2026-27535
HIGH 7.1

WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability

CVE-2026-18888
HIGH 7.1

MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data

CVE-2026-17248
HIGH 7.1

IBM i is Affected By Multiple Vulnerabilities in the Debug Server

CVE-2026-16494
HIGH 7.1

Missing Authorization in GitLab

CVE-2026-13601
HIGH 7.1

Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

CVE-2025-71397
HIGH 7.1

SurrealDB before 2.2.2 CPU Exhaustion via nested FOR loops

CVE-2025-71391
HIGH 7.1

SurrealDB before 2.2.2 Denial of Service via /sql endpoint

CVE-2024-58369
HIGH 7.1

SurrealDB before 1.1.1 Denial of Service via Global Parameters

CVE-2024-58367
HIGH 7.1

SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions

CVE-2026-65783
HIGH 7

Windows Autopilot Elevation of Privilege Vulnerability

CVE-2026-65782
HIGH 7

Windows Autopilot Elevation of Privilege Vulnerability

CVE-2026-65781
HIGH 7

Windows Autopilot Elevation of Privilege Vulnerability

CVE-2026-65780
HIGH 7

Windows Autopilot Elevation of Privilege Vulnerability

CVE-2026-65779
HIGH 7

Windows Autopilot Elevation of Privilege Vulnerability

CVE-2026-65778
HIGH 7

Windows Autopilot Elevation of Privilege Vulnerability

CVE-2026-65776
HIGH 7

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-65678
HIGH 7

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-64283
HIGH 7

KVM: guest_memfd: Treat memslot binding offset+size as unsigned values

CVE-2026-63424
HIGH 7

During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.

CVE-2026-62892
HIGH 7

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2026-62788
HIGH 7

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-62780
HIGH 7

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-62774
HIGH 7

Windows Graphics Kernel Elevation of Privilege Vulnerability

CVE-2026-62773
HIGH 7

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2026-62766
HIGH 7

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2026-62753
HIGH 7

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-62749
HIGH 7

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-62728
HIGH 7

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2026-62705
HIGH 7

Windows Bind Filter Driver Elevation of Privilege Vulnerability

CVE-2026-62693
HIGH 7

Windows MIDI Service Module Elevation of Privileges Vulnerability

CVE-2026-62690
HIGH 7

Windows Push Notifications Elevation of Privilege Vulnerability

CVE-2026-61939
HIGH 7

Winlogon Elevation of Privilege Vulnerability

CVE-2026-61929
HIGH 7

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-61927
HIGH 7

Windows Bind Filter Driver Elevation of Privilege Vulnerability

CVE-2026-61366
HIGH 7

Windows Network Connection Broker Elevation of Privilege Vulnerability

CVE-2026-61361
HIGH 7

Windows DHCP Client Remote Code Execution Vulnerability

CVE-2026-61348
HIGH 7

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-54230
HIGH 7

Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites

CVE-2026-54229
HIGH 7

Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking

CVE-2026-44495
HIGH 7

Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

CVE-2026-4786
HIGH 7

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

CVE-2026-4519
HIGH 7

webbrowser.open() allows leading dashes in URLs

CVE-2018-8120
HIGH 7

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

CVE-2026-73610
MEDIUM 6.9

SiYuan before v3.7.4 Information Disclosure via Local Storage

CVE-2026-73609
MEDIUM 6.9

SiYuan before v3.7.4 Information Disclosure via getBookmarkLabels

CVE-2026-73607
MEDIUM 6.9

SiYuan before v3.7.4 Information Disclosure via getOutlineStorage

CVE-2026-73606
MEDIUM 6.9

SiYuan before v3.7.4 Information Disclosure via getRefIDs

CVE-2026-73605
MEDIUM 6.9

SiYuan before v3.7.4 Path Traversal via getUniqueFilename

CVE-2026-72712
MEDIUM 6.9

Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet

CVE-2026-70459
MEDIUM 6.9

rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry

CVE-2026-67613
MEDIUM 6.9

CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport

CVE-2026-63426
MEDIUM 6.9

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

CVE-2026-55401
MEDIUM 6.9

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

CVE-2026-53798
MEDIUM 6.9

rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping

CVE-2026-53794
MEDIUM 6.9

rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error

CVE-2026-53788
MEDIUM 6.9

rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping

CVE-2026-53786
MEDIUM 6.9

rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive

CVE-2026-53785
MEDIUM 6.9

rsync < 3.5.0 Path Traversal Write Escape via --relative Mode

CVE-2026-46688
MEDIUM 6.9

Meeting Room Booking System has an unauthenticated open redirect

CVE-2026-42039
MEDIUM 6.9

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

CVE-2026-40895
MEDIUM 6.9

follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets

CVE-2026-16455
MEDIUM 6.9

Local privilege escalation via improper input sanitization in execl() call

CVE-2026-12036
MEDIUM 6.9

An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.

CVE-2026-7774
MEDIUM 6.9

tarfile.data_filter path traversal bypass allows writing outside the extraction directory

CVE-2026-4901
MEDIUM 6.9

Insertion of Sesitive Information into Log File in AlanWeb SCADA

CVE-2025-13465
MEDIUM 6.9

Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions

CVE-2026-73419
MEDIUM 6.8

NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

CVE-2026-71194
MEDIUM 6.8

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.

CVE-2026-65939
MEDIUM 6.8

WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.

CVE-2026-62702
MEDIUM 6.8

Windows Graphics Kernel Denial of Service Vulnerability

CVE-2026-62699
MEDIUM 6.8

Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability

CVE-2026-19502
MEDIUM 6.8

Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI

CVE-2026-17268
MEDIUM 6.8

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2025-7708
MEDIUM 6.8

Sensitive Data Exposure in Atlas Software's k12net

CVE-2022-49051
MEDIUM 6.8

net: usb: aqc111: Fix out-of-bounds accesses in RX fixup

CVE-2026-72719
MEDIUM 6.7

Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter

CVE-2026-70330
MEDIUM 6.7

Windows DNS Elevation of Privilege Vulnerability

CVE-2026-73645
MEDIUM 6.6

OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.

CVE-2026-73583
MEDIUM 6.6

Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr

CVE-2026-68756
MEDIUM 6.6

Potential insecure deserialization in JFrog Artifactory

CVE-2026-45819
MEDIUM 6.6

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

CVE-2026-19696
MEDIUM 6.6

Out-of-bounds Write in Wireshark

CVE-2024-5042
MEDIUM 6.6

Submariner-operator: rbac permissions can allow for the spread of node compromises

CVE-2026-73562
MEDIUM 6.5

Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

CVE-2026-73559
MEDIUM 6.5

vLLM: Completion prompt lists fan out into unbounded engine requests

CVE-2026-73357
MEDIUM 6.5

WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability

CVE-2026-73340
MEDIUM 6.5

WordPress Featured Image from URL plugin <= 5.3.3 - Cross Site Scripting (XSS) vulnerability

CVE-2026-73265
MEDIUM 6.5

RustFS: Version-specific object reads authorize the non-version action

CVE-2026-73239
MEDIUM 6.5

Apache Allura: Missing permission checks IDOR

CVE-2026-72907
MEDIUM 6.5

ERPNext: Broken Access Control on certain endpoint

CVE-2026-70328
MEDIUM 6.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2026-70327
MEDIUM 6.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2026-68971
MEDIUM 6.5

Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints

CVE-2026-68969
MEDIUM 6.5

Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext

CVE-2026-66693
MEDIUM 6.5

WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability

CVE-2026-66687
MEDIUM 6.5

WordPress WpBookingly plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66660
MEDIUM 6.5

WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control vulnerability

CVE-2026-66471
MEDIUM 6.5

WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66467
MEDIUM 6.5

WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66464
MEDIUM 6.5

WordPress Internal Link Optimiser plugin <= 5.2.7 - Broken Access Control vulnerability

CVE-2026-66460
MEDIUM 6.5

WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66459
MEDIUM 6.5

WordPress AI for SEO plugin <= 2.4.2 - Broken Access Control vulnerability

CVE-2026-66456
MEDIUM 6.5

WordPress Profile Extra Fields by BestWebSoft plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability

CVE-2026-66454
MEDIUM 6.5

WordPress WP Social Avatar plugin <= 1.5 - Broken Access Control vulnerability

CVE-2026-66444
MEDIUM 6.5

WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability

CVE-2026-65794
MEDIUM 6.5

Windows SMB Client Information Disclosure Vulnerability

CVE-2026-65785
MEDIUM 6.5

Windows DHCP Client Denial of Service Vulnerability

CVE-2026-65660
MEDIUM 6.5

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2026-65017
MEDIUM 6.5

Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)

CVE-2026-62912
MEDIUM 6.5

Microsoft Exchange Server Denial of Service Vulnerability

CVE-2026-62902
MEDIUM 6.5

.NET Information Disclosure Vulnerability

CVE-2026-62839
MEDIUM 6.5

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2026-62782
MEDIUM 6.5

Windows SMB Client Information Disclosure Vulnerability

CVE-2026-62750
MEDIUM 6.5

Windows HTTP Protocol Stack Tampering Vulnerability

CVE-2026-61978
MEDIUM 6.5

WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerability

CVE-2026-61924
MEDIUM 6.5

Windows Remote Desktop Client Information Disclosure Vulnerability

CVE-2026-61921
MEDIUM 6.5

Windows Remote Desktop Client Information Disclosure Vulnerability

CVE-2026-61918
MEDIUM 6.5

Windows Remote Desktop Client Information Disclosure Vulnerability

CVE-2026-61345
MEDIUM 6.5

Microsoft Remote Registry Service Denial of Service Vulnerability

CVE-2026-58481
MEDIUM 6.5

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

CVE-2026-57897
MEDIUM 6.5

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

CVE-2026-49466
MEDIUM 6.5

Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes

CVE-2026-48411
MEDIUM 6.5

Adobe Commerce | Incorrect Authorization (CWE-863)

CVE-2026-48375
MEDIUM 6.5

ColdFusion | Incorrect Authorization (CWE-863)

CVE-2026-47233
MEDIUM 6.5

Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incomplete fix of #2024

CVE-2026-47127
MEDIUM 6.5

Ghostfolio has a Stripe subscription bypass

CVE-2026-42044
MEDIUM 6.5

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

CVE-2026-41607
MEDIUM 6.5

Apache Thrift: C++ JSON OOB read

CVE-2026-40375
MEDIUM 6.5

Microsoft Dynamics Business Central Information Disclosure Vulnerability

CVE-2026-28182
MEDIUM 6.5

WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Cross Site Scripting (XSS) vulnerability

CVE-2026-28181
MEDIUM 6.5

WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability

CVE-2026-28174
MEDIUM 6.5

WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability

CVE-2026-28159
MEDIUM 6.5

WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerability

CVE-2026-28155
MEDIUM 6.5

WordPress Do Lasso plugin <= 358 - Insecure Direct Object References (IDOR) vulnerability

CVE-2026-27999
MEDIUM 6.5

WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability

CVE-2026-27537
MEDIUM 6.5

WordPress Popup by Supsystic plugin <= 1.11.2 - Cross Site Scripting (XSS) vulnerability

CVE-2026-27145
MEDIUM 6.5

Inefficient candidate hostname parsing in crypto/x509

CVE-2026-18744
MEDIUM 6.5

CVE-2026-18744

CVE-2026-18728
MEDIUM 6.5

Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing

CVE-2026-18727
MEDIUM 6.5

Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing

CVE-2026-18726
MEDIUM 6.5

Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing

CVE-2026-17419
MEDIUM 6.5

IBM i is Affected By Multiple Vulnerabilities in SQL

CVE-2026-17266
MEDIUM 6.5

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2026-14663
MEDIUM 6.5

PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext

CVE-2026-14298
MEDIUM 6.5

Denial of service via resource exhaustion in Mattermost

CVE-2026-12236
MEDIUM 6.5

Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length

CVE-2024-9355
MEDIUM 6.5

Golang-fips: golang fips zeroed buffer

CVE-2026-62708
MEDIUM 6.4

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-3639
MEDIUM 6.4

PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

CVE-2025-7195
MEDIUM 6.4

Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd

CVE-2026-73603
MEDIUM 6.3

Flowise before 3.1.4 Credential Abuse via Text-to-Speech

CVE-2026-73585
MEDIUM 6.3

Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack

CVE-2026-73584
MEDIUM 6.3

Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling

CVE-2026-73576
MEDIUM 6.3

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

CVE-2026-73557
MEDIUM 6.3

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

CVE-2026-73412
MEDIUM 6.3

Shescape: Path disclosure on Unix with Zsh

CVE-2026-72916
MEDIUM 6.3

Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses

CVE-2026-67287
MEDIUM 6.3

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0

CVE-2026-66689
MEDIUM 6.3

WordPress Anti Spam and list cleaner – AcyChecker plugin <= 2.0.0 - Broken Access Control vulnerability

CVE-2026-50544
MEDIUM 6.3

NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions

CVE-2026-39828
MEDIUM 6.3

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

CVE-2026-19503
MEDIUM 6.3

Insufficient OIDC endpoint validation could invoke unintended local protocol handlers

CVE-2026-18250
MEDIUM 6.3

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2026-17420
MEDIUM 6.3

IBM i is Affected By Multiple Vulnerabilities in SQL

CVE-2026-7210
MEDIUM 6.3

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

CVE-2026-3276
MEDIUM 6.3

Potential DoS via quadratic complexity in unicodedata.normalize()

CVE-2026-72522
MEDIUM 6.2

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

CVE-2026-56755
MEDIUM 6.2

Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

CVE-2026-56657
MEDIUM 6.2

Gitea SSH Key Parser Denial of Service

CVE-2026-73572
MEDIUM 6.1

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.

CVE-2026-73506
MEDIUM 6.1

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

CVE-2026-73434
MEDIUM 6.1

Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing

CVE-2026-58413
MEDIUM 6.1

EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

CVE-2026-48551
MEDIUM 6.1

Nagios Core / XI CSRF Protection Bypass via Double-Submit Cookie

CVE-2026-17431
MEDIUM 6.1

PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for

CVE-2026-12232
MEDIUM 6.1

Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties

CVE-2026-7163
MEDIUM 6.1

Assisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosure

CVE-2018-19953
MEDIUM 6.1

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE-2018-6882
MEDIUM 6.1

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

CVE-2026-73627
MEDIUM 6

JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass

CVE-2026-73488
MEDIUM 6

Flowise before 3.1.3 IDOR via customer-default-source endpoint

CVE-2026-66654
MEDIUM 6

WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerability

CVE-2026-66455
MEDIUM 6

WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability

CVE-2026-55400
MEDIUM 6

CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.

CVE-2026-19643
MEDIUM 6

Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms

CVE-2026-19642
MEDIUM 6

Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp

CVE-2026-18677
MEDIUM 6

Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity

CVE-2026-18368
MEDIUM 6

Heap buffer overflow in Modbusgwd

CVE-2026-4224
MEDIUM 6

Stack overflow parsing XML with deeply nested DTD content models

CVE-2026-3644
MEDIUM 6

Incomplete control character validation in http.cookies

CVE-2026-3087
MEDIUM 6

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

CVE-2026-0294
MEDIUM 6

Prisma Access Agent: Local Privilege Escalation

CVE-2025-71393
MEDIUM 6

SurrealDB before 2.2.2 Memory Exhaustion via Nested Functions

CVE-2026-73344
MEDIUM 5.9

WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability

CVE-2026-73230
MEDIUM 5.9

Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets

CVE-2026-73068
MEDIUM 5.9

ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tables

CVE-2026-58482
MEDIUM 5.9

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

CVE-2026-49343
MEDIUM 5.9

Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS

CVE-2026-44577
MEDIUM 5.9

Next.js: Denial of Service in the Image Optimization API

CVE-2026-18663
MEDIUM 5.9

389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control

CVE-2026-16459
MEDIUM 5.9

Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto

CVE-2026-16458
MEDIUM 5.9

Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto

CVE-2026-12233
MEDIUM 5.9

Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention

CVE-2026-8328
MEDIUM 5.9

FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address

CVE-2026-0299
MEDIUM 5.9

GlobalProtect App: Local Privilege Escalation Vulnerabilities

CVE-2026-73213
MEDIUM 5.8

Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)

CVE-2026-53796
MEDIUM 5.8

rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling

CVE-2026-42581
MEDIUM 5.8

Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

CVE-2026-18679
MEDIUM 5.8

Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured

CVE-2025-71390
MEDIUM 5.8

SurrealDB before 2.3.6 deny-net Bypass via DNS Resolution

CVE-2026-73651
MEDIUM 5.7

TypeORM: migration:generate template-literal code injection

CVE-2026-64676
MEDIUM 5.7

Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory

CVE-2026-53800
MEDIUM 5.7

rsync < 3.5.0 Symlink Race Condition via --remove-source-files

CVE-2026-53797
MEDIUM 5.7

rsync < 3.5.0 Symlink Race Condition Information Disclosure

CVE-2026-14256
MEDIUM 5.7

ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.

CVE-2026-12539
MEDIUM 5.7

Docker Sandboxes ICMP egress restriction bypass after daemon restart

CVE-2026-12039
MEDIUM 5.7

Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution

CVE-2026-2297
MEDIUM 5.7

SourcelessFileLoader does not use io.open_code()

CVE-2026-1502
MEDIUM 5.7

HTTP client proxy tunnel headers not validated for CR/LF

CVE-2026-73647
MEDIUM 5.6

Quasar Framework: Prototype pollution in Quasar extend() utility

CVE-2026-71407
MEDIUM 5.6

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

CVE-2026-0293
MEDIUM 5.6

Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

CVE-2025-62314
MEDIUM 5.6

HCL AION is affected by multiple security vulnerabilities.

CVE-2026-68808
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2026-68802
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2026-68799
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2026-68797
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2026-66809
MEDIUM 5.5

Microsoft Office Graphics Component Information Disclosure Vulnerability

CVE-2026-65784
MEDIUM 5.5

Windows NTFS Information Disclosure Vulnerability

CVE-2026-64289
MEDIUM 5.5

iommufd: Set upper bounds on cache invalidation entry_num and entry_len

CVE-2026-64288
MEDIUM 5.5

KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB

CVE-2026-64285
MEDIUM 5.5

KVM: SEV: Pin source page for write when adding CPUID data for SNP guest

CVE-2026-64278
MEDIUM 5.5

i2c: imx-lpi2c: mark I2C adapter when hardware is powered down

CVE-2026-64275
MEDIUM 5.5

Input: elan_i2c - prevent division by zero and arithmetic underflow

CVE-2026-64248
MEDIUM 5.5

MIPS: smp: report dying CPU to RCU in stop_this_cpu()

CVE-2026-64241
MEDIUM 5.5

gpio: rockchip: teardown bugs and resource leaks

CVE-2026-64240
MEDIUM 5.5

media: rc: igorplugusb: fix control request setup packet

CVE-2026-64238
MEDIUM 5.5

gpio: shared: fix deadlock on shared proxy's parent removal

CVE-2026-64229
MEDIUM 5.5

x86/mm: Disable broadcast TLB flush when PCID is disabled

CVE-2026-64228
MEDIUM 5.5

net: ethtool: phy: avoid NULL deref when PHY driver is unbound

CVE-2026-64227
MEDIUM 5.5

ACPI: driver: Check ACPI_COMPANION() against NULL during probe

CVE-2026-64177
MEDIUM 5.5

phonet/pep: disable BH around forwarded sk_receive_skb()

CVE-2026-64174
MEDIUM 5.5

wifi: cfg80211: advance loop vars in cfg80211_merge_profile()

CVE-2026-64173
MEDIUM 5.5

tracing: Do not call map->ops->elt_free() if elt_alloc() fails

CVE-2026-64171
MEDIUM 5.5

i2c: tegra: fix pm_runtime leak on mutex_lock failure

CVE-2026-64170
MEDIUM 5.5

spi: qup: fix error pointer deref after DMA setup failure

CVE-2026-64169
MEDIUM 5.5

spi: ep93xx: fix error pointer deref after DMA setup failure

CVE-2026-64168
MEDIUM 5.5

spi: sprd: fix error pointer deref after DMA setup failure

CVE-2026-64167
MEDIUM 5.5

kho: skip KHO for crash kernel

CVE-2026-64166
MEDIUM 5.5

firmware: arm_ffa: Check for NULL FF-A ID table while driver registration

CVE-2026-64165
MEDIUM 5.5

ARM: integrator: Fix early initialization

CVE-2026-64164
MEDIUM 5.5

btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()

CVE-2026-64163
MEDIUM 5.5

test_kprobes: clear kprobes between test runs

CVE-2026-64161
MEDIUM 5.5

net: ti: icssm-prueth: fix eth_ports_node leak in probe

CVE-2026-64156
MEDIUM 5.5

netfs, afs: Fix write skipping in dir/link writepages

CVE-2026-64135
MEDIUM 5.5

hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX

CVE-2026-64131
MEDIUM 5.5

mm/memory: fix spurious warning when unmapping device-private/exclusive pages

CVE-2026-64130
MEDIUM 5.5

mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free

CVE-2026-64129
MEDIUM 5.5

mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page

CVE-2026-64128
MEDIUM 5.5

Bluetooth: ISO: drop ISO_END frames received without prior ISO_START

CVE-2026-64127
MEDIUM 5.5

Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer

CVE-2026-64120
MEDIUM 5.5

net: ethtool: fix NULL pointer dereference in phy_reply_size

CVE-2026-64119
MEDIUM 5.5

l2tp: use list_del_rcu in l2tp_session_unhash

CVE-2026-63517
MEDIUM 5.5

Microsoft Office Graphics Component Information Disclosure Vulnerability

CVE-2026-62887
MEDIUM 5.5

Windows NTFS Information Disclosure Vulnerability

CVE-2026-62842
MEDIUM 5.5

Microsoft Office Graphics Component Information Disclosure Vulnerability

CVE-2026-62798
MEDIUM 5.5

Win32k Information Disclosure Vulnerability

CVE-2026-62796
MEDIUM 5.5

Windows NTFS Information Disclosure Vulnerability

CVE-2026-62793
MEDIUM 5.5

Windows NTFS Information Disclosure Vulnerability

CVE-2026-62786
MEDIUM 5.5

Win32k Information Disclosure Vulnerability

CVE-2026-62775
MEDIUM 5.5

Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability

CVE-2026-62746
MEDIUM 5.5

Win32k Information Disclosure Vulnerability

CVE-2026-62743
MEDIUM 5.5

Win32k Information Disclosure Vulnerability

CVE-2026-62740
MEDIUM 5.5

Windows Imaging Component Information Disclosure Vulnerability

CVE-2026-62738
MEDIUM 5.5

Windows Management Instrumentation Information Disclosure Vulnerability

CVE-2026-62730
MEDIUM 5.5

Windows Wired AutoConfig Service Information Disclosure Vulnerability

CVE-2026-62709
MEDIUM 5.5

Windows GDI+ Information Disclosure Vulnerability

CVE-2026-62703
MEDIUM 5.5

Windows DWM Core Library Information Disclosure Vulnerability

CVE-2026-61936
MEDIUM 5.5

Windows Defender Firewall Service Security Feature Bypass Vulnerability

CVE-2026-61933
MEDIUM 5.5

Windows DWM Core Library Information Disclosure Vulnerability

CVE-2026-61928
MEDIUM 5.5

Windows Hello Tampering Vulnerability

CVE-2026-61360
MEDIUM 5.5

Windows GDI Information Disclosure Vulnerability

CVE-2026-61347
MEDIUM 5.5

Windows Event Logging Service Information Disclosure Vulnerability

CVE-2026-58414
MEDIUM 5.5

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

CVE-2026-19710
MEDIUM 5.5

SourceCodester Simple Student Information System view_department.php sql injection

CVE-2026-18678
MEDIUM 5.5

Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured

CVE-2025-15684
MEDIUM 5.5

Open5GS CER init.c diam_log_func assertion

CVE-2022-49309
MEDIUM 5.5

drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback()

CVE-2022-49296
MEDIUM 5.5

ceph: fix possible deadlock when holding Fwb to get inline_data

CVE-2022-49294
MEDIUM 5.5

drm/amd/display: Check if modulo is 0 before dividing.

CVE-2022-49169
MEDIUM 5.5

f2fs: use spin_lock to avoid hang

CVE-2022-49137
MEDIUM 5.5

drm/amd/amdgpu/amdgpu_cs: fix refcount leak of a dma_fence obj

CVE-2022-49135
MEDIUM 5.5

drm/amd/display: Fix memory leak

CVE-2022-49133
MEDIUM 5.5

drm/amdkfd: svm range restore work deadlock when process exit

CVE-2022-49132
MEDIUM 5.5

ath11k: pci: fix crash on suspend if board file is not found

CVE-2022-49130
MEDIUM 5.5

ath11k: mhi: use mhi_sync_power_up()

CVE-2022-49126
MEDIUM 5.5

scsi: mpi3mr: Fix memory leaks

CVE-2022-49123
MEDIUM 5.5

ath11k: Fix frames flush failure caused by deadlock

CVE-2022-49118
MEDIUM 5.5

scsi: hisi_sas: Free irq vectors in order for v3 HW

CVE-2022-49112
MEDIUM 5.5

mt76: fix monitor mode crash with sdio driver

CVE-2022-49109
MEDIUM 5.5

ceph: fix inode reference leakage in ceph_get_snapdir()

CVE-2022-49107
MEDIUM 5.5

ceph: fix memory leak in ceph_readdir when note_last_dentry returns error

CVE-2022-49105
MEDIUM 5.5

staging: wfx: fix an error handling in wfx_init_common()

CVE-2022-49104
MEDIUM 5.5

staging: vchiq_core: handle NULL result of find_service_by_handle

CVE-2022-49102
MEDIUM 5.5

habanalabs: fix possible memory leak in MMU DR fini

CVE-2022-49069
MEDIUM 5.5

drm/amd/display: Fix by adding FPU protection for dcn30_internal_validate_bw

CVE-2022-48825
MEDIUM 5.5

scsi: qedf: Add stag_work to all the vports

CVE-2022-48823
MEDIUM 5.5

scsi: qedf: Fix refcount issue when LOGO is received during TMF

CVE-2022-48633
MEDIUM 5.5

drm/gma500: Fix WARN_ON(lock->magic != lock) error

CVE-2026-73295
MEDIUM 5.4

Material for MkDocs: DOM XSS in search suggestions via query parameter

CVE-2026-73287
MEDIUM 5.4

RustFS: FTPS MKD bypasses IAM CreateBucket authorization

CVE-2026-73250
MEDIUM 5.4

Notepad++: Install-time PowerShell command injection through installation path

CVE-2026-67990
MEDIUM 5.4

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.

CVE-2026-63134
MEDIUM 5.4

Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation

CVE-2026-60957
MEDIUM 5.4

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

CVE-2026-48762
MEDIUM 5.4

TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler

CVE-2026-48376
MEDIUM 5.4

ColdFusion | Improper Encoding or Escaping of Output (CWE-116)

CVE-2026-47229
MEDIUM 5.4

Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation

CVE-2026-19135
MEDIUM 5.4

OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes

CVE-2026-19088
MEDIUM 5.4

ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication

CVE-2026-14332
MEDIUM 5.4

Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action

CVE-2026-73628
MEDIUM 5.3

Serendipity 2.3.5 Reflected XSS via search clean-URL route

CVE-2026-73621
MEDIUM 5.3

GitPython before 3.1.56 Arbitrary File Truncation via Commit.count

CVE-2026-73565
MEDIUM 5.3

@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake

CVE-2026-73558
MEDIUM 5.3

vLLM: Cross-User Data Leak Vulnerability

CVE-2026-73556
MEDIUM 5.3

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574

CVE-2026-73555
MEDIUM 5.3

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

CVE-2026-73508
MEDIUM 5.3

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

CVE-2026-73481
MEDIUM 5.3

phpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules

CVE-2026-73430
MEDIUM 5.3

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

CVE-2026-73403
MEDIUM 5.3

WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability

CVE-2026-73401
MEDIUM 5.3

WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability

CVE-2026-73353
MEDIUM 5.3

WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Control vulnerability

CVE-2026-73349
MEDIUM 5.3

WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability

CVE-2026-73306
MEDIUM 5.3

Budibase: Account Enumeration via Login Lockout Response Differential

CVE-2026-73244
MEDIUM 5.3

kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing

CVE-2026-73228
MEDIUM 5.3

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

CVE-2026-73038
MEDIUM 5.3

NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name

CVE-2026-70466
MEDIUM 5.3

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

CVE-2026-66377
MEDIUM 5.3

Anonymous users may access restricted Artifactory repository information

CVE-2026-65936
MEDIUM 5.3

RS9116W/SiWx917 malformed packet with increased length field causes memory leak

CVE-2026-65933
MEDIUM 5.3

BT122 malformed packet with increased length field causes memory leak

CVE-2026-65932
MEDIUM 5.3

BT122 stops advertising

CVE-2026-64607
MEDIUM 5.3

Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

CVE-2026-62757
MEDIUM 5.3

Windows Schannel Security Feature Bypass Vulnerability

CVE-2026-59502
MEDIUM 5.3

Priority - CWE-203: Observable Discrepancy

CVE-2026-48043
MEDIUM 5.3

netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

CVE-2026-46405
MEDIUM 5.3

OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens

CVE-2026-41606
MEDIUM 5.3

Apache Thrift: c_glib dispatch stack overflow

CVE-2026-39835
MEDIUM 5.3

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

CVE-2026-19487
MEDIUM 5.3

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass

CVE-2026-18750
MEDIUM 5.3

CVE-2026-18750

CVE-2026-18675
MEDIUM 5.3

Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid

CVE-2026-18673
MEDIUM 5.3

Kong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authentication

CVE-2026-17021
MEDIUM 5.3

Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering

CVE-2026-15141
MEDIUM 5.3

Referer Validation Bypass in TL-WR820N Web Management Interface

CVE-2026-14672
MEDIUM 5.3

PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle

CVE-2026-12003
MEDIUM 5.3

CPython >3.11 Insecure Input Validation resulting in privilege escalation

CVE-2026-7427
MEDIUM 5.3

Allocation of Resources Without Limits or Throttling in GitLab

CVE-2026-3835
MEDIUM 5.3

Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access

CVE-2026-0298
MEDIUM 5.2

GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)

CVE-2026-0297
MEDIUM 5.2

GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

CVE-2026-73671
MEDIUM 5.1

Saurus CMS Unauthenticated Open Redirect via logout url parameter

CVE-2026-73648
MEDIUM 5.1

rails-html-sanitizer: Possible XSS vulnerability with certain configurations

CVE-2026-73423
MEDIUM 5.1

Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

CVE-2026-73037
MEDIUM 5.1

Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter

CVE-2026-72506
MEDIUM 5.1

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.

CVE-2026-19744
MEDIUM 5.1

Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes

CVE-2026-19716
MEDIUM 5.1

Stored Cross-site Scripting in Pentestify user account deletion via unescaped username

CVE-2026-18676
MEDIUM 5.1

Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin

CVE-2026-71475
MEDIUM 5

Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path

CVE-2026-61368
MEDIUM 5

Windows Hyper-V Information Disclosure Vulnerability

CVE-2026-60907
MEDIUM 5

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).

CVE-2026-48384
MEDIUM 4.9

ColdFusion | Improper Input Validation (CWE-20)

CVE-2024-8995
MEDIUM 4.9

Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access

CVE-2026-72727
MEDIUM 4.8

Discourse: Stored XSS in the moderation review queue

CVE-2026-42041
MEDIUM 4.8

Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

CVE-2026-40175
MEDIUM 4.8

Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

CVE-2026-11970
MEDIUM 4.8

This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.

CVE-2026-73563
MEDIUM 4.7

Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend`

CVE-2026-73490
MEDIUM 4.7

Loofah: SVG `href` attribute bypasses local-reference restriction

CVE-2026-64282
MEDIUM 4.7

KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier

CVE-2026-49820
MEDIUM 4.7

Probo has an open redirect bypass via path normalization

CVE-2026-19695
MEDIUM 4.7

Stack-based Buffer Overflow in Wireshark

CVE-2026-19694
MEDIUM 4.7

Heap-based Buffer Overflow in Wireshark

CVE-2026-18622
MEDIUM 4.7

Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid

CVE-2025-52640
MEDIUM 4.7

HCL AION is affected by multiple security vulnerabilities.

CVE-2022-49286
MEDIUM 4.7

tpm: use try_get_ops() in tpm-space.c

CVE-2026-64922
MEDIUM 4.6

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2026-64916
MEDIUM 4.6

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2026-62917
MEDIUM 4.6

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2026-61350
MEDIUM 4.6

Windows NTFS Information Disclosure Vulnerability

CVE-2026-21760
MEDIUM 4.6

Unauthorized Access to Admin Functionality via Forced Browsing

CVE-2026-21269
MEDIUM 4.6

ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)

CVE-2026-0296
MEDIUM 4.5

GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

CVE-2026-18477
MEDIUM 4.4

Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape

CVE-2026-72732
MEDIUM 4.3

Discourse: Templates endpoint exposes hidden tag names

CVE-2026-72722
MEDIUM 4.3

Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs

CVE-2026-70547
MEDIUM 4.3

Potential unauthorized metadata exposure in JFrog Artifactory

CVE-2026-66379
MEDIUM 4.3

Authenticated users may view private Puppet module metadata

CVE-2026-66378
MEDIUM 4.3

Authenticated users may access private NuGet metadata

CVE-2026-63295
MEDIUM 4.3

Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`

CVE-2026-59763
MEDIUM 4.3

Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

CVE-2026-49856
MEDIUM 4.3

@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization

CVE-2026-21832
MEDIUM 4.3

HCL AION is affected by multiple security vulnerabilities.

CVE-2026-19519
MEDIUM 4.3

Claircore: claircore: denial of service via unchecked type assertion in rpm header parser

CVE-2026-19182
MEDIUM 4.3

OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only

CVE-2026-18433
MEDIUM 4.3

Incorrect Authorization in GitLab

CVE-2026-18244
MEDIUM 4.3

Missing Authorization in GitLab

CVE-2026-18148
MEDIUM 4.3

IBM i is Affected By Multiple Vulnerabilities in Navigator for i

CVE-2026-18024
MEDIUM 4.3

PostgreSQL ascii() function reads past end of buffer

CVE-2026-17222
MEDIUM 4.3

IBM i is Affected By Multiple Vulnerabilities in SQL

CVE-2026-17109
MEDIUM 4.3

IBM i is Affected By Multiple Vulnerabilities in SQL

CVE-2026-17020
MEDIUM 4.3

Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure

CVE-2026-16480
MEDIUM 4.3

IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.

CVE-2026-14857
MEDIUM 4.3

WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR

CVE-2026-14678
MEDIUM 4.3

PostgreSQL pg_trgm picksplit reads past end of buffer

CVE-2026-13612
MEDIUM 4.3

KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR

CVE-2026-13177
MEDIUM 4.3

Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR

CVE-2026-8667
MEDIUM 4.3

Incorrect Authorization in GitLab

CVE-2026-6821
MEDIUM 4.3

Missing Authorization in GitLab

CVE-2026-6470
MEDIUM 4.3

PostgreSQL fails to check type USAGE privilege

CVE-2026-4879
MEDIUM 4.3

Missing Authorization in GitLab

CVE-2018-13374
MEDIUM 4.3

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CVE-2026-21761
MEDIUM 4.2

CORS Misconfiguration in DevOps Loop

CVE-2026-19730
MEDIUM 4.2

Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives

CVE-2026-14681
MEDIUM 4.2

PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL

CVE-2026-14666
MEDIUM 4.2

PostgreSQL row security caching disregards role modifications

CVE-2026-7366
MEDIUM 4.2

IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall

CVE-2026-0864
MEDIUM 4.1

Configuration Injection via Carriage Return (\r) in write() method

CVE-2026-0295
MEDIUM 4.1

GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

CVE-2026-15028
LOW 3.9

Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header

CVE-2026-70467
LOW 3.8

A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVE-2026-16241
LOW 3.8

PostgreSQL ECPG integer underflow can crash the client

CVE-2026-14673
LOW 3.8

PostgreSQL amcheck does not clear untrusted search path

CVE-2026-6469
LOW 3.8

PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership

CVE-2026-73425
LOW 3.7

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

CVE-2026-21762
LOW 3.7

Missing HTTP Security Headers in DevOps Loop

CVE-2026-14213
LOW 3.7

Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR

CVE-2025-62318
LOW 3.7

HCL AION is affected by multiple security vulnerabilities.

CVE-2026-60896
LOW 3.6

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Work in Process. CVSS 3.1 Base Score 3.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).

CVE-2025-62315
LOW 3.4

HCL AION is affected by multiple security vulnerabilities.

CVE-2026-18096
LOW 3.3

IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak

CVE-2025-9486
LOW 3.3

Incorrect Privilege Assignment in GitLab

CVE-2026-73575
LOW 3.1

In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.

CVE-2026-73574
LOW 3.1

In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.

CVE-2026-73573
LOW 3.1

In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.

CVE-2026-73571
LOW 3.1

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.

CVE-2026-21764
LOW 3.1

Insufficient Input Validation in DevOps Loop

CVE-2026-18246
LOW 3

IBM i is Affected By security restrictions bypass in Navigator for i

CVE-2026-42578
LOW 2.9

Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

CVE-2026-58511
LOW 2.7

Webhook Authorization Header Returned in Plaintext via API

CVE-2026-18503
LOW 2.4

Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()

CVE-2026-73491
LOW 2.3

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

CVE-2025-71396
LOW 2.3

SurrealDB before 2.2.2 Denial of Service via JavaScript Scripting

CVE-2025-71394
LOW 2.3

SurrealDB before 2.2.2 Local File Read via DEFINE ANALYZER

CVE-2026-73427
LOW 2.1

Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController)

CVE-2026-0292
LOW 2.1

Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

CVE-2026-48791
LOW 2

Sigstore Java has a vulnerability with bundle verification of integratedTime

CVE-2026-6879
LOW 2

Quadratic Behavior in xml.etree.ElementPath Index Predicates

CVE-2026-4360
LOW 2

Tarfile.extract() doesn't fully respect filter parameter

CVE-2025-13462
LOW 2

tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

CVE-2026-60891
LOW 1.9

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVE-2026-0301
LOW 1.7

PAN-OS: Information Disclosure Vulnerability in URL Filtering

CVE-2026-0291
LOW 1.1

Prisma Access Agent: Authenticated Limited File Deletion on Linux

CVE-2026-0290
LOW 0.5

Prisma Browser: Sensitive Information Disclosure Vulnerability

CVE-2026-0289
LOW 0.5

Prisma Browser: Inappropriate Implementation in Account Protection

CVE-2026-73626
NONE

JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager

CVE-2026-68454
NONE

KVM: s390: pci: Fix handling of AIF enable without AISB

CVE-2026-68453
NONE

s390/zcrypt: Fix buffer over-read in cca_cipher2protkey

CVE-2026-68452
NONE

s390/zcrypt: Validate length for CCA AES cipher key requests

CVE-2026-68451
NONE

s390/zcrypt: Validate length for CCA ECC private key requests

CVE-2026-68111
NONE

drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()

CVE-2026-68110
NONE

drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()

CVE-2026-68109
NONE

drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()

CVE-2026-68108
NONE

drm/amdgpu/vce: fix integer overflow in image size

CVE-2026-68107
NONE

drm/amdgpu/vcn4: avoid rereading IB param length

CVE-2026-68106
NONE

drm/amdgpu: fix division by zero with invalid uvd dimensions

CVE-2026-68105
NONE

drm/amdgpu: Fix kernel panic during driver load failure

CVE-2026-68104
NONE

drm/amdgpu: invoke pm_genpd_remove() before freeing genpd

CVE-2026-68103
NONE

drm/amdgpu: reject mapping a reserved doorbell to a new queue

CVE-2026-68100
NONE

ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl

CVE-2026-68098
NONE

ksmbd: bound DACL dedup walk to copied ACEs

CVE-2026-68097
NONE

ksmbd: validate ACE size against SID sub-authorities

CVE-2026-68088
NONE

usb: gadget: function: rndis: add length check to response query

CVE-2026-59765
NONE

SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

CVE-2026-58510
NONE

GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

CVE-2026-58508
NONE

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

CVE-2026-58507
NONE

Private Repository Existence Disclosure via go-get Meta Endpoint

CVE-2026-58445
NONE

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

CVE-2026-58444
NONE

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

CVE-2026-58443
NONE

Public-only repository tokens can update private PR head branches

CVE-2026-58442
NONE

Repository migration SSRF via multi-answer DNS allow-list bypass

CVE-2026-58441
NONE

SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

CVE-2026-58440
NONE

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)

CVE-2026-58439
NONE

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

CVE-2026-58438
NONE

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

CVE-2026-58437
NONE

Repository Visibility Manipulation via Git Push Options

CVE-2026-58436
NONE

ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

CVE-2026-58435
NONE

Gitea LFS Deploy-Key Privilege Escalation

CVE-2026-58434
NONE

Private Repository Metadata Remains Accessible After Access Revocation

CVE-2026-58433
NONE

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

CVE-2026-58432
NONE

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea

CVE-2026-58431
NONE

Public-only API token restriction is not enforced on team API routes

CVE-2026-58429
NONE

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

CVE-2026-58428
NONE

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

CVE-2026-58427
NONE

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

CVE-2026-58425
NONE

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

CVE-2026-58420
NONE

Local File Inclusion via file:// URI in Migration Restore

CVE-2026-58417
NONE

REST API exposes organization membership of private organizations to public

CVE-2026-58314
NONE

Two SSRF findings in Gitea 1.26.2

CVE-2026-57894
NONE

Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

CVE-2026-57886
NONE

Cross-repository issue/comment attachment re-linking can expose private attachment content

CVE-2026-56750
NONE

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

CVE-2026-56654
NONE

Privilege Escalation via Access Token Scope Escalation in API

CVE-2026-56443
NONE

Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

CVE-2026-55987
NONE

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

CVE-2026-55986
NONE

Email Management API Bypasses ManageCredentials Feature Restrictions

CVE-2026-55984
NONE

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

CVE-2026-55982
NONE

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

CVE-2026-54481
NONE

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

CVE-2026-50105
NONE

RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

CVE-2026-42931
NONE

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

CVE-2026-24059
NONE

Gitea runner registration-token GET endpoint performs a write under a read-only token scope

CVE-2026-23603
NONE

Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

CVE-2026-13610
NONE

KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration

CVE-2026-13328
NONE

TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification

CVE-2026-13051
NONE

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template

CVE-2026-13048
NONE

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename

CVE-2026-12908
NONE

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

CVE-2022-4993
NONE

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template