| CVE-2026-25855 | 8.7 | 44.6 | openbullet | openbullet2 | CWE-78 | OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload |
| CVE-2026-25559 | 8.7 | 44.4 | openbullet | openbullet2 | CWE-22 | OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint |
| CVE-2026-52778 | 9.8 | 44.1 | YesWiki | yeswiki | CWE-94 | YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE)… |
| CVE-2026-43951 | 6.5 | 43.3 | Apache Software Foundation | Apache HTTP Server | CWE-125 | Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash |
| CVE-2026-41448 | 9.2 | 43.1 | AdguardTeam | AdGuardHome | CWE-22 | AdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie |
| CVE-2026-35058 | 6.9 | 43.0 | OpenVPN | OpenVPN | CWE-617 | Improper validation of packet length during tls-crypt-v2 key extraction in Op… |
| CVE-2026-42535 | 9.1 | 42.9 | Apache Software Foundation | Apache HTTP Server | CWE-668 | Apache HTTP Server: mod_dav_fs protected directory access |
| CVE-2023-54350 | 8.7 | 42.5 | webandprint | Augmented Reality | CWE-306 | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated |
| CVE-2026-36789 | 7.5 | 42.4 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered t… |
| CVE-2026-29170 | 6.1 | 42.0 | Apache Software Foundation | Apache HTTP Server | CWE-79 | Apache HTTP Server: mod_proxy_ftp XSS |
| CVE-2026-11492 | 2.1 | 41.2 | D-Link | DIR-823G | CWE-266 | D-Link DIR-823G vsftpd vsftpd.conf least privilege violation |
| CVE-2026-44631 | 9.8 | 40.8 | Apache Software Foundation | Apache HTTP Server | CWE-124 | Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow |
| CVE-2026-43973 | 8.7 | 39.3 | ninenines | gun | CWE-770 | gun HTTP/1.1 response buffer has no size limit allowing server-controlled mem… |
| CVE-2026-43974 | 8.7 | 39.3 | ninenines | gun | CWE-841 | gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allo… |
| CVE-2026-48913 | 7.3 | 39.2 | Apache Software Foundation | Apache HTTP Server | CWE-416 | Apache HTTP Server: mod_http2 memory corruption when file handles exhausted |
| CVE-2026-11553 | 7.4 | 39.1 | Tenda | HG7HG9 | CWE-119 | Tenda HG7HG9/HG10 formPPPEdit stack-based overflow |
| CVE-2026-11557 | 7.4 | 39.0 | Tenda | F451 | CWE-119 | Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow |
| CVE-2026-25856 | 8.7 | 38.8 | openbullet | openbullet2 | CWE-94 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface |
| CVE-2026-46490 | 8.7 | 38.5 | tngan | samlify | CWE-91 | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signe… |
| CVE-2026-11503 | 7.4 | 38.3 | Tenda | CX12L | CWE-119 | Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_sett… |
| CVE-2026-11504 | 7.4 | 38.3 | Tenda | CX12L | CWE-119 | Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi … |
| CVE-2026-11522 | 7.4 | 38.3 | Tenda | W20E | CWE-119 | Tenda W20E setPortMirror formSetPortMirror stack-based overflow |
| CVE-2026-11523 | 7.4 | 38.3 | Tenda | W20E | CWE-119 | Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow |
| CVE-2026-11524 | 7.4 | 38.3 | Tenda | W20E | CWE-119 | Tenda W20E Web Management modifyWifiFilterRules stack-based overflow |
| CVE-2026-11528 | 7.4 | 38.3 | Tenda | AC18 | CWE-119 | Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow |
| CVE-2026-46289 | 9.8 | 37.7 | Linux | Linux | CWE-401 | lib/scatterlist: fix length calculations in extract_kvec_to_sg |
| CVE-2026-49233 | 8.3 | 36.9 | NLnet Labs | Routinator | CWE-22 | Routinator cache path traversal using rogue rsync URIs |
| CVE-2026-11497 | 5.5 | 35.8 | D-Link | DCS-5615 | CWE-266 | D-Link DCS-5615 Boa Webserver boa.conf least privilege violation |
| CVE-2026-9669 | 8.2 | 35.4 | Python Software Foundation | CPython | CWE-121 | bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow |
| CVE-2026-36786 | 7.5 | 34.3 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to con… |
| CVE-2026-11555 | 2.9 | 33.4 | D-Link | DGS-1100-08PD | CWE-266 | D-Link DGS-1100-08PD Web boa.conf least privilege violation |
| CVE-2026-41723 | 8.0 | 32.7 | VMware | VCF operations | CWE-79 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple v… |
| CVE-2026-46304 | 7.5 | 31.7 | Linux | Linux | — | nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free |
| CVE-2026-46306 | 7.5 | 31.7 | Linux | Linux | — | flow_dissector: do not dissect PPPoE PFC frames |
| CVE-2026-11518 | 2.1 | 31.6 | SourceCodester | Inventory System | CWE-79 | SourceCodester Inventory System User Management users.php cross site scripting |
| CVE-2026-46486 | 5.3 | 30.4 | mvt-project | mvt | CWE-22 | Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identi… |
| CVE-2026-46484 | 8.1 | 30.1 | tale | headplane | CWE-22 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OI… |
| CVE-2026-40215 | 6.1 | 29.9 | OpenVPN | OpenVPN | CWE-125 | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1… |
| CVE-2026-11516 | 2.0 | 29.7 | UTT | HiPER 2610G | CWE-119 | UTT HiPER 2610G formNatStaticMap strcpy buffer overflow |
| CVE-2026-49235 | 8.7 | 29.4 | NLnet Labs | Routinator | CWE-755 | Routinator crashes on specifically crafted RRDP XML files |
| CVE-2026-47345 | 5.1 | 29.3 | TYPO3 | HTML Sanitizer | CWE-79 | TYPO3 HTML Sanitizer allows Cross-Site Scripting |
| CVE-2026-11662 | 8.8 | 28.6 | Google | Chrome | CWE-843 | Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-49232 | 8.7 | 26.7 | NLnet Labs | Routinator | CWE-755 | Routinator exits when accepting an incoming HTTP or RTR connection fails |
| CVE-2026-46478 | 7.7 | 26.7 | FlowiseAI | Flowise | CWE-915 | Flowise: DatasetRow create+update mass-assignment allows cross-workspace row … |
| CVE-2022-50953 | 6.9 | 26.7 | brooks24 | admin-word-count-column | CWE-22 | WordPress Plugin admin-word-count-column 2.2 Local File Read |
| CVE-2026-11393 | 8.8 | 26.5 | AWS | AgentCore CLI | CWE-94 | Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Ag… |
| CVE-2026-22164 | 7.5 | 26.3 | Imagination Technologies | Graphics DDK | CWE-122 | GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical |
| CVE-2026-11651 | 9.6 | 26.2 | Google | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a … |
| CVE-2026-46475 | 7.7 | 25.9 | FlowiseAI | Flowise | CWE-915 | Flowise: Assistant create+update mass-assignment allows cross-workspace assis… |
| CVE-2026-46476 | 7.7 | 25.9 | FlowiseAI | Flowise | CWE-915 | Flowise: CustomTemplate create+update mass-assignment allows cross-workspace … |
| CVE-2026-46477 | 7.7 | 25.9 | FlowiseAI | Flowise | CWE-915 | Flowise: Dataset create+update mass-assignment allows cross-workspace dataset… |
| CVE-2026-46479 | 7.7 | 25.9 | FlowiseAI | Flowise | CWE-915 | Flowise: Evaluation create+update mass-assignment allows cross-workspace eval… |
| CVE-2026-46480 | 7.7 | 25.9 | FlowiseAI | Flowise | CWE-915 | Flowise: Evaluator create+update mass-assignment allows cross-workspace evalu… |
| CVE-2026-46444 | 8.7 | 25.1 | FlowiseAI | Flowise | CWE-862 | Flowise: Vector Store No Permission Checks |
| CVE-2026-11530 | 5.5 | 25.1 | imvks786 | student_management_system | CWE-74 | imvks786 student_management_system Login index.ph sql injection |
| CVE-2026-11531 | 5.5 | 25.2 | imvks786 | student_management_system | CWE-74 | imvks786 student_management_system Administrator Login Endpoint admin_login.p… |
| CVE-2026-11649 | 8.8 | 23.6 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remot… |
| CVE-2026-11650 | 8.8 | 23.6 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remot… |
| CVE-2026-39908 | 7.1 | 23.6 | openbullet | openbullet2 | CWE-522 | OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source |
| CVE-2026-41724 | 5.4 | 23.5 | VMware | VCF operations | CWE-79 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple v… |
| CVE-2026-11683 | 8.8 | 22.7 | Google | Chrome | CWE-416 | Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed … |
| CVE-2026-11477 | 2.1 | 22.4 | hs-web | hsweb-framework | CWE-601 | hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect |
| CVE-2026-39910 | 9.3 | 22.2 | STACKIT | IaaS API | CWE-862 | STACKIT IaaS API Privilege Escalation via Service Account Attachment |
| CVE-2026-41722 | 5.4 | 22.2 | VMware | VCF operations | CWE-79 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple v… |
| CVE-2026-11470 | 2.1 | 22.1 | hs-web | hsweb-framework | CWE-22 | hs-web hsweb-framework File Upload FileUploadProperties.java denied path trav… |
| CVE-2026-44541 | 7.0 | 21.7 | ethyca | fides | CWE-79 | Fides: DOM-based XSS vulnerability in fides.js via fides_description override |
| CVE-2026-46656 | 8.8 | 21.4 | bludit | bludit | CWE-285 | Bludit CMS has improper authorization and mediation failure leading to persis… |
| CVE-2026-11482 | 5.5 | 21.0 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive5.php sql injection |
| CVE-2026-11490 | 5.5 | 21.0 | code-projects | Online Music Site | CWE-74 | code-projects Online Music Site Search.php sql injection |
| CVE-2026-11474 | 5.5 | 20.7 | Kushan2k | student-management-system | CWE-284 | Kushan2k student-management-system Registration Endpoint RegisterService.php … |
| CVE-2026-11552 | 5.5 | 20.5 | SourceCodester | Onlne Examination & Learning Management System | CWE-255 | SourceCodester Onlne Examination & Learning Management System import_users.ph… |
| CVE-2026-47344 | 2.1 | 20.1 | TYPO3 | HTML Sanitizer | CWE-79 | TYPO3 HTML Sanitizer allows Cross-Site Scripting |
| CVE-2026-11500 | 1.3 | 20.1 | n/a | Weaviate | CWE-285 | Weaviate Static API Key client.go validateConfig authorization |
| CVE-2026-46303 | 8.2 | 19.8 | Linux | Linux | CWE-401 | isofs: validate Rock Ridge CE continuation extent against volume size |
| CVE-2026-11515 | 5.5 | 19.4 | SourceCodester | Barangay Resident Profiling and Information Management System | CWE-255 | SourceCodester Barangay Resident Profiling and Information Management System … |
| CVE-2026-11639 | 7.5 | 19.4 | Google | Chrome | CWE-416 | Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103… |
| CVE-2026-11641 | 7.5 | 19.4 | Google | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.1… |
| CVE-2026-11483 | 5.5 | 19.3 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive4.php sql injection |
| CVE-2026-11484 | 5.5 | 19.3 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive3.php sql injection |
| CVE-2026-11485 | 5.5 | 19.3 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive2.php sql injection |
| CVE-2026-11486 | 5.5 | 19.3 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive1.php sql injection |
| CVE-2026-11488 | 5.5 | 19.3 | code-projects | Simple Flight Ticket Booking System | CWE-74 | code-projects Simple Flight Ticket Booking System POST Parameter checkUser.ph… |
| CVE-2026-11489 | 5.5 | 19.3 | code-projects | Online Music Site | CWE-74 | code-projects Online Music Site AdminDeleteAlbum.php sql injection |
| CVE-2026-46441 | 7.6 | 19.2 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace … |
| CVE-2026-11512 | 2.1 | 19.1 | itsourcecode | Hospital Management System | CWE-79 | itsourcecode Hospital Management System billing.php cross site scripting |
| CVE-2026-11521 | 2.1 | 19.0 | Mohammed-eid35 | bank-management-system-springboot | CWE-266 | Mohammed-eid35 bank-management-system-springboot Transaction Endpoint Transac… |
| CVE-2026-11643 | 8.1 | 19.0 | Google | Chrome | CWE-416 | Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a re… |
| CVE-2026-46657 | 7.1 | 18.8 | bludit | bludit | CWE-212 | Bludit's persistent authentication tokens not revoked upon account disablement |
| CVE-2026-46443 | 7.0 | 18.8 | FlowiseAI | Flowise | CWE-200 | Flowise: Credential Data Leak |
| CVE-2026-11629 | 8.8 | 18.7 | Google | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a re… |
| CVE-2026-11532 | 2.1 | 18.7 | imvks786 | student_management_system | CWE-266 | imvks786 student_management_system Student Record add.php access control |
| CVE-2026-11582 | 5.5 | 18.5 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System index.php sql injection |
| CVE-2026-42863 | 7.6 | 18.5 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace A… |
| CVE-2026-49234 | 8.2 | 18.1 | NLnet Labs | Routinator | CWE-20 | Routinator crashes on specifically crafted ASN strings in the API |
| CVE-2026-11632 | 7.5 | 17.9 | Google | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-11648 | 8.8 | 17.6 | Google | Chrome | CWE-416 | Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.… |
| CVE-2026-11471 | 5.5 | 17.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System index2.php sql injection |
| CVE-2026-11472 | 5.5 | 17.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System index1.php sql injection |
| CVE-2026-11501 | 5.5 | 17.7 | SourceCodester | Hospitals Patient Records Management System | CWE-74 | SourceCodester Hospitals Patient Records Management System Master.php save_pa… |
| CVE-2026-11637 | 8.8 | 17.6 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allow… |
| CVE-2026-11646 | 8.8 | 17.6 | Google | Chrome | CWE-416 | Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 al… |
| CVE-2026-11519 | 2.1 | 17.5 | SourceCodester | Inventory System | CWE-266 | SourceCodester Inventory System Account Creation users_handler.php improper a… |
| CVE-2026-11660 | 8.3 | 17.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in New Tab Page in Google Chrome p… |
| CVE-2026-11688 | 8.8 | 16.8 | Google | Chrome | CWE-94 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 … |
| CVE-2026-42861 | 7.6 | 16.6 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace R… |
| CVE-2026-11634 | 9.6 | 16.4 | Google | Chrome | CWE-416 | Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103… |
| CVE-2026-11638 | 9.6 | 16.4 | Google | Chrome | CWE-416 | Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-11654 | 9.6 | 16.4 | Google | Chrome | CWE-416 | Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.1… |
| CVE-2026-11659 | 9.6 | 16.4 | Google | Chrome | CWE-20 | Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allo… |
| CVE-2026-11630 | 8.8 | 16.4 | Google | Chrome | CWE-416 | Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed… |
| CVE-2026-11657 | 8.8 | 16.3 | Google | Chrome | CWE-416 | Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 al… |
| CVE-2026-11664 | 8.8 | 16.4 | Google | Chrome | CWE-416 | Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-46440 | 9.1 | 16.3 | FlowiseAI | Flowise | CWE-522 | Flowise: Basic Auth Credentials Exposed via API |
| CVE-2026-43966 | 6.3 | 16.1 | ninenines | cowlib | CWE-113 | HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_stri… |
| CVE-2026-11502 | 1.3 | 16.1 | n/a | JeecgBoot | CWE-601 | JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sen… |
| CVE-2026-11520 | 2.0 | 15.8 | SourceCodester | Inventory System | CWE-79 | SourceCodester Inventory System header.php cross site scripting |
| CVE-2026-11611 | 6.5 | 15.3 | Red Hat | Red Hat Directory Server 11 | CWE-400 | 389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race… |
| CVE-2026-11671 | 9.6 | 15.2 | Google | Chrome | CWE-416 | Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed… |
| CVE-2026-11673 | 8.8 | 15.2 | Google | Chrome | CWE-416 | Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 all… |
| CVE-2026-11674 | 8.8 | 15.2 | Google | Chrome | CWE-416 | Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed… |
| CVE-2026-11680 | 8.8 | 15.2 | Google | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 a… |
| CVE-2026-11652 | 8.3 | 15.1 | Google | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed… |
| CVE-2026-11655 | 8.3 | 15.1 | Google | Chrome | CWE-472 | Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 all… |
| CVE-2026-11661 | 8.3 | 15.1 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 a… |
| CVE-2026-46481 | 8.3 | 14.9 | open-metadata | OpenMetadata | CWE-201 | OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database p… |
| CVE-2026-11672 | 8.3 | 14.6 | Google | Chrome | CWE-787 | Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.1… |
| CVE-2026-48507 | 7.1 | 14.2 | grokability | snipe-it | CWE-863 | Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk ed… |
| CVE-2026-11633 | 8.8 | 13.9 | Google | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… |
| CVE-2026-11640 | 8.3 | 13.7 | Google | Chrome | CWE-472 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-11642 | 8.3 | 13.7 | Google | Chrome | CWE-416 | Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-11676 | 8.3 | 13.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Linux … |
| CVE-2026-25558 | 4.8 | 13.6 | QloApps | QloApps | CWE-79 | QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager |
| CVE-2026-11533 | 2.1 | 13.5 | imvks786 | student_management_system | CWE-266 | imvks786 student_management_system Student Deletion Endpoint see.php improper… |
| CVE-2026-11653 | 6.5 | 12.9 | Google | Chrome | CWE-20 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… |
| CVE-2026-11658 | 6.5 | 12.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… |
| CVE-2026-11670 | 8.8 | 12.8 | Google | Chrome | CWE-416 | Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remo… |
| CVE-2026-11493 | 1.3 | 12.8 | Tenda | AC15 | CWE-521 | Tenda AC15 Samba smb.conf weak password |
| CVE-2026-11491 | 1.9 | 12.7 | CodeAstro | Human Resource Management System | CWE-79 | CodeAstro Human Resource Management System Notice Board Management All_notice… |
| CVE-2026-11631 | 8.3 | 12.5 | Google | Chrome | CWE-416 | Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 al… |
| CVE-2026-11635 | 8.3 | 12.5 | Google | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… |
| CVE-2026-11647 | 8.3 | 12.5 | Google | Chrome | CWE-416 | Use after free in Printing in Google Chrome on Android prior to 149.0.7827.10… |
| CVE-2026-11663 | 8.3 | 12.5 | Google | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a rem… |
| CVE-2026-11636 | 7.5 | 12.5 | Google | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.10… |
| CVE-2026-46307 | 8.3 | 12.4 | Linux | Linux | CWE-125 | wifi: ath5k: do not access array OOB |
| CVE-2026-11689 | 8.1 | 12.0 | Google | Chrome | CWE-20 | Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.… |
| CVE-2026-11665 | 4.3 | 12.0 | Google | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.10… |
| CVE-2026-49141 | 5.1 | 11.8 | ArnasDon | wacrm | CWE-639 | WACRM Authorization Bypass via Automation Engine Endpoint |
| CVE-2026-11667 | 7.5 | 11.8 | Google | Chrome | CWE-125 | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed… |
| CVE-2026-11494 | 2.1 | 11.7 | TOTOLINK | AC1200 T8 | CWE-266 | TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation |
| CVE-2026-11690 | 7.5 | 11.6 | Google | Chrome | CWE-125 | Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.… |
| CVE-2026-11694 | 7.5 | 11.6 | Google | Chrome | CWE-416 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allo… |
| CVE-2026-11666 | 5.4 | 11.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Input in Google Chrome prior to… |
| CVE-2026-11669 | 5.3 | 11.4 | Google | Chrome | CWE-472 | Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.… |
| CVE-2026-11476 | 2.1 | 11.0 | Kushan2k | student-management-system | CWE-266 | Kushan2k student-management-system Profile Update Endpoint AdminController.ph… |
| CVE-2026-11558 | 2.1 | 10.9 | CodeAstro | Payroll System | CWE-74 | CodeAstro Payroll System home_salary.php sql injection |
| CVE-2026-49756 | 2.1 | 10.7 | wojtekmach | req | CWE-93 | Multipart form-data header injection in Req via unescaped name/filename/conte… |
| CVE-2026-3011 | 6.4 | 10.6 | wpzoom | Recipe Card Blocks Lite | CWE-79 | Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site… |
| CVE-2026-11554 | 2.1 | 10.5 | TOTOLINK | CP450 | CWE-266 | TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation |
| CVE-2026-11529 | 2.1 | 10.4 | designcomputer | mysql-mcp-server | CWE-74 | designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection |
| CVE-2026-11473 | 5.3 | 10.3 | jflyfox | jfinal_cms | CWE-74 | jflyfox jfinal_cms AdvicefeedbackController.java list sql injection |
| CVE-2026-11559 | 2.1 | 10.3 | CodeAstro | Payroll System | CWE-74 | CodeAstro Payroll System view_account.php sql injection |
| CVE-2026-11583 | 2.1 | 10.3 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System createClass.php sql injection |
| CVE-2026-11584 | 2.1 | 10.3 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System createClass.php edit sql injec… |
| CVE-2026-11697 | 9.6 | 10.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome prior to 14… |
| CVE-2026-11681 | 8.8 | 10.1 | Google | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 all… |
| CVE-2026-11687 | 8.8 | 10.1 | Google | Chrome | CWE-416 | Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowe… |
| CVE-2026-11698 | 8.8 | 10.1 | Google | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… |
| CVE-2026-11699 | 8.8 | 10.1 | Google | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… |
| CVE-2026-11644 | 7.5 | 10.0 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 all… |
| CVE-2026-11675 | 3.1 | 9.8 | Google | Chrome | CWE-20 | Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-11480 | 2.1 | 9.8 | Chengdu Everbrite Network Technology | BeikeShop | CWE-74 | Chengdu Everbrite Network Technology BeikeShop Admin Design Builder Endpoint … |
| CVE-2026-11495 | 2.1 | 9.8 | CodeAstro | Ingredients Stock Management System | CWE-74 | CodeAstro Ingredients Stock Management System add_stock.php sql injection |
| CVE-2026-11506 | 2.1 | 9.8 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System search_staff_for_deletion.php sql injection |
| CVE-2026-11507 | 2.1 | 9.8 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System delete_leave_type.php sql injection |
| CVE-2026-11508 | 2.1 | 9.8 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection |
| CVE-2026-11510 | 2.1 | 9.8 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System add_leave.php sql injection |
| CVE-2026-11513 | 2.1 | 9.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System adminaccount.php sql injection |
| CVE-2026-11514 | 2.1 | 9.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System addpatient.php sql injection |
| CVE-2026-11585 | 2.1 | 9.8 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System createClassArms.php sql injection |
| CVE-2026-11534 | 2.0 | 9.6 | imvks786 | student_management_system | CWE-79 | imvks786 student_management_system add.php cross site scripting |
| CVE-2026-11505 | 2.3 | 9.4 | GL.iNet | A1300 | CWE-320 | GL.iNet XE3000 glnassys hard-coded key |
| CVE-2026-10544 | 6.5 | 9.3 | Devolutions | Server | CWE-78 | Improper neutralization of special elements in the built-in PAM provider pass… |
| CVE-2026-42862 | 7.6 | 9.2 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resou… |
| CVE-2026-11696 | 5.3 | 9.0 | Google | Chrome | CWE-457 | Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.10… |
| CVE-2026-11668 | 4.3 | 9.0 | Google | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.… |
| CVE-2026-11682 | 8.3 | 8.8 | Google | Chrome | CWE-20 | Inappropriate implementation in Views in Google Chrome on Linux prior to 149.… |
| CVE-2026-11509 | 5.3 | 8.9 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System search_staff_for_updation.php sql injection |
| CVE-2026-11511 | 2.0 | 8.7 | Bolt | CMS | CWE-74 | Bolt CMS HTML Attribute TextType.php HTML injection |
| CVE-2026-7765 | 6.3 | 8.3 | Checkmk GmbH | Checkmk | CWE-863 | User Messages widget leaked issuer messages on shared dashboards |
| CVE-2021-47982 | 5.1 | 8.3 | maxfoundry | WP-Paginate | CWE-79 | WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset |
| CVE-2021-47983 | 5.1 | 8.3 | mra13 | Accept Stripe Payments | CWE-79 | WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code |
| CVE-2021-47984 | 5.1 | 8.3 | WP24 | WP24 Domain Check | CWE-79 | WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS |
| CVE-2020-37248 | 6.5 | 8.1 | OfflineIMAP | OfflineIMAP | CWE-348 | OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability pri… |
| CVE-2026-46275 | 7.8 | 8.1 | Linux | Linux | CWE-362 | Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths |
| CVE-2026-11693 | 8.1 | 8.0 | Google | Chrome | CWE-346 | Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.… |
| CVE-2023-54351 | 5.1 | 8.0 | Sonaar | Sonaar Music Plugin | CWE-79 | WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments |
| CVE-2026-48488 | 2.7 | 7.8 | thorsten | phpMyFAQ | CWE-328 | phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing |
| CVE-2026-11628 | 6.8 | 7.6 | Google | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a lo… |
| CVE-2026-11679 | 8.3 | 7.5 | Google | Chrome | CWE-416 | Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 … |
| CVE-2026-11692 | 8.3 | 7.5 | Google | Chrome | CWE-416 | Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allo… |
| CVE-2026-11700 | 8.3 | 7.5 | Google | Chrome | CWE-416 | Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a … |
| CVE-2026-11701 | 5.4 | 7.4 | Google | Chrome | CWE-20 | Inappropriate implementation in Guest View in Google Chrome prior to 149.0.78… |
| CVE-2026-44119 | 5.5 | 7.3 | Apache Software Foundation | Apache HTTP Server | CWE-269 | Apache HTTP Server: escalation of privilege through expressions in .htaccess … |
| CVE-2026-11678 | 5.3 | 7.3 | Google | Chrome | CWE-472 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a… |
| CVE-2026-11685 | 4.3 | 7.2 | Google | Chrome | CWE-20 | Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to… |
| CVE-2026-11695 | 4.3 | 7.2 | Google | Chrome | CWE-693 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… |
| CVE-2026-11684 | 3.1 | 6.6 | Google | Chrome | CWE-693 | Insufficient policy enforcement in Network in Google Chrome prior to 149.0.78… |
| CVE-2026-11686 | 3.1 | 6.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on macOS … |
| CVE-2026-11656 | 8.3 | 6.4 | Google | Chrome | CWE-416 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allo… |
| CVE-2026-11691 | 3.1 | 6.4 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in New Tab Page in Google Chrome p… |
| CVE-2026-43972 | 6.3 | 6.2 | ninenines | gun | CWE-346 | gun HTTP/2 PUSH_PROMISE authority not validated against connection origin all… |
| CVE-2026-11479 | 1.3 | 5.4 | yoanbernabeu | grepai | CWE-327 | yoanbernabeu grepai Qdrant Backend chunker.go weak hash |
| CVE-2026-10787 | 4.3 | 4.9 | Devolutions | Server | CWE-862 | Missing authorization in the deleted user groups API in Devolutions Server al… |
| CVE-2026-11677 | 8.3 | 4.2 | Google | Chrome | CWE-362 | Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a rem… |
| CVE-2026-10786 | 6.5 | 4.3 | Devolutions | Server | CWE-312 | Improper access control in the ticketing integration settings in Devolutions … |
| CVE-2026-46294 | 7.8 | 3.8 | Linux | Linux | CWE-787 | dm: fix a buffer overflow in ioctl processing |
| CVE-2026-8078 | 4.8 | 3.8 | Checkmk GmbH | Checkmk | CWE-79 | Fix stored XSS in global settings change log |
| CVE-2026-9549 | 4.8 | 3.8 | Checkmk GmbH | Checkmk | CWE-79 | Fix XSS in service discovery active check output |
| CVE-2026-8833 | 8.5 | 3.6 | Checkmk GmbH | Checkmk | CWE-79 | XSS in urls |
| CVE-2026-46288 | 8.4 | 3.5 | Linux | Linux | CWE-416 | of: unittest: fix use-after-free in of_unittest_changeset() |
| CVE-2026-46281 | 7.8 | 3.6 | Linux | Linux | CWE-787 | vmalloc: fix buffer overflow in vrealloc_node_align() |
| CVE-2026-46274 | 7.8 | 3.4 | Linux | Linux | CWE-416 | io-wq: check that the predecessor is hashed in io_wq_remove_pending() |
| CVE-2026-11569 | 5.4 | 3.4 | Red Hat | Red Hat Quay 3 | CWE-79 | Quay: quay: stored xss via filedrop svg upload |
| CVE-2026-7186 | 8.5 | 3.3 | Checkmk GmbH | Checkmk | CWE-79 | Fix stored XSS in URL dashboard widget via dangerous URI schemes |
| CVE-2026-11475 | 2.1 | 3.1 | Kushan2k | student-management-system | CWE-74 | Kushan2k student-management-system Certificate Verification Endpoint GradeCon… |
| CVE-2026-46279 | 7.8 | 2.6 | Linux | Linux | CWE-415 | mm/alloc_tag: clear codetag for pages allocated before page_ext initialization |
| CVE-2026-46280 | 7.8 | 2.5 | Linux | Linux | CWE-416 | lib: test_hmm: evict device pages on file close to avoid use-after-free |
| CVE-2026-46285 | 7.8 | 2.5 | Linux | Linux | CWE-416 | mtd: docg3: fix use-after-free in docg3_release() |
| CVE-2026-46293 | 7.1 | 2.5 | Linux | Linux | CWE-125 | clk: microchip: mpfs-ccc: fix out of bounds access during output registration |
| CVE-2026-46309 | 7.0 | 2.4 | Linux | Linux | CWE-401 | drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise |
| CVE-2026-46276 | 5.5 | 2.3 | Linux | Linux | — | drm/amdgpu: fix zero-size GDS range init on RDNA4 |
| CVE-2026-46291 | 5.5 | 2.3 | Linux | Linux | — | crypto: caam - guard HMAC key hex dumps in hash_digest_key |
| CVE-2026-46292 | 5.5 | 2.3 | Linux | Linux | CWE-772 | pmdomain: core: Fix detach procedure for virtual devices in genpd |
| CVE-2026-46282 | 5.5 | 2.2 | Linux | Linux | CWE-476 | iio: frequency: admv1013: fix NULL pointer dereference on str |
| CVE-2026-46283 | 5.5 | 2.2 | Linux | Linux | — | tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() |
| CVE-2026-46286 | 5.5 | 2.2 | Linux | Linux | — | leds: qcom-lpg: Check for array overflow when selecting the high resolution |
| CVE-2026-46287 | 5.5 | 2.2 | Linux | Linux | CWE-617 | net: txgbe: fix RTNL assertion warning when remove module |
| CVE-2026-46284 | 5.5 | 2.1 | Linux | Linux | CWE-476 | mm/hugetlb: fix early boot crash on parameters without '=' separator |
| CVE-2026-46290 | 5.5 | 2.1 | Linux | Linux | — | x86/efi: Fix graceful fault handling after FPU softirq changes |
| CVE-2026-46277 | 7.8 | 2.1 | Linux | Linux | — | mm/zone_device: do not touch device folio after calling ->folio_free() |
| CVE-2026-46301 | 7.8 | 1.8 | Linux | Linux | CWE-416 | spi: topcliff-pch: fix use-after-free on unbind |
| CVE-2026-34194 | 7.1 | 1.8 | Imagination Technologies | Graphics DDK | CWE-468 | GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChang… |
| CVE-2026-46308 | 7.8 | 1.7 | Linux | Linux | CWE-416 | pmdomain: mediatek: fix use-after-free in scpsys_get_bus_protection_legacy() |
| CVE-2026-46314 | 5.5 | 1.7 | Linux | Linux | CWE-835 | drm/v3d: Reject empty multisync extension to prevent infinite loop |
| CVE-2026-46296 | 5.5 | 1.7 | Linux | Linux | CWE-476 | spi: s3c64xx: fix NULL-deref on driver unbind |
| CVE-2026-46312 | 5.5 | 1.6 | Linux | Linux | — | media: videobuf2: Set vma_flags in vb2_dma_sg_mmap |
| CVE-2026-46313 | 5.5 | 1.6 | Linux | Linux | CWE-476 | media: intel/ipu6: fix error pointer dereference |
| CVE-2026-11478 | 1.9 | 1.6 | kokke | tiny-regex-c | CWE-400 | kokke tiny-regex-c Pattern re.c matchstar redos |
| CVE-2026-46311 | 7.8 | 1.5 | Linux | Linux | — | drm/amdgpu/userq: fix access to stale wptr mapping |
| CVE-2025-71315 | 5.5 | 1.5 | Linux | Linux | — | drm/vkms: Convert to DRM's vblank timer |
| CVE-2026-46295 | 5.5 | 1.5 | Linux | Linux | — | KVM: x86: Do IRR scan in __kvm_apic_update_irr even if PIR is empty |
| CVE-2026-46297 | 5.5 | 1.5 | Linux | Linux | — | net: libwx: use request_irq for VF misc interrupt |
| CVE-2026-46310 | 5.5 | 1.5 | Linux | Linux | CWE-476 | media: renesas: vsp1: Fix NULL pointer deref on module unload |
| CVE-2026-46278 | 5.5 | 1.3 | Linux | Linux | CWE-476 | drm/imagination: Fix segfault when updating ftrace mask |
| CVE-2026-45581 | 5.5 | 1.2 | hyperledger | fabric-chaincode-java | CWE-532 | fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Log… |
| CVE-2026-46302 | 5.5 | 0.9 | Linux | Linux | — | selinux: allow multiple opens of /sys/fs/selinux/policy |
| CVE-2026-46305 | 5.5 | 0.9 | Linux | Linux | CWE-476 | staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc |
| CVE-2026-46299 | 7.0 | 0.5 | Linux | Linux | CWE-667 | hfsplus: fix held lock freed on hfsplus_fill_super() |
| CVE-2026-11481 | 1.1 | 0.3 | yoanbernabeu | grepai | CWE-327 | yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupB… |
| CVE-2026-46298 | 4.7 | 0.1 | Linux | Linux | CWE-362 | pseries/papr-hvpipe: Fix race with interrupt handler |