| CVE-2026-48449 | 9.8 | 43.2 | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-18245 | 6.4 | 42.8 | AWS | Amplify Codegen UI | CWE-94 | Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codege… |
| CVE-2026-68502 | 9.8 | 42.4 | grisuno | LazyOwn | CWE-306 | LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Disp… |
| CVE-2026-12940 | 9.8 | 42.3 | IBM | Langflow OSS | CWE-78 | Langflow is affected by remote code execution due to multiple unauthenticated… |
| CVE-2026-14602 | 9.0 | 42.3 | Unknown | Remote API | CWE-94 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query… |
| CVE-2026-59952 | 6.9 | 42.3 | open-circle | valibot | CWE-755 | Valibot: record() issue paths can make flatten() throw for inherited Object p… |
| CVE-2026-17544 | 8.1 | 42.1 | PHP Group | PHP | CWE-787 | Out-of-bounds write in bccomp() via crafted operand and scale |
| CVE-2026-58216 | 5.3 | 41.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might ca… |
| CVE-2026-12118 | 9.8 | 40.7 | IBM | webMethods Integration (on prem) | CWE-502 | IBM webMethods Integration could allow an unauthenticated remote attacker to … |
| CVE-2026-16527 | 7.3 | 40.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-306 | Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing … |
| CVE-2026-66803 | 10.0 | 39.8 | Microsoft | Azure Cosmos DB | CWE-284 | Azure Cosmos DB Remote Code Execution Vulnerability |
| CVE-2026-28811 | 7.5 | 39.4 | Apache Software Foundation | Apache JSPWiki | CWE-1295 | Apache JSPWiki: Error Handling - Reveals Error Details |
| CVE-2026-17543 | 8.1 | 38.8 | PHP Group | PHP | CWE-89 | SQL injection in ext-pgsql via E'...' backslash breakout |
| CVE-2026-44108 | 9.3 | 38.4 | Phoenix Contact | CHARX SEC-3150 | CWE-696 | Firewall bypass during shutdown |
| CVE-2026-12996 | 6.0 | 38.3 | OpenVPN | OpenVPN | CWE-125 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4… |
| CVE-2026-67594 | 9.3 | 37.9 | yolanmees | Spikster | CWE-306 | Spikster Missing Authentication via API Route Group |
| CVE-2026-16526 | 8.8 | 37.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-403 | Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability |
| CVE-2026-44616 | 6.5 | 37.5 | Apache Software Foundation | Apache Zeppelin | CWE-90 | Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction |
| CVE-2026-66756 | 6.9 | 37.2 | Apache Software Foundation | Apache Tika | CWE-424 | Apache Tika: unpack endpoint in tika-server allows configuration with unsecur… |
| CVE-2026-66755 | 5.9 | 37.0 | Apache Software Foundation | Apache Tika | CWE-22 | Apache Tika: Arbitrary Local File Read in ISArchiveParser |
| CVE-2026-17658 | 8.8 | 37.0 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… |
| CVE-2026-17661 | 8.8 | 37.0 | Google | Chrome | CWE-416 | Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a re… |
| CVE-2026-17665 | 8.8 | 37.0 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… |
| CVE-2026-17685 | 8.8 | 37.0 | Google | Chrome | CWE-416 | Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-17694 | 8.8 | 37.0 | Google | Chrome | CWE-416 | Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remot… |
| CVE-2026-17705 | 8.8 | 37.0 | Google | Chrome | CWE-190 | Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-67206 | 8.7 | 36.6 | wolfcms | wolfcms | CWE-434 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload |
| CVE-2026-18140 | 8.7 | 36.5 | AWS | aws-smithy-json | CWE-674 | Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows un… |
| CVE-2026-63559 | 8.7 | 36.3 | o6 Automation | open62541 | CWE-190 | o6 Automation open62541 Integer Overflow or Wraparound |
| CVE-2026-17664 | 6.5 | 36.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Loader in Google Chrome prior t… |
| CVE-2026-17681 | 9.6 | 35.3 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Web Authentication in Google Ch… |
| CVE-2026-7849 | 9.3 | 35.2 | Phoenix Contact | CHARX SEC-3150 | CWE-77 | Command Injection in SCM (idledisconnect parameter) |
| CVE-2026-17881 | 8.8 | 35.0 | Google | Chrome | CWE-416 | Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a r… |
| CVE-2026-12932 | 7.1 | 34.9 | OpenVPN | OpenVPN | CWE-401 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 thro… |
| CVE-2026-12942 | 7.5 | 34.8 | IBM | Langflow OSS | CWE-22 | Langflow is affected by path traversal due to multiple unauthenticated and in… |
| CVE-2026-53431 | 9.1 | 34.6 | malach-it | boruta | CWE-294 | Boruta accepts expired JWT client assertions due to missing exp claim validation |
| CVE-2026-17725 | 8.8 | 34.6 | Google | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… |
| CVE-2026-23985 | 5.3 | 34.6 | Apache Software Foundation | Apache Superset | CWE-1333 | Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser |
| CVE-2026-28814 | 7.5 | 34.4 | Apache Software Foundation | Apache JSPWiki | CWE-306 | Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering |
| CVE-2026-15971 | 9.8 | 33.8 | SGLang | SGLang | CWE-95 | CVE-2026-15971 |
| CVE-2026-28812 | 9.8 | 33.7 | Apache Software Foundation | Apache JSPWiki | CWE-290 | Apache JSPWiki: UserManager does not sanity-check user database at startup |
| CVE-2026-17687 | 9.6 | 33.7 | Google | Chrome | CWE-843 | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17697 | 9.6 | 33.7 | Google | Chrome | CWE-843 | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-44090 | 9.3 | 33.5 | Phoenix Contact | CHARX SEC-3150 | CWE-306 | Missing authentication for MQTT Broker |
| CVE-2026-44101 | 9.3 | 33.5 | Phoenix Contact | CHARX SEC-3150 | CWE-306 | OCPP reconfiguration vulnerability |
| CVE-2026-17680 | 9.6 | 33.4 | Google | Chrome | CWE-122 | Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.792… |
| CVE-2026-17922 | 8.8 | 33.3 | Google | Chrome | CWE-94 | Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.79… |
| CVE-2026-57859 | 7.7 | 33.2 | e107inc | e107 | CWE-502 | e107 Second-Order Code Execution via eval()-Based Deserialization in e_array:… |
| CVE-2026-13117 | 6.0 | 33.1 | OpenVPN | OpenVPN | CWE-416 | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.… |
| CVE-2026-17651 | 9.6 | 33.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Androi… |
| CVE-2026-17652 | 9.6 | 33.0 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17655 | 9.6 | 33.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-17656 | 9.6 | 33.0 | Google | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-68503 | 9.8 | 32.9 | grisuno | LazyOwn | CWE-1392 | LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 D… |
| CVE-2026-12947 | 7.5 | 32.8 | IBM | App Connect Enterprise | CWE-532 | IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Dis… |
| CVE-2026-54363 | 9.3 | 32.7 | Gladinet | CentreStack | CWE-321 | CentreStack < 17.5 Hardcoded Key Token Forgery RCE |
| CVE-2026-54368 | 8.7 | 32.5 | Gladinet | CentreStack | CWE-89 | CentreStack < 17.4 SQL Injection via x-glad-filter Header |
| CVE-2026-10700 | 6.5 | 32.4 | IBM | Langflow OSS | CWE-639 | Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling… |
| CVE-2026-60074 | 7.5 | 32.1 | SBECK | Date::Manip | CWE-1289 | Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASC… |
| CVE-2026-60075 | 7.5 | 32.1 | SBECK | Date::Manip | CWE-1333 | Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic… |
| CVE-2026-44613 | 6.1 | 32.0 | Apache Software Foundation | Apache Zeppelin | CWE-352 | Apache Zeppelin: Cross-site request forgery in REST and WebSocket request han… |
| CVE-2026-68500 | 7.5 | 31.5 | Sylius | MolliePlugin | CWE-639 | Sylius Mollie Plugin: Payment status forgery via the payment webhook |
| CVE-2026-41709 | 2.7 | 31.5 | VMware | Cloud Foundation | CWE-778 | ESX insufficient logging vulnerability |
| CVE-2026-17667 | 6.5 | 31.4 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-17668 | 6.5 | 31.4 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-17707 | 6.5 | 31.4 | Google | Chrome | CWE-457 | Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72… |
| CVE-2026-17714 | 6.5 | 31.4 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-44092 | 8.8 | 31.3 | Phoenix Contact | CHARX SEC-3150 | CWE-93 | Missing input validation / stripping of CRLF characters in SystemConfigManager |
| CVE-2026-17719 | 8.8 | 31.2 | Google | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-11771 | 7.0 | 30.7 | OpenVPN | OpenVPN | CWE-121 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows atta… |
| CVE-2026-54885 | 6.9 | 30.5 | malach-it | boruta | CWE-918 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri f… |
| CVE-2026-67351 | 8.7 | 30.3 | s9y | Serendipity | CWE-304 | Serendipity < 2.6.1 Authentication Bypass via Username Collision |
| CVE-2026-48448 | 8.6 | 30.2 | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-17669 | 9.6 | 30.2 | Google | Chrome | CWE-693 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-17670 | 9.6 | 30.2 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17671 | 9.6 | 30.2 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-17672 | 9.6 | 30.2 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromecast in Google Chrome pri… |
| CVE-2026-17673 | 9.6 | 30.2 | Google | Chrome | CWE-190 | Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a re… |
| CVE-2026-17676 | 9.6 | 30.2 | Google | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15… |
| CVE-2026-17682 | 9.6 | 30.2 | Google | Chrome | CWE-190 | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r… |
| CVE-2026-17684 | 9.6 | 30.2 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… |
| CVE-2026-17688 | 9.6 | 30.2 | Google | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17691 | 9.6 | 30.2 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.… |
| CVE-2026-17692 | 9.6 | 30.2 | Google | Chrome | CWE-416 | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.792… |
| CVE-2026-17695 | 9.6 | 30.2 | Google | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.… |
| CVE-2026-17704 | 9.6 | 30.2 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17708 | 9.6 | 30.2 | Google | Chrome | CWE-416 | Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17710 | 9.6 | 30.2 | Google | Chrome | CWE-693 | Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.… |
| CVE-2026-17713 | 9.6 | 30.2 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Accessibility in Google Chrome … |
| CVE-2026-17717 | 9.6 | 30.2 | Google | Chrome | CWE-190 | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r… |
| CVE-2026-17677 | 8.8 | 30.2 | Google | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15… |
| CVE-2026-17678 | 8.8 | 30.2 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a… |
| CVE-2026-35847 | 9.8 | 29.9 | n/a | n/a | CWE-77 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbit… |
| CVE-2026-6540 | 7.9 | 29.9 | Tigera | Calico | CWE-22 | L7 policy bypass via unnormalized HTTP path matching |
| CVE-2026-16529 | 7.5 | 29.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Pcp: pcp: denial of service due to signed integer overflow |
| CVE-2026-17751 | 8.8 | 29.7 | Google | Chrome | CWE-269 | Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922… |
| CVE-2026-23981 | 5.3 | 29.6 | Apache Software Foundation | Apache Superset | CWE-285 | Apache Superset: Improper Authorization in Chart Update allowing Dashboard Mo… |
| CVE-2026-66421 | 8.8 | 29.5 | tugcantopaloglu | openclaw-dashboard | CWE-79 | OpenClaw Dashboard Stored XSS via lastMessage Session Field |
| CVE-2026-22620 | 8.6 | 29.5 | Eaton | PADM | CWE-89 | Improper input validation in the authentication component of Eaton's Tripp Li… |
| CVE-2026-17896 | 7.5 | 29.5 | Google | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-18362 | 5.9 | 29.0 | dfir-iris | iris-web | CWE-770 | DFIR-IRIS Missing Brute Force Protection in User Authentication |
| CVE-2026-16531 | 5.3 | 29.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-22 | Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet |
| CVE-2026-17701 | 9.6 | 28.5 | Google | Chrome | CWE-125 | Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac p… |
| CVE-2026-17712 | 8.8 | 28.5 | Google | Chrome | CWE-362 | Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote … |
| CVE-2026-17686 | 8.1 | 28.4 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Passwords in Google Chrome prio… |
| CVE-2026-12946 | 9.9 | 28.3 | IBM | Langflow OSS | CWE-94 | Remote Code Execution in CUGA Component CodeAgent |
| CVE-2026-17778 | 8.8 | 28.1 | Google | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed … |
| CVE-2026-17679 | 6.5 | 28.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Print Preview in Google Chrome … |
| CVE-2026-17683 | 6.5 | 28.1 | Google | Chrome | CWE-200 | Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72… |
| CVE-2026-17650 | 8.3 | 28.1 | Google | Chrome | CWE-416 | Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed… |
| CVE-2026-17653 | 8.3 | 28.1 | Google | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remo… |
| CVE-2026-48910 | 6.5 | 28.0 | Apache Software Foundation | Apache JSPWiki | CWE-80 | Apache JSPWiki: Markdown parser allows XSS injection in Markdown error proces… |
| CVE-2026-17660 | 8.3 | 27.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … |
| CVE-2026-17663 | 8.3 | 27.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in GPU in Google Chrome on Android… |
| CVE-2026-11536 | 8.5 | 27.6 | IBM | WebSphere Application Server | CWE-502 | IBM WebSphere Application Server is affected by a remote code execution vulne… |
| CVE-2026-58046 | 9.9 | 27.5 | WebPros | Plesk | CWE-89 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticate… |
| CVE-2026-41186 | 6.0 | 27.5 | Tigera | Calico | CWE-200 | Unauthenticated Go pprof exposure in Calico debug server |
| CVE-2026-17758 | 9.6 | 27.3 | Google | Chrome | CWE-122 | Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed … |
| CVE-2026-68501 | 6.5 | 27.2 | Sylius | MolliePlugin | CWE-639 | Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII |
| CVE-2026-17729 | 8.8 | 27.1 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… |
| CVE-2026-17935 | 8.8 | 26.9 | Google | Chrome | CWE-122 | Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowe… |
| CVE-2026-13395 | 8.6 | 26.9 | Unknown | Online Scheduling and Appointment Booking System | CWE-89 | Bookly < 27.8 - Unauthenticated SQL Injection via staff_id |
| CVE-2026-18064 | 8.2 | 27.0 | NASA | Core Flight System (cFS) Health & Safety (HS) Application | CWE-476 | NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer D… |
| CVE-2026-66418 | 9.3 | 26.8 | tugcantopaloglu | openclaw-dashboard | CWE-79 | OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field |
| CVE-2026-13379 | 5.1 | 26.9 | OpenVPN | OpenVPN | CWE-125 | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows re… |
| CVE-2026-62663 | 7.5 | 26.6 | masci | banks | CWE-22 | Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/v… |
| CVE-2026-15976 | 9.8 | 26.2 | SGLang | SGLang | CWE-502 | CVE-2026-15976 |
| CVE-2026-17868 | 8.8 | 26.2 | Google | Chrome | CWE-269 | Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.7… |
| CVE-2026-54722 | 8.7 | 25.8 | HackingRepo | dssrf-js | CWE-76 | dssrf: there a critical security bug with remove_at_symbol_in_string |
| CVE-2026-44091 | 8.8 | 25.7 | Phoenix Contact | CHARX SEC-3150 | CWE-501 | Creation of a new configuration by posting a malicious ID to MQTT |
| CVE-2026-17759 | 6.5 | 25.6 | Google | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a… |
| CVE-2026-17657 | 8.3 | 25.4 | Google | Chrome | CWE-416 | Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed … |
| CVE-2025-65336 | 9.8 | 25.0 | n/a | n/a | CWE-89 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL I… |
| CVE-2026-17674 | 6.5 | 24.7 | Google | Chrome | CWE-693 | Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 … |
| CVE-2026-17703 | 6.5 | 24.7 | Google | Chrome | CWE-602 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… |
| CVE-2026-16971 | 5.9 | 24.7 | dfir-iris | iris-web | CWE-770 | DFIR-IRIS Missing Brute Force Protection in OTP Validation |
| CVE-2026-17989 | 8.8 | 24.5 | Google | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… |
| CVE-2026-14318 | 6.8 | 24.5 | Unknown | GiveWP | CWE-79 | GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings |
| CVE-2026-17675 | 9.6 | 24.4 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed … |
| CVE-2026-17718 | 9.6 | 24.4 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17721 | 9.6 | 24.4 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed … |
| CVE-2026-17726 | 9.6 | 24.4 | Google | Chrome | CWE-190 | Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 … |
| CVE-2026-17727 | 9.6 | 24.4 | Google | Chrome | CWE-787 | Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.… |
| CVE-2026-17738 | 9.6 | 24.4 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Payments in Google Chrome prior… |
| CVE-2026-17768 | 9.6 | 24.4 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in WebSockets in Google Chrome pri… |
| CVE-2026-17801 | 9.6 | 24.4 | Google | Chrome | CWE-125 | Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72… |
| CVE-2026-17804 | 9.6 | 24.4 | Google | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17752 | 8.8 | 24.4 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowe… |
| CVE-2026-17784 | 8.8 | 24.4 | Google | Chrome | CWE-416 | Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowe… |
| CVE-2026-17967 | 8.8 | 24.4 | Google | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.… |
| CVE-2026-15397 | 7.2 | 24.2 | wpswings | Subscriptions for WooCommerce | CWE-862 | Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticat… |
| CVE-2026-12733 | 7.5 | 24.1 | IBM | DataPower Gateway 10.6CD | CWE-770 | IBM DataPower Gateway affected by denial of service |
| CVE-2026-67345 | 8.5 | 23.8 | dromara | MaxKey | CWE-183 | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft |
| CVE-2026-10842 | 7.5 | 23.8 | IBM | WebSphere Application Server | CWE-289 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-17689 | 4.3 | 23.8 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-44107 | 8.7 | 23.7 | Phoenix Contact | CHARX SEC-3150 | CWE-749 | Exposed Reboot via Modbus |
| CVE-2026-67246 | 6.9 | 23.4 | ASUSTOR Inc. | ADM | CWE-22 | A path traversal vulnerability was found in the Wallpaper component of ADM |
| CVE-2026-17875 | 8.8 | 23.2 | Google | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a re… |
| CVE-2026-22622 | 8.8 | 23.2 | Eaton | PADM | CWE-78 | Improper input validation in one of the session management interface of Eaton… |
| CVE-2026-9322 | 7.5 | 23.2 | IBM | WebSphere Application Server | CWE-400 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-11897 | 7.5 | 23.1 | IBM | WebSphere Application Server - Liberty | CWE-770 | IBM WebSphere Application Server Liberty is affected by a denial of service v… |
| CVE-2026-17887 | 7.5 | 23.1 | Google | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-52539 | 9.1 | 23.0 | n/a | n/a | CWE-798 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_… |
| CVE-2026-17807 | 8.8 | 22.9 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… |
| CVE-2026-17836 | 8.8 | 22.9 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… |
| CVE-2026-17918 | 8.8 | 22.9 | Google | Chrome | CWE-416 | Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remo… |
| CVE-2026-17698 | 7.5 | 22.8 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome on Android … |
| CVE-2026-67247 | 7.1 | 22.9 | ASUSTOR Inc. | ADM | CWE-22 | A path traversal vulnerability was found in the IHM Log handling of ADM |
| CVE-2026-59881 | 6.9 | 22.8 | aio-libs | aiohttp | CWE-20 | AIOHTTP: WebSocket client accepts compressed frames without negotiated permes… |
| CVE-2026-65635 | 8.3 | 22.8 | malach-it | boruta | CWE-653 | Boruta dynamic client registration allows creation of over-privileged OAuth c… |
| CVE-2026-67207 | 8.7 | 22.6 | wolfcms | wolfcms | CWE-697 | Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController |
| CVE-2026-61536 | 7.5 | 22.6 | masci | banks | CWE-94 | Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path… |
| CVE-2026-16530 | 6.5 | 22.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Pcp: pcp: remote denial of service and information leakage |
| CVE-2026-17796 | 6.5 | 22.6 | Google | Chrome | CWE-1300 | Side-channel information leakage in WebXR in Google Chrome prior to 151.0.792… |
| CVE-2026-17800 | 6.5 | 22.6 | Google | Chrome | CWE-1300 | Inappropriate implementation in MediaRecording in Google Chrome prior to 151.… |
| CVE-2026-18363 | 9.1 | 22.5 | Enhancesoft LLC | osTicket | CWE-640 | Weak password recovery mechanism in osTicket by Enhancesoft LLC |
| CVE-2026-15153 | 6.8 | 22.4 | Unknown | WP Hotel Booking | CWE-89 | WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search |
| CVE-2026-12687 | 7.5 | 22.2 | Unknown | ProfileGrid | CWE-269 | ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted… |
| CVE-2026-17709 | 9.6 | 22.1 | Google | Chrome | CWE-362 | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re… |
| CVE-2026-17711 | 9.6 | 22.1 | Google | Chrome | CWE-362 | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re… |
| CVE-2026-13435 | 9.9 | 22.1 | IBM | Langflow OSS | CWE-94 | Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure |
| CVE-2026-15978 | 7.5 | 22.0 | SGLang | SGLang | CWE-306 | CVE-2026-15978 |
| CVE-2026-57862 | 8.4 | 21.9 | Kanboard | Kanboard | CWE-918 | Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation |
| CVE-2026-11904 | 5.3 | 21.9 | IBM | Verify Identity Access | CWE-209 | Security vulnerabilities have been found in IBM Verify Identity Access and IB… |
| CVE-2026-17803 | 9.6 | 21.8 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Save to Drive in Google Chrome … |
| CVE-2026-17956 | 8.8 | 21.7 | Google | Chrome | CWE-269 | Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.79… |
| CVE-2026-17969 | 8.8 | 21.7 | Google | Chrome | CWE-269 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.792… |
| CVE-2026-17735 | 8.7 | 21.7 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in BFCache in Google Chrome prior … |
| CVE-2026-67346 | 7.7 | 21.6 | kyegomez | swarms | CWE-918 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass |
| CVE-2026-54366 | 8.7 | 21.2 | Gladinet | CentreStack | CWE-611 | CentreStack < 17.4 XXE via SharePoint Storage Configuration |
| CVE-2026-67349 | 8.7 | 21.1 | opencost | opencost | CWE-306 | OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass |
| CVE-2026-17696 | 4.3 | 21.0 | Google | Chrome | CWE-1300 | Side-channel information leakage in Media in Google Chrome prior to 151.0.792… |
| CVE-2026-17700 | 4.3 | 21.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Actor in Google Chrome prior to… |
| CVE-2026-17706 | 4.3 | 21.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Windo… |
| CVE-2026-66415 | 8.4 | 21.0 | Leantime | Leantime | CWE-918 | Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::… |
| CVE-2026-56428 | 8.1 | 21.0 | Bosch | BSH ELP (Electronic Platform) Modules | CWE-286 | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-… |
| CVE-2026-47876 | 9.3 | 20.7 | VMware | Cloud Foundation | CWE-787 | VMXNET3 out-of-bounds write vulnerability |
| CVE-2026-17951 | 8.8 | 20.4 | Google | Chrome | CWE-122 | Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowe… |
| CVE-2026-55768 | 8.7 | 20.4 | allinurl | goaccess | CWE-681 | GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame lengt… |
| CVE-2026-12562 | 8.7 | 20.4 | Toptech Systems | RCU II+ | CWE-306 | Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical… |
| CVE-2026-66360 | 8.7 | 20.4 | MZ Automation GmbH | libiec61850 | CWE-125 | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-67244 | 8.6 | 20.3 | ASUSTOR Inc. | ADM | CWE-134 | A format string vulnerability was found in the Notification OAuth settings of… |
| CVE-2026-17722 | 8.3 | 20.4 | Google | Chrome | CWE-416 | Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.… |
| CVE-2026-17723 | 8.3 | 20.4 | Google | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 al… |
| CVE-2026-44100 | 8.8 | 20.2 | Phoenix Contact | CHARX SEC-3150 | CWE-306 | JupiCore charging point reconfiguration without auth |
| CVE-2026-67248 | 8.7 | 20.2 | ASUSTOR Inc. | ADM | CWE-121 | A stack-based buffer overflow vulnerability was found in the File Explorer on… |
| CVE-2026-67347 | 6.1 | 20.2 | vendurehq | vendure | CWE-863 | Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset … |
| CVE-2026-17847 | 9.6 | 20.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-17856 | 9.6 | 20.0 | Google | Chrome | CWE-693 | Inappropriate implementation in Network in Google Chrome on Mac prior to 151.… |
| CVE-2026-17865 | 9.6 | 20.0 | Google | Chrome | CWE-693 | Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0… |
| CVE-2026-17884 | 8.8 | 20.0 | Google | Chrome | CWE-416 | Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allo… |
| CVE-2026-17886 | 8.8 | 20.0 | Google | Chrome | CWE-416 | Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed … |
| CVE-2026-17894 | 8.8 | 20.0 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allo… |
| CVE-2026-17690 | 6.5 | 19.7 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in PDF in Google Chrome on Android… |
| CVE-2026-17756 | 6.5 | 19.7 | Google | Chrome | CWE-602 | Insufficient policy enforcement in Presentation in Google Chrome prior to 151… |
| CVE-2026-17764 | 6.5 | 19.7 | Google | Chrome | CWE-693 | Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72… |
| CVE-2026-17814 | 6.5 | 19.7 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… |
| CVE-2026-58040 | 6.3 | 19.6 | nodejs | node | CWE-297 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reu… |
| CVE-2026-17971 | 8.8 | 19.4 | Google | Chrome | CWE-125 | Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72… |
| CVE-2026-17946 | 6.5 | 19.2 | Google | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r… |
| CVE-2026-17968 | 6.5 | 19.2 | Google | Chrome | CWE-457 | Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72… |
| CVE-2026-14356 | 8.8 | 19.2 | fleekdash | FleekDash V2 | CWE-862 | FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+… |
| CVE-2026-17950 | 8.8 | 19.2 | Google | Chrome | CWE-269 | Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to… |
| CVE-2026-62246 | 8.5 | 19.2 | clastix | kamaji | CWE-284 | Kamaji: TenantControlPlane namespace/name collision binds two tenants to the … |
| CVE-2026-18360 | 7.6 | 19.0 | dfir-iris | iris-web | CWE-79 | DFIR-IRIS Stored XSS in Custom Attributes |
| CVE-2026-18361 | 7.6 | 19.0 | dfir-iris | iris-web | CWE-79 | DFIR-IRIS Stored XSS in Datastore Upload |
| CVE-2026-17816 | 7.5 | 19.0 | Google | Chrome | CWE-269 | Insufficient policy enforcement in Speech in Google Chrome on Android prior t… |
| CVE-2026-18382 | 6.8 | 19.1 | Red Hat | Cost Management Metrics Operator | CWE-918 | Project-koku/koku-metrics-operator: koku-metrics-operator: service-account cl… |
| CVE-2026-64816 | 7.1 | 18.9 | CyberTimon | RapidRAW | CWE-73 | RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath |
| CVE-2026-65834 | 6.8 | 18.9 | projectcapsule | capsule | CWE-20 | Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validati… |
| CVE-2026-17740 | 4.3 | 18.6 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-17757 | 4.3 | 18.6 | Google | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r… |
| CVE-2026-17771 | 4.3 | 18.6 | Google | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r… |
| CVE-2026-17785 | 4.3 | 18.6 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-17790 | 4.3 | 18.6 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72… |
| CVE-2026-17808 | 4.3 | 18.6 | Google | Chrome | CWE-457 | Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72… |
| CVE-2026-17810 | 4.3 | 18.6 | Google | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r… |
| CVE-2026-18186 | 7.1 | 18.5 | ASUSTOR Inc. | ADM | CWE-134 | A stored format string vulnerability was found in the FTP Backup on the ADM |
| CVE-2026-18187 | 7.1 | 18.5 | ASUSTOR Inc. | ADM | CWE-134 | A format string vulnerability was found in the Internal Backup on the ADM |
| CVE-2026-18188 | 7.1 | 18.5 | ASUSTOR Inc. | ADM | CWE-134 | A format string vulnerability was found in the Rsync Backup on the ADM |
| CVE-2026-61893 | 6.9 | 18.4 | MZ Automation | lib60870 | CWE-125 | MZ Automation lib60870 Out-of-bounds Read |
| CVE-2026-63033 | 6.9 | 18.4 | MZ Automation | lib60870 | CWE-125 | MZ Automation lib60870 Out-of-bounds Read |
| CVE-2026-17791 | 6.5 | 18.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Payments in Google Chrome prior… |
| CVE-2026-17792 | 6.5 | 18.5 | Google | Chrome | CWE-451 | Inappropriate implementation in Credential Management in Google Chrome prior … |
| CVE-2026-17793 | 6.5 | 18.5 | Google | Chrome | CWE-451 | Inappropriate implementation in Messages in Google Chrome on Android prior to… |
| CVE-2026-17831 | 6.5 | 18.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Passwords in Google Chrome prio… |
| CVE-2024-25039 | 7.5 | 18.2 | IBM | Engineering Requirements Management DOORS and DOORS Web Access | CWE-400 | IBM Engineering Requirements Management DOORS and DOORS Web Access is affecte… |
| CVE-2026-54715 | 7.1 | 18.2 | allinurl | goaccess | CWE-122 | GoAccess: Heap Out-of-Bounds Write in parse_browser() |
| CVE-2026-17892 | 6.5 | 18.2 | Google | Chrome | CWE-200 | Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72… |
| CVE-2026-55777 | 5.3 | 18.2 | allinurl | goaccess | CWE-125 | GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads… |
| CVE-2026-17830 | 6.5 | 18.2 | Google | Chrome | CWE-284 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-17869 | 8.1 | 18.0 | Google | Chrome | CWE-125 | Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a… |
| CVE-2025-69930 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69931 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69933 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69934 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69935 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in t… |
| CVE-2025-69936 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69937 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69938 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69941 | 9.8 | 17.9 | n/a | n/a | CWE-89 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in… |
| CVE-2025-69947 | 9.8 | 17.9 | n/a | n/a | CWE-89 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in… |
| CVE-2026-4978 | 9.8 | 17.9 | UMAI Vision | Traffic Analysis System | CWE-89 | SQLi in UMAI Vision's Traffic Analysis System |
| CVE-2026-14923 | 6.5 | 17.8 | Unknown | Sync Post With Other Site | CWE-863 | Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modi… |
| CVE-2026-17992 | 6.5 | 17.8 | Google | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 … |
| CVE-2026-17851 | 4.3 | 17.8 | Google | Chrome | CWE-1300 | Side-channel information leakage in Autofill in Google Chrome prior to 151.0.… |
| CVE-2026-17859 | 4.3 | 17.8 | Google | Chrome | CWE-1300 | Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922… |
| CVE-2026-44094 | 8.3 | 17.7 | Phoenix Contact | CHARX SEC-3150 | CWE-636 | Fallback to second RAUC slot with default credentials |
| CVE-2026-12722 | 8.2 | 17.3 | FTC Software IT Services | FTC E-Commerce Management Panel | CWE-306 | Authentication Bypass in FTC Software's E-Commerce Management Panel |
| CVE-2026-17848 | 9.6 | 17.2 | Google | Chrome | CWE-20 | Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-17832 | 9.6 | 17.0 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-17834 | 9.6 | 17.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Passwords in Google Chrome prio… |
| CVE-2026-17837 | 9.6 | 17.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… |
| CVE-2026-17924 | 9.6 | 17.0 | Google | Chrome | CWE-416 | Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remot… |
| CVE-2026-17940 | 9.6 | 17.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Picture-in-Picture in Google Ch… |
| CVE-2026-17947 | 9.6 | 17.0 | Google | Chrome | CWE-416 | Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed … |
| CVE-2026-67348 | 8.6 | 17.0 | julep-ai | julep | CWE-639 | Julep Insecure Direct Object Reference via GET /executions/{execution_id} |
| CVE-2026-12500 | 7.5 | 17.1 | Unknown | WP Travel Engine | CWE-862 | WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update |
| CVE-2026-13178 | 7.5 | 17.1 | Unknown | Eventin | CWE-639 | Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation |
| CVE-2026-54364 | 6.9 | 16.9 | Gladinet | CentreStack | CWE-116 | CentreStack < 17.4 Session Injection via SelectProvider.aspx |
| CVE-2026-63550 | 7.1 | 16.5 | MZ Automation GmbH | libiec61850 | CWE-125 | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-16092 | 6.5 | 16.5 | labelblanc | Improved Save Button | CWE-89 | Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Inje… |
| CVE-2026-13345 | 5.3 | 16.1 | Unknown | Essential Addons for Elementor | CWE-639 | Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Privat… |
| CVE-2026-58066 | 9.8 | 15.9 | Rocket.Chat | Rocket.Chat | CWE-287 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2… |
| CVE-2026-44097 | 5.3 | 15.9 | Phoenix Contact | CHARX SEC-3150 | CWE-434 | File Upload vulnerability |
| CVE-2026-17730 | 4.3 | 15.9 | Google | Chrome | CWE-1300 | Side-channel information leakage in Autofill in Google Chrome prior to 151.0.… |
| CVE-2026-17760 | 4.3 | 15.9 | Google | Chrome | CWE-1300 | Side-channel information leakage in NoStatePrefetch in Google Chrome prior to… |
| CVE-2026-17767 | 4.3 | 15.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in WebView in Google Chrome on And… |
| CVE-2026-17769 | 4.3 | 15.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Cast in Google Chrome prior to … |
| CVE-2026-17772 | 4.3 | 15.9 | Google | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a… |
| CVE-2026-17773 | 4.3 | 15.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Cast in Google Chrome prior to … |
| CVE-2026-17795 | 4.3 | 15.9 | Google | Chrome | CWE-20 | Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.… |
| CVE-2026-17991 | 9.6 | 15.7 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in AI in Google Chrome prior to 15… |
| CVE-2026-18017 | 8.8 | 15.7 | Google | Chrome | CWE-416 | Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remo… |
| CVE-2026-67527 | 7.6 | 15.6 | opf | openproject | CWE-862 | OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via… |
| CVE-2026-17779 | 5.4 | 15.6 | Google | Chrome | CWE-693 | Inappropriate implementation in Site Isolation in Google Chrome prior to 151.… |
| CVE-2026-14222 | 3.8 | 15.6 | Unknown | Easy Appointments | CWE-284 | Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Au… |
| CVE-2026-17749 | 9.6 | 15.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… |
| CVE-2026-44104 | 9.3 | 15.5 | Phoenix Contact | CHARX SEC-3150 | CWE-347 | ControllerAgent does not perform validation of firmware |
| CVE-2026-17786 | 8.8 | 15.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… |
| CVE-2026-15977 | 7.5 | 15.6 | SGLang | SGLang | CWE-522 | CVE-2026-15977 |
| CVE-2025-36374 | 5.5 | 15.5 | IBM | DataPower Gateway 10.6CD | CWE-611 | IBM DataPower Gateway affected by XML external entity injection |
| CVE-2026-17913 | 5.4 | 15.3 | Google | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-14188 | 2.7 | 15.4 | Unknown | Easy Appointments | CWE-200 | Easy Appointments < 3.12.28 - Contributor+ Customer Data Disclosure |
| CVE-2026-18353 | 8.8 | 15.3 | Eclipse Foundation | Eclipse CSI - PIA | CWE-918 | Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass |
| CVE-2026-48499 | 9.3 | 15.1 | activepieces | activepieces | CWE-200 | Activepieces: Cross-tenant data exposure and code injection via the Code piec… |
| CVE-2026-17840 | 6.5 | 15.1 | Google | Chrome | CWE-451 | Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 al… |
| CVE-2026-17850 | 6.5 | 15.1 | Google | Chrome | CWE-346 | Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7… |
| CVE-2026-17852 | 6.5 | 15.1 | Google | Chrome | CWE-346 | Inappropriate implementation in Media Router in Google Chrome prior to 151.0.… |
| CVE-2026-17662 | 4.3 | 15.1 | Google | Chrome | CWE-346 | Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7… |
| CVE-2026-17693 | 4.3 | 15.1 | Google | Chrome | CWE-346 | Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0… |
| CVE-2026-17934 | 4.3 | 15.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… |
| CVE-2026-17930 | 7.5 | 15.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… |
| CVE-2026-17824 | 6.5 | 14.9 | Google | Chrome | CWE-284 | Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 15… |
| CVE-2026-17873 | 6.5 | 14.9 | Google | Chrome | CWE-284 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… |
| CVE-2026-17975 | 6.5 | 15.0 | Google | Chrome | CWE-200 | Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.79… |
| CVE-2026-67529 | 4.3 | 15.0 | opf | openproject | CWE-200 | OpenProject: Private work package subject/identity disclosure through the glo… |
| CVE-2026-17995 | 8.1 | 14.8 | Google | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-44103 | 6.9 | 14.9 | Phoenix Contact | CHARX SEC-3150 | CWE-434 | JupiCore does not perform validation of firmware |
| CVE-2026-14980 | 8.8 | 14.7 | IBM | WebSphere Application Server - Liberty | CWE-269 | IBM WebSphere Application Server Liberty is affected by a cross-site request … |
| CVE-2026-17858 | 4.3 | 14.5 | Google | Chrome | CWE-457 | Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72… |
| CVE-2026-17889 | 4.3 | 14.5 | Google | Chrome | CWE-457 | Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a … |
| CVE-2026-44093 | 8.5 | 14.3 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via… |
| CVE-2026-44095 | 8.5 | 14.3 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation via Network scripts |
| CVE-2026-44096 | 8.5 | 14.3 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | udhcpc Privilege Escalation |
| CVE-2026-44099 | 8.5 | 14.3 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation via pppd password injection |
| CVE-2026-44106 | 8.5 | 14.3 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via… |
| CVE-2026-14305 | 5.3 | 14.2 | Unknown | WP Delicious | CWE-287 | WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe… |
| CVE-2026-17782 | 4.3 | 14.1 | Google | Chrome | CWE-451 | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.… |
| CVE-2026-17794 | 4.3 | 14.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Mobile in Google Chrome on Andr… |
| CVE-2026-17938 | 4.3 | 14.1 | Google | Chrome | CWE-451 | Inappropriate implementation in FullScreen in Google Chrome on Android prior … |
| CVE-2026-17941 | 4.3 | 14.1 | Google | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-18378 | 6.8 | 13.9 | Red Hat | Cost Management Metrics Operator | CWE-918 | Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secre… |
| CVE-2026-15382 | 6.5 | 13.6 | Unknown | Ultimate Addons for WPBakery Page Builder | CWE-73 | Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom I… |
| CVE-2026-17849 | 4.3 | 13.6 | Google | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-17805 | 6.5 | 13.5 | Google | Chrome | CWE-602 | Insufficient policy enforcement in Glic in Google Chrome on Android prior to … |
| CVE-2026-17813 | 6.5 | 13.5 | Google | Chrome | CWE-602 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… |
| CVE-2026-17921 | 6.5 | 13.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… |
| CVE-2026-17926 | 6.5 | 13.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… |
| CVE-2026-17931 | 6.5 | 13.5 | Google | Chrome | CWE-693 | Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922… |
| CVE-2026-17953 | 6.5 | 13.5 | Google | Chrome | CWE-602 | Insufficient policy enforcement in WebView in Google Chrome on Android prior … |
| CVE-2026-17659 | 4.2 | 13.4 | Google | Chrome | CWE-693 | Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0… |
| CVE-2026-17987 | 9.6 | 13.3 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Notifications in Google Chrome … |
| CVE-2026-17990 | 9.6 | 13.3 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAuthn in Google Chrome prior… |
| CVE-2026-14226 | 4.3 | 13.3 | Unknown | Easy Appointments | CWE-200 | Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure vi… |
| CVE-2026-14231 | 4.3 | 13.3 | Unknown | LifterLMS | CWE-200 | LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select… |
| CVE-2026-15235 | 4.3 | 13.3 | Unknown | MotoPress Hotel Booking | CWE-200 | Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin … |
| CVE-2026-18012 | 8.8 | 13.2 | Google | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a re… |
| CVE-2026-17920 | 8.8 | 13.1 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attac… |
| CVE-2026-14227 | 6.9 | 13.1 | MikroTik | RouterOS | CWE-613 | Insufficient session expiration in MikroTik RouterOS |
| CVE-2026-10545 | 7.5 | 13.0 | IBM | Planning Analytics Local | CWE-601 | IBM Planning Analytics Local is affected by Open Redirect |
| CVE-2026-11782 | 5.9 | 12.9 | Unknown | Points and Rewards for WooCommerce | CWE-284 | Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User … |
| CVE-2026-13143 | 5.3 | 12.9 | Unknown | WP Travel | CWE-290 | WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN |
| CVE-2026-17855 | 9.6 | 12.8 | Google | Chrome | CWE-362 | Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a rem… |
| CVE-2026-41187 | 6.2 | 12.8 | Tigera | Calico | CWE-285 | Calico Tier Authorization Bypass via DeleteCollection |
| CVE-2026-17914 | 5.3 | 12.8 | Google | Chrome | CWE-1300 | Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922… |
| CVE-2026-17949 | 4.3 | 12.7 | Google | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.72 a… |
| CVE-2026-68562 | 6.2 | 12.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-610 | Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information… |
| CVE-2026-17743 | 6.5 | 12.5 | Google | Chrome | CWE-346 | Insufficient policy enforcement in ControlledFrame in Google Chrome prior to … |
| CVE-2026-17748 | 6.5 | 12.5 | Google | Chrome | CWE-346 | Inappropriate implementation in Extensions in Google Chrome prior to 151.0.79… |
| CVE-2026-17754 | 6.5 | 12.5 | Google | Chrome | CWE-346 | Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72… |
| CVE-2026-17787 | 6.5 | 12.5 | Google | Chrome | CWE-346 | Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922… |
| CVE-2026-17819 | 6.5 | 12.6 | Google | Chrome | CWE-451 | Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.… |
| CVE-2026-17828 | 6.5 | 12.6 | Google | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-17835 | 6.5 | 12.6 | Google | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-17838 | 6.5 | 12.6 | Google | Chrome | CWE-451 | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.… |
| CVE-2026-17839 | 6.5 | 12.6 | Google | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … |
| CVE-2026-11707 | 9.3 | 12.4 | IBM | Tivoli System Automation Application Manager | CWE-79 | Multiple vulnerabilities have been identified in IBM WebSphere Application Se… |
| CVE-2026-17825 | 6.5 | 12.4 | Google | Chrome | CWE-284 | Insufficient policy enforcement in Passwords in Google Chrome on Android prio… |
| CVE-2026-17917 | 6.5 | 12.4 | Google | Chrome | CWE-284 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… |
| CVE-2025-51684 | 6.1 | 12.5 | n/a | n/a | CWE-79 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The ap… |
| CVE-2026-54365 | 8.7 | 12.4 | Gladinet | CentreStack | CWE-306 | CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNam… |
| CVE-2026-17985 | 6.5 | 12.4 | Google | Chrome | CWE-602 | Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.792… |
| CVE-2026-17988 | 6.5 | 12.4 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… |
| CVE-2026-17747 | 4.2 | 12.3 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Payments in Google Chrome on An… |