| CVE-2026-75977 | 8.8 | 47.3 | kitae-park | Mang Board WP | CWE-269 | Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to … |
| CVE-2026-80233 | 8.6 | 47.1 | CAYIN Technology | CAYIN CMS-WS | CWE-434 | CAYIN Technology|CAYIN CMS-WS/CMS-SE/SMP - Arbitrary File Upload |
| CVE-2026-58095 | 9.8 | 46.2 | FreeBSD | FreeBSD | CWE-122 | ppp(8): incorrect length calculation in mp_Enddisc() |
| CVE-2026-58096 | 9.8 | 46.2 | FreeBSD | FreeBSD | CWE-130 | ppp(8): missing length validation in LcpDecodeConfig() |
| CVE-2026-80237 | 8.7 | 45.9 | Thinking Software Technology | Efence | CWE-434 | Thinking Software Technology|Efence - Arbitrary File Upload |
| CVE-2026-9668 | 6.3 | 45.2 | ZTE | SCP | CWE-89 | SQL injection vulnerability in ZTE SCP product |
| CVE-2026-59683 | 9.3 | 45.1 | CalcProgrammer1 | OpenRGB | CWE-73 | OpenRGB: local and remote system compromise via arbitrary file write using at… |
| CVE-2020-15874 | await | 44.3 | n/a | n/a | — | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker wit… |
| CVE-2026-74737 | 9.8 | 44.2 | Linux | Linux | — | net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG |
| CVE-2026-65641 | 9.3 | 43.4 | Veeam | One | CWE-288 | A vulnerability allowing an unauthenticated network attacker to coerce SMB au… |
| CVE-2026-74746 | 9.8 | 43.3 | Linux | Linux | — | netfilter: flowtable: publish GC-visible tuple last |
| CVE-2026-73108 | 8.7 | 42.5 | rustdesk | rustdesk | CWE-770 | RustDesk < 1.4.7 Uncontrolled Memory Allocation DoS via BytesCodec |
| CVE-2026-80528 | 9.8 | 42.0 | Linux | Linux | — | ceph: avoid fs reclaim while using current->journal_info |
| CVE-2026-80558 | 9.8 | 42.0 | Linux | Linux | — | libceph: Avoid using invalid osd indices from primary_temp |
| CVE-2026-80561 | 9.8 | 42.0 | Linux | Linux | — | libceph: fix multiple unsafe decodes in decode_locker() |
| CVE-2026-74743 | 9.8 | 41.9 | Linux | Linux | — | macvlan: inherit needed_headroom and needed_tailroom from lowerdev |
| CVE-2026-74744 | 9.8 | 41.9 | Linux | Linux | — | ipvlan: inherit needed_headroom and needed_tailroom from phy_dev |
| CVE-2026-80428 | 9.3 | 41.8 | ILIAS-eLearning e.V. | ILIAS | CWE-502 | ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Sh… |
| CVE-2026-80348 | 8.7 | 41.7 | TarsCloud | TarsWeb | CWE-862 | TarsWeb through 3.0.16 Missing Authorization on Patch Deploy, Download and De… |
| CVE-2026-59682 | 8.8 | 41.6 | CalcProgrammer1 | OpenRGB | CWE-73 | Arbitrary file overwrite and deletion local and remote in OpenRGB |
| CVE-2026-80527 | 7.5 | 41.2 | Linux | Linux | — | ceph: fix hanging __ceph_get_caps() with stale mds_wanted |
| CVE-2026-74851 | 7.2 | 40.9 | Unknown | Pods | CWE-94 | Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback |
| CVE-2026-18794 | 8.8 | 38.6 | CalcProgrammer1 | OpenRGB | CWE-1288 | OpenRGB: insufficient input data checks lead to Denial-of-Service, memory ove… |
| CVE-2026-74742 | 7.5 | 38.4 | Linux | Linux | — | veth: fix queue index used to wake the peer txq in veth_poll |
| CVE-2026-63041 | 5.3 | 38.0 | Apache Software Foundation | Apache APISIX | CWE-807 | Apache APISIX: attach-consumer-label does not strip client-supplied consumer-… |
| CVE-2026-65647 | 8.7 | 37.9 | WebPros | Plesk Migrator | CWE-59 | Improper symlink resolution before file access in Plesk allows remote authent… |
| CVE-2026-58474 | 8.6 | 37.8 | Andyyyy64 | whichllm | CWE-94 | whichllm < 0.5.16 Code Injection via run and snippet commands |
| CVE-2026-80349 | 9.3 | 37.6 | TarsCloud | TarsWeb | CWE-290 | TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and … |
| CVE-2026-12717 | 9.4 | 37.5 | Google Cloud | BigQuery Data Transfer Service | CWE-74 | Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection S… |
| CVE-2026-74741 | 7.5 | 37.4 | Linux | Linux | — | net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling |
| CVE-2026-80519 | 9.8 | 37.2 | Linux | Linux | — | ovpn: finish crypto callback cleanup before peer release |
| CVE-2026-74752 | 9.8 | 36.2 | Linux | Linux | — | sctp: validate cookie AUTH state before use |
| CVE-2026-80520 | 7.5 | 35.9 | Linux | Linux | — | ovpn: fix NULL dereference when killing missing key |
| CVE-2026-77550 | 10.0 | 35.6 | Ubiquiti Inc | UniFi OS Server | CWE-93 | A malicious actor with access to the network could exploit an Improper Neutra… |
| CVE-2026-65642 | 8.6 | 35.5 | WebPros | Plesk | CWE-639 | Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 th… |
| CVE-2025-10903 | 6.5 | 35.1 | GitLab | GitLab | CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab |
| CVE-2026-80214 | 8.6 | 34.8 | librenms | librenms | CWE-78 | LibreNMS Virtualisation Discovery Module RCE |
| CVE-2026-18884 | 7.5 | 34.4 | wpgenie | WooCommerce Lottery | CWE-89 | WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Based SQL Injection via '… |
| CVE-2026-14216 | 6.5 | 34.2 | Unknown | Booking for Appointments and Events Calendar | CWE-287 | Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch |
| CVE-2026-80586 | 9.8 | 33.4 | Linux | Linux | — | mptcp: options: reset DSS fields in case of unexpected size |
| CVE-2026-54523 | 9.6 | 33.1 | kyverno | kyverno | CWE-862 | Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unva… |
| CVE-2026-19760 | 7.2 | 33.1 | emrevona | WP Fastest Cache – WordPress Cache Plugin | CWE-79 | WP Fastest Cache <= 1.5.0 - Unauthenticated Stored Cross-Site Scripting via H… |
| CVE-2026-80234 | 6.9 | 33.1 | CAYIN Technology | CAYIN CMS-WS | CWE-306 | CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication |
| CVE-2026-81202 | 5.5 | 33.1 | itsourcecode | Payroll System | CWE-287 | itsourcecode Payroll System CRUD Operation ajax.php delete missing authentica… |
| CVE-2026-46369 | 7.5 | 32.1 | nimiq | core-rs-albatross | CWE-193 | Nimiq: Validity store off by one error |
| CVE-2026-81030 | 7.1 | 32.0 | mage-ai | mage-ai | CWE-22 | Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_it… |
| CVE-2026-80203 | 9.3 | 31.6 | getgrav | grav | CWE-863 | Grav before 1.0.18 Authentication Bypass via Scoped API Key |
| CVE-2026-80346 | 7.1 | 31.6 | StarRocks | StarRocks | CWE-862 | StarRocks through 4.0.13 Missing Authorization on DROP MATERIALIZED VIEW for … |
| CVE-2026-75797 | 7.7 | 31.0 | Unknown | AI Engine | CWE-22 | AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter |
| CVE-2026-80557 | 9.8 | 30.8 | Linux | Linux | — | libceph: fix OOB read in decode_watchers() via missing bounds check |
| CVE-2026-80205 | 8.7 | 30.7 | nltk | nltk | CWE-1333 | NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex |
| CVE-2026-54550 | 7.4 | 30.5 | izpack | izpack | CWE-22 | IzPack: Path Traversal in UnpackerBase allows writing files outside the insta… |
| CVE-2026-80589 | 9.8 | 30.4 | Linux | Linux | — | block: stop the timeout timer when releasing a never added disk |
| CVE-2026-80236 | 8.8 | 30.0 | Thinking Software Technology | Efence | CWE-89 | Thinking Software Technology|Efence - SQL Injection |
| CVE-2026-18331 | 7.2 | 30.0 | strategy11team | Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More | CWE-79 | Formidable Forms <= 6.33.1 - Unauthenticated Stored Cross-Site Scripting via … |
| CVE-2026-80587 | 9.8 | 29.2 | Linux | Linux | — | mptcp: avoid combining some incoming suboptions |
| CVE-2026-15203 | 9.3 | 28.9 | Danfoss | iC7-Automation SP | CWE-1191 | Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 … |
| CVE-2026-74745 | 7.5 | 28.7 | Linux | Linux | — | eth: bnxt: avoid deadlock when canceling IRQ affinity notifier |
| CVE-2026-74750 | 7.5 | 28.7 | Linux | Linux | — | ovpn: defer key slot crypto freeing to workqueue |
| CVE-2026-65956 | 10.0 | 28.6 | 1Panel-dev | KubePi | CWE-306 | KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover … |
| CVE-2026-54606 | 8.5 | 28.1 | JiHong88 | suneditor | CWE-79 | SunEditor: DOM XSS in SunEditor Embed Plugin via External Script Element Afte… |
| CVE-2026-19538 | 8.2 | 28.2 | NLnet Labs | NSD | CWE-290 | Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS |
| CVE-2026-63179 | 4.9 | 27.8 | wintercms | winter | CWE-22 | Winter: Local File Inclusion through @import directives in LESS compilation o… |
| CVE-2026-75960 | 8.7 | 27.7 | Rently | Smart Home | CWE-522 | Insufficiently Protected Credentials in Rently Smart Home |
| CVE-2026-81028 | 6.9 | 27.8 | ZLMediaKit | ZLMediaKit | CWE-22 | ZLMediaKit downloadFile Root-Directory Confinement Bypass via Prefix Collision |
| CVE-2026-6178 | 6.4 | 27.6 | MuffinGroup | Betheme | CWE-79 | Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting vi… |
| CVE-2026-77801 | 6.5 | 27.1 | GitLab | GitLab | CWE-770 | Allocation of Resources Without Limits or Throttling in GitLab |
| CVE-2026-77693 | 8.7 | 26.8 | Unknown | Order Tip for WooCommerce | CWE-73 | Order Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via… |
| CVE-2026-80588 | 7.5 | 26.5 | Linux | Linux | — | mptcp: reclaim forward-allocated memory on RX path errors |
| CVE-2026-18252 | 7.3 | 26.4 | GitLab | GitLab | CWE-829 | Inclusion of Functionality from Untrusted Control Sphere in GitLab |
| CVE-2026-16984 | 6.5 | 26.4 | Unknown | Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates | CWE-284 | WP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure |
| CVE-2026-74751 | 9.4 | 26.3 | Linux | Linux | — | riscv: lib: Fix ZBB strnlen reading past count boundary |
| CVE-2026-54245 | 7.6 | 26.3 | fleetdm | fleet | CWE-89 | Fleet: SQL injection in Okta conditional access endpoint allows host-controll… |
| CVE-2026-54553 | 5.4 | 26.2 | jowilf | starlette-admin | CWE-200 | Starlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden c… |
| CVE-2026-19401 | 8.2 | 25.7 | NLnet Labs | NSD | CWE-400 | Remote UDP DoS by sending multiple DNS Cookie options |
| CVE-2026-18916 | 6.9 | 25.7 | NLnet Labs | NSD | CWE-191 | Remote TCP DoS by throttling the TCP receive window |
| CVE-2026-77557 | 9.8 | 25.5 | Ubiquiti Inc | UniFi Protect AI Key | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-79654 | 4.3 | 25.2 | Red Hat | Red Hat Satellite 6 | CWE-639 | Ketello: katello content view history api cross-organization authorization by… |
| CVE-2026-15985 | 8.1 | 24.9 | RadiusTheme | Classified Listing - Mobile Number Verification | CWE-289 | Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Au… |
| CVE-2026-14550 | 5.3 | 24.9 | Unknown | WPCafe | CWE-862 | WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Aut… |
| CVE-2026-19226 | 6.8 | 24.4 | Unknown | Royal Addons for Elementor | CWE-79 | Royal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordi… |
| CVE-2026-80585 | 9.4 | 24.0 | Linux | Linux | — | mptcp: fastopen: only mark MPTFO subflows with SYN data |
| CVE-2026-79921 | 8.9 | 23.9 | rabbitmq | amqp091-go | CWE-770 | amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Co… |
| CVE-2026-61792 | 7.7 | 23.9 | WeblateOrg | weblate | CWE-22 | Weblate path traversal allows a project administrator to read arbitrary files… |
| CVE-2026-18664 | 8.2 | 23.8 | NLnet Labs | NSD | CWE-284 | Wrong interpretation of ACL ranges |
| CVE-2026-81031 | 8.6 | 23.6 | idurar | idurar-erp-crm | CWE-639 | IDURAR ERP CRM through 4.1.1 Account Takeover via Unverified Identifier on Pa… |
| CVE-2026-13172 | 5.3 | 23.1 | Unknown | Eventin | CWE-862 | Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure |
| CVE-2026-13406 | 5.3 | 23.1 | Unknown | Royal Addons for Elementor | CWE-862 | Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure |
| CVE-2026-54614 | 4.3 | 23.1 | cakephp | debug_kit | CWE-470 | DebugKit: MailPreview contains unsafe reflection |
| CVE-2026-81036 | 8.5 | 22.9 | stalwartlabs | stalwart | CWE-601 | Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvali… |
| CVE-2026-66003 | 7.1 | 22.9 | frappe | frappe | CWE-863 | Frappe: Access control bypass via REST API dot-notation fields on linked doct… |
| CVE-2026-54511 | 8.6 | 22.8 | dahlia | logtape | CWE-93 | @logtape/syslog: syslog log injection via unescaped control characters and un… |
| CVE-2026-74928 | 7.5 | 22.8 | Unknown | Project Manager | CWE-862 | WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creatio… |
| CVE-2026-39275 | await | 22.6 | n/a | n/a | — | Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows … |
| CVE-2026-47841 | 7.4 | 22.5 | Spring | Spring Security | — | WebAuthn User Verification Bypass via Session Serialization |
| CVE-2026-19271 | 7.5 | 22.4 | TÜBİTAK BİLGEM Software Technologies Research Institute | Liderahenk | CWE-90 | Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk |
| CVE-2026-54556 | 8.2 | 22.3 | http4s | http4s | CWE-409 | Http4s: HTTP/2 Denial of Service with Ember Backend |
| CVE-2026-77549 | 9.0 | 22.2 | Ubiquiti Inc | UniFi OS Server | CWE-93 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2026-81029 | 8.5 | 22.1 | open-metadata | OpenMetadata | CWE-601 | OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redire… |
| CVE-2026-73102 | 6.9 | 21.3 | rustdesk | rustdesk | CWE-22 | RustDesk Path Traversal via macOS Clipboard File-Paste |
| CVE-2026-13404 | 5.3 | 21.1 | Unknown | Royal Addons for Elementor | CWE-639 | Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Mo… |
| CVE-2026-16986 | 5.3 | 21.1 | Unknown | Booking Package | CWE-284 | Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and… |
| CVE-2026-81032 | 9.3 | 21.0 | vesoft-inc | nebula | CWE-306 | NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Co… |
| CVE-2026-77298 | 8.7 | 21.0 | seaweedfs | seaweedfs | CWE-863 | SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy |
| CVE-2026-19718 | 8.1 | 21.0 | Unknown | BlogVault Backup & Staging | CWE-287 | BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover … |
| CVE-2026-81421 | 6.9 | 20.8 | ddfourtwo | sentry-selfhosted-mcp | CWE-918 | ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery |
| CVE-2026-81027 | 8.4 | 20.6 | songquanpeng | one-api | CWE-862 | one-api through 0.6.10 Missing Authorization on URL-Parameter Channel Pinning |
| CVE-2026-65646 | 8.7 | 20.5 | WebPros | Plesk | CWE-74 | Improper neutralization of special elements in Plesk allows remote authentica… |
| CVE-2026-80350 | 7.1 | 20.6 | OneUptime | OneUptime | CWE-918 | OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webh… |
| CVE-2026-81033 | 6.9 | 20.5 | automatisch | automatisch | CWE-204 | Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Disc… |
| CVE-2026-47837 | 6.8 | 20.4 | Spring | Spring Cloud Config | CWE-306 | Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests |
| CVE-2026-19094 | 5.3 | 20.3 | Unknown | Tutor LMS | CWE-89 | Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Par… |
| CVE-2026-68863 | 7.5 | 19.9 | Dell | PowerProtect One | CWE-121 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buf… |
| CVE-2026-81035 | 7.2 | 19.9 | midday-ai | midday | CWE-862 | Midday Missing Owner Check on Team Deletion |
| CVE-2026-32639 | 6.8 | 19.9 | wintercms | winter | CWE-289 | Winter: Broken access control in `Cms\Controllers\Index` allows cross-templat… |
| CVE-2026-80347 | 8.7 | 19.6 | kazuph | mcp-fetch | CWE-918 | mcp-fetch through 1.6.3 Server-Side Request Forgery via Unstripped IPv6 Liter… |
| CVE-2026-14212 | 4.7 | 19.5 | Unknown | Booking for Appointments and Events Calendar | CWE-639 | Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR |
| CVE-2020-15878 | await | 19.5 | n/a | n/a | — | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker wit… |
| CVE-2025-56798 | await | 19.6 | n/a | n/a | — | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Un… |
| CVE-2026-63360 | 7.4 | 19.1 | LimeSurvey | LimeSurvey | CWE-79 | LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirm… |
| CVE-2026-77532 | 9.6 | 18.8 | Ubiquiti Inc | EdgeMAX EdgeSwitch | CWE-122 | A malicious actor with access to an adjacent network could exploit a Buffer O… |
| CVE-2026-77754 | 5.3 | 18.9 | Unknown | Kirki | CWE-200 | Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via… |
| CVE-2026-77758 | 5.3 | 18.9 | Unknown | Stripe Payment Forms by WP Full Pay | CWE-200 | Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal… |
| CVE-2026-46370 | 6.5 | 18.8 | fleetdm | fleet | CWE-89 | Fleet has observer-level enrollment secret extraction via ORDER BY oracle on … |
| CVE-2026-47851 | 7.5 | 17.7 | Spring | Spring AI | CWE-674 | Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PD… |
| CVE-2026-3002 | 6.4 | 17.7 | jegstudio | Gutenverse – WordPress Blocks, Page Builder & Site Editor | CWE-79 | Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-81203 | 5.5 | 17.8 | SourceCodester | Simple Online Food Ordering System | CWE-74 | SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection |
| CVE-2026-15973 | 8.4 | 17.5 | LimeSurvey | LimeSurvey | CWE-79 | LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries |
| CVE-2026-16444 | 7.5 | 17.1 | TeamViewer | Full Client, Host, QuickSupport & Portable | CWE-73 | Improper Validation of File Paths in TeamViewer Desktop Clients |
| CVE-2026-77541 | 9.1 | 17.0 | Ubiquiti Inc | UniFi Network Application | CWE-284 | A malicious actor with access to the network and high privileges could exploi… |
| CVE-2026-77757 | 5.4 | 16.7 | Unknown | Directorist: AI-Powered Business Directory, Listings & Classified Ads | CWE-22 | Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listin… |
| CVE-2026-61790 | 4.4 | 16.6 | WeblateOrg | weblate | CWE-284 | Weblate: Team-enforced 2FA is bypassed for global permissions |
| CVE-2026-35445 | 7.1 | 16.5 | wintercms | winter | CWE-285 | Winter: Authenticated backend users can bypass Users controller permission ch… |
| CVE-2026-47665 | 8.7 | 16.3 | penpot | penpot | CWE-79 | Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML |
| CVE-2026-48786 | 6.5 | 16.3 | fleetdm | fleet | CWE-200 | Fleet: Observer-class users can view team enroll secrets and credential-beari… |
| CVE-2026-47861 | 6.3 | 16.3 | Spring | Spring Integration | CWE-918 | UDP adapter sends ack to attacker-supplied host:port parsed from packet body,… |
| CVE-2026-80206 | 8.2 | 16.1 | nltk | nltk | CWE-1333 | NLTK 3.10.2 Regular Expression Denial of Service via tgrep |
| CVE-2026-61617 | 7.7 | 16.0 | pterodactyl | wings | CWE-400 | Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-… |
| CVE-2026-62326 | 6.5 | 16.0 | WeblateOrg | weblate | CWE-400 | Weblate Has Uncontrolled Resource Consumption via |
| CVE-2026-47862 | 5.4 | 16.1 | Spring | Spring Integration | CWE-22 | ZipTransformer uses file_name header to build workDirectory path without sani… |
| CVE-2026-12587 | 8.6 | 15.3 | Resamania | Virtuagym | CWE-798 | Embedded credentials in Virtuagym |
| CVE-2026-16809 | 7.2 | 15.3 | LimeSurvey | LimeSurvey | CWE-79 | LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering |
| CVE-2026-65930 | 4.8 | 15.3 | LimeSurvey | LimeSurvey | CWE-79 | LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields |
| CVE-2026-3035 | 5.5 | 14.8 | GitLab | GitLab | CWE-288 | Authentication Bypass Using an Alternate Path or Channel in GitLab |
| CVE-2026-75798 | 5.3 | 14.7 | Unknown | AI Engine | CWE-862 | AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Ed… |
| CVE-2026-77694 | 5.3 | 14.7 | Unknown | Eventin | CWE-862 | Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order… |
| CVE-2026-69129 | 5.8 | 14.6 | 1Panel-dev | KubePi | CWE-639 | KubePi: Insufficient per-cluster authorization checks in cluster management APIs |
| CVE-2026-47874 | 5.3 | 14.6 | Spring | Reactor Netty | CWE-770 | Reactor Netty HTTP Server Denial of Service With Pipelined Requests |
| CVE-2026-3235 | 5.3 | 14.5 | peterschulznl | WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards | CWE-639 | WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5… |
| CVE-2026-77507 | 5.3 | 14.6 | WeblateOrg | weblate | CWE-200 | Weblate: Object-scoped RSS feeds disclose private change history to unauthori… |
| CVE-2026-47860 | 6.5 | 14.2 | Spring | Spring AMQP | — | Unbounded decompression of attacker-supplied compressed message bodies |
| CVE-2026-2388 | 6.4 | 14.2 | designextreme | Reviews and Rating – Google Reviews | CWE-79 | Reviews and Rating – Google Reviews <= 5.10 - Authenticated (Contributor+) St… |
| CVE-2026-47856 | 6.3 | 14.3 | Spring | Spring Integration | CWE-502 | JsonToObjectTransformer resolves the json__TypeId__ message header to an arbi… |
| CVE-2026-58108 | 1.2 | 14.0 | Ericsson | CodeChecker | CWE-284 | Personal access token delete filters on Session columns while deleting from P… |
| CVE-2026-77534 | 9.9 | 13.9 | Ubiquiti Inc | UniFi OS Server | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-77536 | 9.9 | 13.9 | Ubiquiti Inc | UniFi OS Server | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-77553 | 9.9 | 13.9 | Ubiquiti Inc | UniFi Access Application | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-75896 | 9.1 | 13.9 | TÜBİTAK BİLGEM Software Technologies Research Institute | Liderahenk | CWE-798 | Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk |
| CVE-2026-75062 | 9.2 | 13.7 | Google | langfun | CWE-95 | Eval Injection in google/langfun via default lf.query protocol |
| CVE-2026-80426 | 7.0 | 13.8 | voxel51 | fiftyone | CWE-79 | FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Descri… |
| CVE-2026-78146 | 6.5 | 13.7 | Unknown | Simple Newsletter Plugin | CWE-200 | Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure vi… |
| CVE-2020-15876 | await | 13.8 | n/a | n/a | — | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker wit… |
| CVE-2026-75601 | 4.3 | 13.7 | static-web-server | static-web-server | CWE-306 | Static Web Server: Authentication bypass on /metrics endpoint when --basic-au… |
| CVE-2026-7487 | 3.5 | 13.6 | GitLab | GitLab | CWE-1280 | Access Control Check Implemented After Asset is Accessed in GitLab |
| CVE-2026-55228 | 8.1 | 13.2 | WeblateOrg | weblate | CWE-639 | Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gai… |
| CVE-2026-19485 | 9.3 | 13.1 | Google Cloud | Vertex AI Search for Commerce | CWE-330 | Bucket Squatting in Vertex AI Search for Commerce |
| CVE-2026-80183 | 7.1 | 13.1 | OpenStack | Keystone | CWE-843 | In OpenStack Keystone before 29.0.3, any authenticated user holding role:read… |
| CVE-2026-77538 | 8.2 | 13.0 | Ubiquiti Inc | UniFi Connect Application | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-75411 | await | 12.9 | n/a | n/a | — | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode comp… |
| CVE-2026-47857 | 5.9 | 12.6 | Spring | Reactor Core | CWE-190 | Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index … |
| CVE-2026-47863 | 5.9 | 12.6 | Spring | Reactor Core | CWE-835 | Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when … |
| CVE-2026-77611 | 7.1 | 12.5 | seaweedfs | seaweedfs | CWE-863 | SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwr… |
| CVE-2026-77551 | 9.0 | 12.3 | Ubiquiti Inc | UniFi Connect Display Cast Pro | CWE-284 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2026-77317 | 8.1 | 12.4 | seaweedfs | seaweedfs | CWE-863 | SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read … |
| CVE-2026-36851 | await | 12.4 | n/a | n/a | — | Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitra… |
| CVE-2026-79938 | 7.6 | 12.2 | Dell | Power Protect Cyber Recovery | CWE-287 | Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper… |
| CVE-2026-46371 | 6.5 | 12.2 | fleetdm | fleet | CWE-89 | Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on App… |
| CVE-2026-49809 | 6.5 | 12.2 | Dell | Power Protect Cyber Recovery | CWE-89 | Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Imprope… |
| CVE-2026-58097 | 7.8 | 12.1 | FreeBSD | FreeBSD | CWE-122 | ppp(8): missing length validation in mp_SetEnddisc() |
| CVE-2026-15365 | 2.4 | 11.9 | vivo | Kids Mode | CWE-841 | A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass … |
| CVE-2026-52103 | await | 11.9 | n/a | n/a | — | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notif… |
| CVE-2026-71054 | 6.5 | 11.9 | Oracle Corporation | Oracle Java SE | CWE-770 | Vulnerability in Oracle Java SE (component: 2D). Supported versions that are … |
| CVE-2026-77695 | 6.5 | 11.9 | Unknown | Return Refund and Exchange For WooCommerce | CWE-284 | Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Di… |
| CVE-2026-32257 | 8.1 | 11.8 | wintercms | winter | CWE-79 | Winter: Stored XSS through Brand Settings custom styles |
| CVE-2026-32258 | 8.1 | 11.8 | wintercms | winter | CWE-79 | Winter: Stored XSS through Editor Settings custom styles |
| CVE-2026-77368 | 7.6 | 11.8 | seaweedfs | seaweedfs | CWE-639 | SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbit… |
| CVE-2026-77545 | 9.0 | 11.7 | Ubiquiti Inc | UniFi OS Server | CWE-489 | A malicious actor with access to the network, low privileges and under certai… |
| CVE-2026-74930 | 4.3 | 11.4 | Unknown | Project Manager | CWE-639 | WP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure … |
| CVE-2026-64632 | 8.5 | 10.7 | Veeam | ONE | CWE-522 | A vulnerability allowing a low-privileged user to capture the NTLM credential… |
| CVE-2026-15387 | 4.3 | 10.8 | GitLab | GitLab | CWE-349 | Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab |
| CVE-2026-76148 | 8.4 | 10.6 | SASAKI Nobuyuki | CorvusSKK | CWE-94 | CorvusSKK contains a code injection vulnerability, which may lead to arbitrar… |
| CVE-2026-5092 | 6.4 | 10.5 | wpsoul | Greenshift – animation and page builder blocks | CWE-79 | Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripti… |
| CVE-2026-15366 | 2.4 | 10.3 | vivo | Kids Mode | CWE-653 | A control logic defect in a specific built-in webpage of Kids Mode allows use… |
| CVE-2026-47852 | 7.5 | 10.1 | Spring | Spring AI | CWE-377 | Predictable cache directory location allows local ONNX model substitution in … |
| CVE-2026-19197 | 6.3 | 10.1 | Grafana | Grafana OSS | CWE-862 | Broken access control in dashboard snapshots |
| CVE-2026-47666 | 7.6 | 9.9 | penpot | penpot | CWE-79 | Penpot: Stored XSS via custom font family name injected into a @font-face sty… |
| CVE-2026-47834 | 4.8 | 9.8 | Spring | Spring Data JPA | — | Spring Data JPA Sort expression validation bypass |
| CVE-2026-77789 | 4.3 | 9.8 | Unknown | Stripe Payment Forms by WP Full Pay | CWE-639 | Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Mod… |
| CVE-2026-74771 | 6.5 | 9.2 | Dell | PowerProtect One | CWE-639 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization … |
| CVE-2026-47859 | 5.4 | 9.3 | Spring | Spring Integration | CWE-770 | Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted frami… |
| CVE-2026-75363 | await | 9.1 | n/a | n/a | — | An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute … |
| CVE-2026-19220 | 3.7 | 8.7 | Unknown | Forminator Forms | CWE-269 | Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privi… |
| CVE-2026-77790 | await | 8.7 | Unknown | RegistrationMagic | — | RegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter |
| CVE-2026-47844 | 5.3 | 8.6 | Spring | Reactor Netty | — | Reactor Netty HTTP Server Leaks Exception Details |
| CVE-2026-71172 | 4.3 | 8.0 | Dell | Cloud Disaster Recovery | CWE-918 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side … |
| CVE-2026-41262 | 4.3 | 7.9 | fleetdm | fleet | CWE-863 | Fleet: Cross-Team Policy Data Exposure via Global Policy Read Endpoint |
| CVE-2026-55227 | 4.3 | 7.9 | WeblateOrg | weblate | CWE-203 | Observable object existence disclosure in private Weblate projects via global… |
| CVE-2026-62249 | 4.3 | 7.9 | WeblateOrg | weblate | CWE-200 | Weblate: Restricted-component change history leaked to non-member project use… |
| CVE-2026-43621 | 8.6 | 7.7 | SimpleMachines | SMF | CWE-863 | Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load() |
| CVE-2026-79940 | 5.9 | 7.7 | Dell | iDRAC9 | CWE-284 | Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to … |
| CVE-2026-74929 | 5.4 | 7.7 | Unknown | Project Manager | CWE-284 | WP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Ta… |
| CVE-2026-75325 | await | 7.5 | n/a | n/a | — | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsu… |
| CVE-2026-47850 | 4.3 | 7.5 | Spring | Spring Data REST | CWE-915 | Spring Data REST allows mutation of the version property of immutable aggrega… |
| CVE-2025-70293 | await | 7.4 | n/a | n/a | — | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vu… |
| CVE-2026-47845 | 5.3 | 7.2 | Spring | Reactor Netty | CWE-290 | Reactor Netty HTTP Server may incorrectly evaluate proxy addresses |
| CVE-2026-74740 | await | 7.1 | Linux | Linux | — | net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain |
| CVE-2026-74734 | await | 6.8 | Linux | Linux | — | firewire: ohci: fix NULL pointer dereference in ar_context_release |
| CVE-2026-74738 | await | 6.8 | Linux | Linux | — | regmap: sdw-mbq: don't call an unset readable_reg callback |
| CVE-2026-75414 | await | 6.8 | n/a | n/a | — | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expression… |
| CVE-2026-80529 | await | 6.8 | Linux | Linux | — | xfs: don't swallow dquot recovery verification errors |
| CVE-2026-80534 | await | 6.8 | Linux | Linux | — | xfs: fix ilock leak on error in xfs_dq_get_next_id |
| CVE-2026-32593 | 5.9 | 6.7 | wintercms | winter | CWE-89 | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersF… |
| CVE-2026-67275 | 5.3 | 6.7 | Dell | PowerProtect One | CWE-1357 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Ins… |
| CVE-2025-70290 | await | 6.5 | n/a | n/a | — | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vu… |
| CVE-2026-75329 | 9.8 | 6.5 | n/a | n/a | CWE-306 | The Netty configuration distribution service (port 8283) of super-diamond-ser… |
| CVE-2026-75338 | 9.8 | 6.5 | n/a | n/a | CWE-284 | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable … |
| CVE-2026-52473 | await | 6.4 | n/a | n/a | — | An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via… |
| CVE-2026-75364 | await | 6.4 | n/a | n/a | — | Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the updat… |
| CVE-2026-75413 | await | 6.5 | n/a | n/a | — | DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need… |
| CVE-2026-48549 | 6.9 | 6.3 | Nagios Enterprises, LLC. | Nagios Core | CWE-352 | Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie |
| CVE-2026-80525 | await | 6.3 | Linux | Linux | — | ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup |
| CVE-2026-80532 | await | 6.3 | Linux | Linux | — | xfs: fix another iunlink infinite loop bug in online fsck |
| CVE-2026-80533 | await | 6.3 | Linux | Linux | — | xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair |
| CVE-2026-80535 | await | 6.3 | Linux | Linux | — | xfs: don't double-lock when deleting a self-referential directory |
| CVE-2026-80539 | await | 6.3 | Linux | Linux | — | drm/amdgpu: disallow multiple FENCE chunks in one submit |
| CVE-2026-80563 | await | 6.3 | Linux | Linux | — | gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind |
| CVE-2026-47843 | 3.7 | 6.1 | Spring | Reactor Netty | — | Reactor Netty may incorrectly route traffic due to DNS resolver reuse |
| CVE-2026-80542 | await | 6.1 | Linux | Linux | — | drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() |
| CVE-2026-80562 | await | 6.1 | Linux | Linux | — | gpio: ml-ioh: use raw_spinlock_t for the register lock |
| CVE-2026-80564 | await | 6.1 | Linux | Linux | — | gve: fix NULL dereference due to missing ptp adjfine |
| CVE-2026-80567 | await | 5.9 | Linux | Linux | — | Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue |
| CVE-2026-80573 | await | 5.9 | Linux | Linux | — | Input: iforce - validate input packet lengths |
| CVE-2026-56547 | 3.5 | 5.8 | HCLSoftware | Traveler | CWE-20 | An input reflection vulnerability affects HCL Traveler |
| CVE-2026-74735 | await | 5.7 | Linux | Linux | — | l2tp: fix tunnel and session refcount leak on seq_file release |
| CVE-2026-74749 | await | 5.7 | Linux | Linux | — | rseq: Prevent hard lockup on granted time slice extension |
| CVE-2026-13481 | 5.4 | 5.6 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP |
| CVE-2026-13480 | 3.1 | 5.6 | zephyrproject | zephyr | CWE-20 | Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlin… |
| CVE-2026-81034 | 8.3 | 5.5 | gravitl | netmaker | CWE-295 | Netmaker through 1.6.0 Improper Certificate Validation in SMTP Client |
| CVE-2026-80566 | await | 5.1 | Linux | Linux | — | Input: hynitron_cstxxx - validate touch count and finger IDs |
| CVE-2026-80577 | await | 5.1 | Linux | Linux | — | drm/panthor: skip zero-sized firmware sections |
| CVE-2025-70340 | await | 5.0 | n/a | n/a | — | A Broken Access Control vulnerability exists in ThingsBoard Professional Edit… |
| CVE-2026-26445 | await | 5.0 | n/a | n/a | — | stomper 5e2741e is vulnerable to Denial of Service. A malicious client can se… |
| CVE-2026-26446 | await | 5.0 | n/a | n/a | — | Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data … |
| CVE-2026-26447 | await | 5.0 | n/a | n/a | — | Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeate… |
| CVE-2026-26448 | await | 5.0 | n/a | n/a | — | Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple… |
| CVE-2026-26449 | await | 5.0 | n/a | n/a | — | In Stomper 5e2741e when a client sends a SEND frame missing the destination h… |
| CVE-2026-74754 | await | 5.0 | Linux | Linux | — | scsi: core: pair EH runtime PM get and put |
| CVE-2026-75334 | await | 4.9 | n/a | n/a | — | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitr… |
| CVE-2026-80524 | await | 5.0 | Linux | Linux | — | optee: ffa: Add NULL check in optee_ffa_lend_protmem |
| CVE-2026-80543 | await | 5.0 | Linux | Linux | — | s390/zcrypt: Pad trailing CCA or EP11 message with zeros |
| CVE-2025-51679 | await | 4.9 | n/a | n/a | — | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between … |
| CVE-2025-61165 | await | 4.9 | n/a | n/a | — | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload compo… |
| CVE-2026-80571 | await | 4.9 | Linux | Linux | — | powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak |
| CVE-2026-80581 | await | 4.9 | Linux | Linux | — | ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout |
| CVE-2026-80204 | 9.3 | 4.8 | getgrav | grav | CWE-863 | Grav before 1.0.18 Authentication Bypass via Scoped API Key |
| CVE-2026-80427 | 8.6 | 4.7 | nfriedly | bestzip | CWE-88 | bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Op… |
| CVE-2026-47848 | 6.1 | 4.7 | Spring | Reactor Netty | — | Reactor Netty WebSocket Client Leaks Credentials On Redirect |
| CVE-2026-77508 | 3.5 | 4.7 | WeblateOrg | weblate | CWE-302 | Weblate: Unverified REST API email changes |
| CVE-2026-68000 | await | 4.6 | n/a | n/a | — | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to S… |
| CVE-2026-77652 | 7.8 | 4.6 | GNOME | Dia | CWE-122 | Dia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palet… |
| CVE-2026-13479 | 3.1 | 4.6 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler |
| CVE-2026-29988 | 8.3 | 4.5 | Milesight | AM102/102L V2 | CWE-319 | A cleartext transmission of sensitive information vulnerability in the NFC in… |
| CVE-2026-54467 | 7.0 | 4.5 | TrustedFirmware | Trusted Firmware-M | CWE-283 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mai… |
| CVE-2025-29419 | await | 4.5 | n/a | n/a | — | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. |
| CVE-2026-47842 | 6.5 | 4.4 | Spring | Spring Security | — | Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows … |
| CVE-2026-76784 | 8.7 | 4.2 | TP-Link Systems Inc. | HS103P3 / HS103P4 v5 | CWE-325 | Insufficient Cryptographic Protections in Local Device Communication Protocol… |
| CVE-2026-45694 | 5.4 | 4.2 | librenms | librenms | CWE-79 | LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid… |
| CVE-2026-58092 | 5.4 | 4.2 | FreeBSD | FreeBSD | CWE-288 | Unauthorized credential switching |
| CVE-2023-42179 | await | 4.1 | n/a | n/a | — | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access C… |
| CVE-2025-61162 | await | 4.1 | n/a | n/a | — | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitr… |
| CVE-2025-61163 | await | 4.1 | n/a | n/a | — | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross… |
| CVE-2025-61164 | await | 4.1 | n/a | n/a | — | Cohere North AI v1.1.5 was discovered to contain an information leak via the … |
| CVE-2026-80551 | 9.3 | 4.0 | Linux | Linux | — | s390/vfio_ccw: Ensure first IDAW remains constant |
| CVE-2026-80554 | 9.3 | 4.0 | Linux | Linux | — | s390/vfio_ccw: Limit the number of channel program segments |
| CVE-2026-77658 | 7.8 | 4.0 | GNOME | Dia | CWE-121 | Dia: dia: stack buffer overflow in bus object via unvalidated handle count in… |
| CVE-2026-75330 | 9.8 | 3.9 | n/a | n/a | CWE-89 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} o… |
| CVE-2026-75336 | 9.8 | 3.9 | n/a | n/a | CWE-89 | Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces … |
| CVE-2026-54256 | 5.4 | 3.9 | wintercms | winter | CWE-284 | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user acc… |
| CVE-2026-80536 | 8.4 | 3.8 | Linux | Linux | — | xfs: bounds-check buffer log item's dirty bitmap |
| CVE-2026-80544 | 7.8 | 3.8 | Linux | Linux | — | s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing |
| CVE-2026-77573 | 3.5 | 3.8 | WeblateOrg | weblate | CWE-367 | Weblate: DNS rebinding in VCS operations allows server-side request forgery |
| CVE-2026-80555 | 7.1 | 3.7 | Linux | Linux | — | s390/vfio_ccw: Free all memory if cp_init() fails |
| CVE-2026-75332 | 9.1 | 3.6 | n/a | n/a | CWE-918 | Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via … |
| CVE-2026-75340 | 9.1 | 3.6 | n/a | n/a | CWE-918 | The device metadata import interface /device/instance/{productId}/property-me… |
| CVE-2026-75333 | 7.5 | 3.6 | n/a | n/a | CWE-22 | yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as… |
| CVE-2026-48548 | 6.9 | 3.6 | Nagios Enterprises, LLC. | Nagios Core | CWE-352 | Nagios Core CSRF via cmd.cgi |
| CVE-2026-74774 | 5.9 | 3.5 | Dell | PowerProtect One | CWE-295 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certi… |
| CVE-2025-51675 | await | 3.6 | n/a | n/a | — | An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate updat… |
| CVE-2025-61478 | await | 3.6 | n/a | n/a | — | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.1… |
| CVE-2025-61479 | await | 3.6 | n/a | n/a | — | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.1… |
| CVE-2025-61480 | await | 3.6 | n/a | n/a | — | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.1… |
| CVE-2026-75327 | await | 3.6 | n/a | n/a | — | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSyst… |
| CVE-2026-75328 | await | 3.6 | n/a | n/a | — | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/c… |
| CVE-2026-75415 | await | 3.6 | n/a | n/a | — | AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsReque… |
| CVE-2026-75466 | await | 3.6 | n/a | n/a | — | libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the… |
| CVE-2026-74736 | 7.8 | 3.5 | Linux | Linux | — | net/sched: cls_bpf: reject dev-bound programs bound to a different device |
| CVE-2026-74739 | 7.8 | 3.5 | Linux | Linux | — | net/sched: cls_u32: skip hash tables in u32_bind_class() |
| CVE-2026-74748 | 7.8 | 3.5 | Linux | Linux | — | netfilter: ipset: fix refcount race between list:set GC and swap |
| CVE-2026-79619 | 7.3 | 3.5 | OpenZFS | OpenZFS | CWE-863 | OpenZFS: user-namespace capability check allows unprivileged local authorizat… |
| CVE-2026-80550 | 7.9 | 3.4 | Linux | Linux | — | s390/vfio_ccw: Fix out of bounds check on CCW array |
| CVE-2026-75331 | 4.6 | 3.4 | n/a | n/a | CWE-434 | tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS.… |
| CVE-2026-80545 | 7.8 | 3.3 | Linux | Linux | — | s390/zcrypt: Improve EP11 CPRB length and overflow checks |
| CVE-2026-80546 | 7.8 | 3.3 | Linux | Linux | — | s390/zcrypt: Improve CCA CPRB length and overflow checks |
| CVE-2026-80574 | 8.4 | 3.2 | Linux | Linux | — | Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet |
| CVE-2026-80584 | 8.4 | 3.2 | Linux | Linux | — | s390/qeth: validate user buffer length in SNMP and ARP query ioctls |
| CVE-2026-80549 | 8.2 | 3.2 | Linux | Linux | — | s390/vfio_ccw: Move cp cleanup out of not operational |
| CVE-2026-58090 | 7.8 | 3.2 | FreeBSD | FreeBSD | CWE-416 | Use-after-free in unix SOCK_STREAM message handling |
| CVE-2026-58091 | 7.8 | 3.2 | FreeBSD | FreeBSD | CWE-416 | Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl |
| CVE-2026-78237 | 7.8 | 3.2 | Admin By Request (ABR) | Admin By Request (ABR) | CWE-20 | Insufficient input validation in Admin By Request (ABR) |
| CVE-2026-80570 | 7.8 | 3.2 | Linux | Linux | — | Input: synaptics-rmi4 - zero report size on F54 work error |
| CVE-2026-76149 | 4.6 | 3.2 | SASAKI Nobuyuki | CorvusSKK | CWE-190 | CorvusSKK contains an integer overflow vulnerability, which may allow malicio… |
| CVE-2026-80568 | 7.8 | 3.1 | Linux | Linux | — | Input: synaptics-rmi4 - block s_input when F54 queue is busy |
| CVE-2026-51106 | await | 3.1 | n/a | n/a | — | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of … |
| CVE-2026-80552 | 8.8 | 2.8 | Linux | Linux | — | s390/vfio_ccw: Ensure index for read/write regions are within range |
| CVE-2026-74747 | 7.8 | 2.9 | Linux | Linux | — | ipvs: revalidate ihl to prevent out-of-bounds access |
| CVE-2026-80540 | 7.8 | 2.8 | Linux | Linux | — | drm/amdgpu: Fix UVD decode image min size calculation |
| CVE-2026-80541 | 7.8 | 2.8 | Linux | Linux | — | drm/amdgpu: validate GEM_CREATE domain combinations |
| CVE-2026-80559 | 7.8 | 2.8 | Linux | Linux | — | Input: sur40 - fix input device registration ordering |
| CVE-2026-80560 | 7.8 | 2.8 | Linux | Linux | — | openrisc: signal: do not restore privileged SR bits on sigreturn |
| CVE-2026-80547 | 8.8 | 2.8 | Linux | Linux | — | s390/vfio_ccw: Implement a crw lock |
| CVE-2026-80548 | 8.8 | 2.8 | Linux | Linux | — | s390/vfio_ccw: Selectively expand io_mutex |
| CVE-2026-80553 | 8.8 | 2.8 | Linux | Linux | — | s390/vfio_ccw: Cancel existing workqueues |
| CVE-2026-80522 | 7.8 | 2.8 | Linux | Linux | — | crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() |
| CVE-2026-80526 | 7.8 | 2.8 | Linux | Linux | — | ASoC: tas2562: Validate values for volume writes |
| CVE-2026-80531 | 7.8 | 2.8 | Linux | Linux | — | xfs: avoid UAF on sc->tempip in xrep_tempfile_create |
| CVE-2026-79902 | 5.5 | 2.8 | GNOME | GIMP | CWE-190 | Gimp: stack vla size underflow denial of service in seattle |
| CVE-2026-73335 | 4.6 | 2.8 | Digital Agency | Android App "Myna Point" | CWE-939 | Android application "Myna Point" is vulnerable to Improper Authorization in H… |
| CVE-2026-74753 | 7.8 | 2.6 | Linux | Linux | — | perf: Reject exited events as group leaders |
| CVE-2026-80537 | 7.8 | 2.6 | Linux | Linux | — | xfs: fix off-by-one in rtrefcount btree root level validation |
| CVE-2026-80530 | 7.1 | 2.6 | Linux | Linux | — | xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN |
| CVE-2026-80556 | 7.8 | 2.5 | Linux | Linux | — | mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition |
| CVE-2026-80523 | 7.1 | 2.5 | Linux | Linux | — | clk: spacemit: k3: set hdma clock as critical |
| CVE-2026-80538 | 7.1 | 2.4 | Linux | Linux | — | xfs: propagate errors from xfs_rtginode_load |
| CVE-2026-80576 | 8.8 | 2.0 | Linux | Linux | — | drm/amdgpu: reject oversized IBs with per-ring packet limits |
| CVE-2026-80521 | 7.8 | 2.1 | Linux | Linux | — | af_unix: Unlink scc_entry in unix_del_edge(). |
| CVE-2026-80565 | 7.8 | 2.1 | Linux | Linux | — | crypto: qce - fix error path in devm_qce_register_algs |
| CVE-2026-80569 | 7.8 | 2.1 | Linux | Linux | — | Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer |
| CVE-2026-80575 | 7.8 | 2.0 | Linux | Linux | — | Input: cs40l50-vibra - validate custom data from user space |
| CVE-2026-58089 | 7.8 | 2.0 | FreeBSD | FreeBSD | CWE-273 | hwpmc fails to detach PMCs during exec credential transitions |
| CVE-2026-80572 | 7.8 | 1.9 | Linux | Linux | — | Input: byd - synchronize timer deletion before freeing private data |
| CVE-2026-9805 | 2.7 | 1.8 | Insyde Software | InsydeH2O | CWE-787 | FMTSWriteUseIntelLib: FMTS SMM IHISI Buffer Overflow |
| CVE-2026-80578 | 7.3 | 1.8 | Linux | Linux | — | fbdev: core: Fix pointer desynchronization in fb_io_read() |
| CVE-2026-58070 | 6.8 | 1.8 | Veeam | Backup and Replication | CWE-532 | A vulnerability that records guest OS processing credentials in cleartext in … |
| CVE-2025-62341 | 3.7 | 1.8 | HCLSoftware | Connections | CWE-918 | HCL Connections is vulnerable to server-side request forgery (SSRF) |
| CVE-2026-80579 | 7.8 | 1.5 | Linux | Linux | — | fbdev: clear fb_info->mode before deleting a videomode |
| CVE-2026-80580 | 7.8 | 1.5 | Linux | Linux | — | fbdev: bound mode sysfs output to the sysfs buffer |
| CVE-2026-80582 | 7.8 | 1.5 | Linux | Linux | — | drm/shmem_helper: Check VMA boundaries for PMD mappings |
| CVE-2026-80583 | 7.8 | 1.5 | Linux | Linux | — | ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses |
| CVE-2026-79939 | 5.8 | 1.5 | Dell | Power Protect Cyber Recovery | CWE-61 | Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Sym… |
| CVE-2026-58094 | 7.8 | 1.4 | FreeBSD | FreeBSD | CWE-367 | TOCTOU race in POSIX shared memory large page configuration |
| CVE-2026-80158 | 5.5 | 1.0 | Red Hat | Red Hat Ceph Storage 5 | CWE-214 | Ansible-collection-community-general: community.general: ipa_getkeytab does n… |
| CVE-2026-21808 | 4.1 | 1.0 | HCLSoftware | BigFix Quantum Risk Analyzer | CWE-532 | HCL BigFix Quantum Risk Analyzer is affected by logging sensitive information |
| CVE-2026-78236 | 8.8 | 0.7 | Admin By Request (ABR) | Admin By Request (ABR) | CWE-284 | Insecure PIN derivation mechanism in Admin By Request (ABR) |
| CVE-2026-21807 | 3.9 | 0.6 | HCLSoftware | BigFix Quantum Risk Analyzer | CWE-121 | HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow |
| CVE-2026-21809 | 3.9 | 0.5 | HCLSoftware | BigFix Quantum Risk Analyzer | CWE-209 | HCL BigFix Quantum Risk Analyzer is affected by generating error messages wit… |
| CVE-2026-54548 | 3.3 | 0.5 | siemens | kas | CWE-295 | kas: Persistent SSH Host Key Checking Disablement |
| CVE-2026-58093 | 7.0 | 0.5 | FreeBSD | FreeBSD | CWE-362 | Kernel use-after-free via tty ioctls |
| CVE-2026-47836 | 7.2 | 0.2 | Spring | Spring Cloud Config | — | Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN |
| CVE-2026-21810 | 4.4 | 0.1 | HCLSoftware | BigFix Quantum Risk Analyzer | CWE-494 | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource… |