| CVE-2026-43618 | 6.1 | 52.9 | RsyncProject | rsync | CWE-125 | Rsync < 3.4.3 Integer Overflow Information Disclosure |
| CVE-2026-42959 | 8.7 | 52.9 | NLnet Labs | Unbound | CWE-824 | Crash during DNSSEC validation of malicious content |
| CVE-2026-24217 | 8.8 | 52.4 | NVIDIA | BioNeMo Framework | CWE-29 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cau… |
| CVE-2026-24425 | 8.7 | 52.2 | twigphp | Twig | CWE-693 | Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface |
| CVE-2026-7522 | 8.8 | 52.1 | SigmaPlugin | Advanced Database Cleaner – Premium | CWE-98 | Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Lo… |
| CVE-2026-24214 | 9.8 | 50.8 | NVIDIA | Triton Inference Server | CWE-190 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend w… |
| CVE-2026-24213 | 9.8 | 50.8 | NVIDIA | Triton Inference Server | CWE-125 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend w… |
| CVE-2026-5950 | 5.3 | 48.6 | ISC | BIND 9 | CWE-606 | Unbounded resend loop in BIND 9 resolver |
| CVE-2026-24208 | 7.5 | 48.2 | NVIDIA | Triton Inference Server | CWE-22 | NVIDIA Triton Inference Server contains a vulnerability where an attacker cou… |
| CVE-2026-24209 | 7.5 | 48.2 | NVIDIA | Triton Inference Server | CWE-22 | NVIDIA Triton Inference Server contains a vulnerability where an attacker cou… |
| CVE-2026-39047 | 7.5 | 48.1 | n/a | n/a | CWE-121 | Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker… |
| CVE-2026-40092 | 7.5 | 47.1 | nimiq | core-rs-albatross | CWE-252 | nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify cau… |
| CVE-2026-44390 | 6.9 | 47.1 | NLnet Labs | Unbound | CWE-407 | Unbounded name compression in certain cases causes degradation of service |
| CVE-2026-41292 | 6.6 | 47.1 | NLnet Labs | Unbound | CWE-407 | Long list of incoming EDNS options degrades performance |
| CVE-2026-24210 | 7.5 | 46.0 | NVIDIA | Triton Inference Server | CWE-190 | NVIDIA Triton Inference Server contains a vulnerability where an attacker cou… |
| CVE-2026-24163 | 9.8 | 45.6 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, wher… |
| CVE-2026-33137 | 9.3 | 45.6 | xwiki | xwiki-platform | CWE-862 | XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName} |
| CVE-2026-24218 | 8.1 | 45.2 | NVIDIA | DGX Spark | CWE-321 | NVIDIA DGX OS contains a vulnerability in the factory provisioning process, w… |
| CVE-2026-42534 | 6.9 | 45.1 | NLnet Labs | Unbound | CWE-440 | Jostle logic bypass degrades resolution performance |
| CVE-2026-7637 | 9.8 | 44.6 | PixelYourSite | Boost | CWE-502 | Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_… |
| CVE-2025-33255 | 9.8 | 44.3 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where… |
| CVE-2026-9102 | 9.4 | 44.2 | Altium | Altium Enterprise Server | CWE-22 | Path Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary… |
| CVE-2026-47784 | 8.1 | 43.4 | memcached | memcached | CWE-208 | In memcached before 1.6.42, password data for SASL password database authenti… |
| CVE-2026-24206 | 9.8 | 43.4 | NVIDIA | Triton Inference Server | CWE-288 | NVIDIA Triton Inference Server contains a vulnerability where an attacker cou… |
| CVE-2026-9003 | 8.7 | 42.9 | TONNET | TPR7308 | CWE-89 | TONNET|E-LAN Hybrid Recording System - SQL Injection |
| CVE-2026-9119 | 8.8 | 42.8 | Google | Chrome | CWE-122 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 al… |
| CVE-2026-8469 | 8.2 | 42.7 | phenixdigital | phoenix_storybook | CWE-770 | Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_s… |
| CVE-2026-8598 | 9.1 | 41.0 | ZKTeco | SSC335-GC2063-Face-0b77 Solution Camera | CWE-288 | Unauthenticated Export Service in ZKTeco CCTV Cameras |
| CVE-2026-40165 | 8.7 | 40.7 | goauthentik | authentik | CWE-91 | authentik: SAML NameID XML Comment Injection Enables Authentication Bypass vi… |
| CVE-2026-9120 | 8.8 | 40.6 | Google | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a r… |
| CVE-2026-7284 | 9.8 | 40.2 | themewant | Easy Elements for Elementor – Addons & Website Templates | CWE-269 | Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation v… |
| CVE-2026-20239 | 6.5 | 39.6 | Splunk | Splunk Enterprise | CWE-532 | Sensitive Information Disclosure through Log Files in Splunk Enterprise |
| CVE-2026-9141 | 9.3 | 39.4 | Taiko Network Communications Pte Ltd. | AG1000-01A SMS Alert Gateway | CWE-306 | Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface |
| CVE-2026-6072 | 6.5 | 39.0 | oliverpos | Oliver POS – A WooCommerce Point of Sale (POS) | CWE-639 | Oliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Con… |
| CVE-2026-24160 | 7.5 | 38.5 | NVIDIA | TensorRT-LLM | CWE-690 | NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker co… |
| CVE-2026-20171 | 6.8 | 38.5 | Cisco | Cisco NX-OS Software | CWE-670 | Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vu… |
| CVE-2026-39850 | 7.4 | 37.7 | yiisoft | yii2 | CWE-20 | Yii 2: Local file inclusion via view parameter name collision |
| CVE-2026-9139 | 9.3 | 37.6 | Taiko Network Communications Pte Ltd. | AG1000-01A SMS Alert Gateway | CWE-798 | Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml |
| CVE-2026-35070 | 6.7 | 37.5 | Dell | SmartFabric Storage Software | CWE-77 | Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Impro… |
| CVE-2026-47068 | 2.3 | 37.3 | phenixdigital | phoenix_storybook | CWE-639 | Cross-session PubSub topic injection via URL parameter in phoenix_storybook |
| CVE-2026-7472 | 4.9 | 37.2 | edmonparker | Read More & Accordion | CWE-89 | Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection… |
| CVE-2026-9144 | 8.4 | 36.7 | Taiko Network Communications Pte Ltd. | AG1000-01A SMS Alert Gateway | CWE-79 | Taiko AG1000-01A Rev 7.3/8 Stored XSS via Web Configuration Interface |
| CVE-2026-20199 | 7.2 | 36.5 | Cisco | Cisco ThousandEyes Enterprise Agent | CWE-74 | A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual… |
| CVE-2026-43620 | 6.9 | 35.7 | RsyncProject | rsync | CWE-125 | Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files() |
| CVE-2026-20206 | 6.3 | 34.7 | Cisco | Cisco ThousandEyes Enterprise Agent | CWE-78 | Cisco ThousandEyes BrowserBot Command Injection Vulnerability |
| CVE-2026-24215 | 7.5 | 34.2 | NVIDIA | Triton Inference Server | CWE-400 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, … |
| CVE-2026-9101 | 5.3 | 34.3 | MongoDB, Inc. | Compass | CWE-1321 | Prototype pollution in csv parsing |
| CVE-2026-9150 | 6.5 | 34.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when… |
| CVE-2026-42834 | 7.8 | 34.0 | Microsoft | Windows Admin Center in Azure Portal | CWE-59 | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability |
| CVE-2026-3592 | 5.3 | 33.8 | ISC | BIND 9 | CWE-408 | Amplification vulnerabilities via self-pointed glue records |
| CVE-2026-3985 | 7.5 | 33.7 | constantcontact | Creative Mail – Easier WordPress & WooCommerce Email Marketing | CWE-89 | Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Una… |
| CVE-2026-47372 | 9.1 | 32.9 | RRWO | Crypt::SaltedHash | CWE-338 | Crypt::SaltedHash versions through 0.09 for Perl generate insecure random val… |
| CVE-2026-9112 | 8.8 | 32.8 | Google | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 all… |
| CVE-2026-9118 | 8.8 | 32.8 | Google | Chrome | CWE-416 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allo… |
| CVE-2026-9126 | 8.8 | 32.8 | Google | Chrome | CWE-416 | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a r… |
| CVE-2026-20240 | 6.5 | 32.8 | Splunk | Splunk Enterprise | CWE-20 | Denial of Service through coldToFrozen.sh Script in Splunk Enterprise |
| CVE-2026-8486 | 7.5 | 32.7 | Progress Software | MOVEit Automation | CWE-770 | Allocation of resources without limits or throttling vulnerability in Progres… |
| CVE-2026-47373 | 7.5 | 32.5 | RRWO | Crypt::SaltedHash | CWE-208 | Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing att… |
| CVE-2026-39310 | 8.6 | 32.3 | TriliumNext | Trilium | CWE-284 | Trilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) Bu… |
| CVE-2026-22314 | 9.0 | 31.8 | Mesalvo | Meona Client Launcher Component | CWE-94 | Improper Control of Generation of Code ('Code Injection') vulnerability in Me… |
| CVE-2026-6456 | 8.8 | 31.7 | beycanpress | Account Switcher | CWE-287 | Account Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass… |
| CVE-2026-24188 | 7.5 | 31.6 | NVIDIA | TensorRT | CWE-787 | NVIDIA TensorRT contains a vulnerability where an attacker could cause an out… |
| CVE-2026-24142 | 9.8 | 31.1 | NVIDIA | TensorRT-LLM | CWE-502 | NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and … |
| CVE-2026-44926 | 8.8 | 30.6 | n/a | n/a | CWE-284 | InfoScale CmdServer before 7.4.2 mishandles access control. |
| CVE-2026-9010 | 7.5 | 29.7 | PixelYourSite | Boost | CWE-89 | Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters |
| CVE-2026-9114 | 8.8 | 29.6 | Google | Chrome | CWE-416 | Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a … |
| CVE-2026-9137 | 5.1 | 29.6 | misp | misp | CWE-400 | CSP Report Endpoint Log Flooding in MISP via Incorrect Size Limit |
| CVE-2026-8488 | 7.5 | 29.5 | Progress Software | MOVEit Automation | CWE-770 | Allocation of resources without limits or throttling vulnerability in Progres… |
| CVE-2026-2812 | 5.3 | 29.1 | Esri | ArcGIS Server | CWE-287 | Improper Authentication issue in ArcGIS Server |
| CVE-2026-8685 | 6.5 | 28.9 | infility | Infility Global | CWE-89 | Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'o… |
| CVE-2026-47099 | 2.1 | 28.9 | storybookjs | telejson | CWE-79 | TeleJSON < 6.0.0 DOM-based XSS via parse() Function |
| CVE-2026-7467 | 8.8 | 28.7 | edmonparker | Read More & Accordion | CWE-269 | Read More & Accordion <= 3.5.7 - Privilege Escalation via importData |
| CVE-2025-32750 | 7.5 | 28.0 | Dell | PowerFlex Manager (Appliance) | CWE-548 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informa… |
| CVE-2026-22315 | 7.2 | 28.0 | Mesalvo | Meona Client Launcher Component | CWE-266 | Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher… |
| CVE-2026-8485 | 7.5 | 27.8 | Progress Software | MOVEit Automation | CWE-789 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Auto… |
| CVE-2026-9133 | 8.3 | 27.4 | AWS | RabbitMQ AWS | CWE-489 | Arbitrary file read in rabbitmq-aws plugin |
| CVE-2026-42923 | 6.9 | 26.8 | NLnet Labs | Unbound | CWE-407 | Degradation of service with unbounded NSEC3 hash calculations |
| CVE-2026-9065 | 9.3 | 26.7 | brainstormforce | Surecart | CWE-89 | Surecart - SQL Injection |
| CVE-2026-32792 | 4.6 | 26.6 | NLnet Labs | Unbound | CWE-125 | Packet of death with DNSCrypt |
| CVE-2026-9110 | 4.2 | 26.7 | Google | Chrome | CWE-451 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0… |
| CVE-2026-45232 | 2.1 | 26.7 | RsyncProject | rsync | CWE-193 | Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy |
| CVE-2026-5200 | 8.8 | 26.5 | acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | CWE-862 | AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) P… |
| CVE-2026-6728 | 5.3 | 26.0 | Revolution Slider | Slider Revolution | CWE-200 | Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure v… |
| CVE-2026-9121 | 8.8 | 25.9 | Google | Chrome | CWE-125 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed… |
| CVE-2026-7460 | 7.4 | 24.8 | mailcow | mailcow-dockerized | CWE-79 | mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped |
| CVE-2026-20238 | 6.5 | 24.8 | Splunk | Splunk AI Toolkit | CWE-863 | Improper Access Control through Role Inheritance in Splunk AI Toolkit app |
| CVE-2026-6394 | 5.4 | 24.3 | wpdive | Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | CWE-918 | Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via … |
| CVE-2026-9087 | 8.1 | 23.8 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-639 | Keycloak: cross-session email verification proof not bound to upstream identi… |
| CVE-2026-9149 | 6.5 | 23.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize f… |
| CVE-2026-44923 | 6.5 | 23.5 | n/a | n/a | CWE-89 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to esca… |
| CVE-2026-5293 | 6.4 | 23.5 | olivesystem | 診断ジェネレータ作成プラグイン | CWE-79 | 診断ジェネレータ作成プラグイン <= 1.4.16 - Authenticated (Subscriber+) Stored Cross-Site Scr… |
| CVE-2026-27405 | 6.5 | 23.3 | Magepeople inc. | WpBookingly | CWE-862 | WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability |
| CVE-2026-39405 | 9.4 | 22.9 | frappe | lms | CWE-22 | Frappe has Path Transversal via SCORM |
| CVE-2026-40094 | 4.3 | 22.8 | nimiq | core-rs-albatross | CWE-754 | nimiq-blockchain: network-libp2p untrusted peer can crash address book via em… |
| CVE-2026-2813 | 4.1 | 22.6 | Esri | ArcGIS Server | CWE-601 | Unvalidated Redirect in ArcGIS Server |
| CVE-2026-30691 | 6.1 | 22.4 | n/a | n/a | CWE-79 | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1… |
| CVE-2026-40102 | 6.5 | 22.1 | makeplane | plane | CWE-943 | Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics |
| CVE-2026-9100 | 6.0 | 22.0 | MongoDB, Inc. | C Driver | CWE-1285 | Heap memory out of bounds read and crash in C Driver legacy GridFS file reader |
| CVE-2026-8610 | 4.3 | 21.9 | conoha | TypeSquare Webfonts for ConoHa | CWE-862 | TypeSquare Webfonts for ConoHa <= 2.0.4 - Missing Authorization to Authentica… |
| CVE-2026-24216 | 7.8 | 21.4 | NVIDIA | BioNeMo Framework | CWE-502 | NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a … |
| CVE-2026-42383 | 7.6 | 21.4 | YITH | YITH WooCommerce Product Add-Ons | CWE-89 | WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection v… |
| CVE-2026-39311 | 6.8 | 21.2 | TriliumNext | Trilium | CWE-79 | Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) v… |
| CVE-2026-9059 | 9.3 | 21.2 | awesomemotive | NextGEN Gallery | CWE-89 | NextGEN Gallery - SQL Injection |
| CVE-2026-5075 | 4.3 | 21.0 | smub | All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic | CWE-200 | All in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information … |
| CVE-2026-45444 | 10.0 | 20.7 | WP Swings | Gift Cards For WooCommerce Pro | CWE-434 | WordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upl… |
| CVE-2026-43617 | 6.3 | 20.6 | RsyncProject | rsync | CWE-289 | Rsync < 3.4.3 Authorization Bypass via Hostname Resolution |
| CVE-2026-8487 | 7.5 | 20.5 | Progress Software | MOVEit Automation | CWE-276 | Incorrect default permissions vulnerability in Progress Software MOVEit Autom… |
| CVE-2026-7462 | 6.1 | 19.9 | vatanyazilim | VatanSMS WP SMS | CWE-79 | VatanSMS WP SMS <= 1.01 - Reflected Cross-Site Scripting via 'page' Parameter |
| CVE-2026-7385 | 5.8 | 19.3 | Unknown | Decent Comments | — | Decent Comments < 3.0.2 - Unauthenticated Email Address Disclosure |
| CVE-2026-4293 | 5.3 | 19.4 | Kieback & Peter | DDC4002 | CWE-79 | Kieback & Peter DDC Building Controllers Cross-site Scripting |
| CVE-2026-9122 | 6.5 | 19.1 | Google | Chrome | CWE-125 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 all… |
| CVE-2026-8624 | 6.1 | 18.8 | etspring | LJ comments import: reloaded | CWE-79 | LJ comments import: reloaded <= 0.97.1 - Reflected Cross-Site Scripting via P… |
| CVE-2026-8626 | 6.1 | 18.8 | owencutajar | SponsorMe | CWE-79 | SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter |
| CVE-2026-9117 | 7.5 | 18.5 | Google | Chrome | CWE-843 | Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778… |
| CVE-2026-21836 | 6.5 | 18.4 | HCLSoftware | DominoIQ | CWE-862 | HCL DominoIQ is affected by broken access control |
| CVE-2026-6566 | 4.3 | 18.4 | smub | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | CWE-639 | Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object… |
| CVE-2026-9057 | 8.2 | 17.9 | Talend | Talend Administration Center | — | Security fix for Qlik Talend Administration Center URL access control vulnera… |
| CVE-2026-9124 | 5.3 | 17.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Input in Google Chrome on prior… |
| CVE-2026-7613 | 7.2 | 17.3 | pixelyoursite | Cost of Goods by PixelYourSite | CWE-79 | Cost of Goods by PixelYourSite <= 1.2.12 - Unauthenticated Stored Cross-Site … |
| CVE-2026-44608 | 4.6 | 17.3 | NLnet Labs | Unbound | CWE-413 | Use after free and crash under special conditions in RPZ code |
| CVE-2026-5776 | 6.1 | 16.8 | Unknown | Email Encoder | — | Email Encoder < 2.4.7 - Unauthenticated Stored XSS |
| CVE-2026-42960 | 5.7 | 16.5 | NLnet Labs | Unbound | CWE-349 | Possible cache poisoning via promiscuous records for the authority section |
| CVE-2026-44392 | 5.3 | 16.5 | Six Apart Ltd. | Movable Type | CWE-862 | Missing authorization vulnerability exists in Movable Type. Under certain con… |
| CVE-2025-15369 | 5.3 | 16.4 | xpro | Xpro Addons — 140+ Widgets for Elementor | CWE-862 | Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 - Missing Authorization to … |
| CVE-2026-8038 | 6.4 | 16.0 | mcinvale | Faces of Users | CWE-79 | Faces of Users <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-6397 | 6.4 | 16.0 | cvmh | Sticky | CWE-79 | Sticky <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting vi… |
| CVE-2026-6549 | 6.4 | 16.0 | goback2 | Logo Manager For Enamad | CWE-79 | Logo Manager For Enamad <= 0.7.4 - Authenticated (Contributor+) Stored Cross-… |
| CVE-2026-26028 | 6.1 | 15.6 | cryptpad | cryptpad | CWE-79 | CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection a… |
| CVE-2026-9129 | 9.4 | 15.2 | Altium | Altium Enterprise Server | CWE-22 | Path Traversal in Altium Enterprise Server Viewer StorageController Allows Ar… |
| CVE-2026-6404 | 4.4 | 15.2 | simonholliday | Anomify AI – Anomaly Detection and Alerting | CWE-79 | Anomify AI <= 0.3.6 - Authenticated (Administrator+) Stored Cross-Site Script… |
| CVE-2026-39960 | 5.4 | 14.0 | mantisbt | mantisbt | CWE-79 | MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values |
| CVE-2026-6399 | 4.4 | 14.0 | yog2515 | General Options | CWE-79 | General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site S… |
| CVE-2026-9136 | 8.3 | 14.0 | misp | misp | CWE-639 | Unauthorized ShadowAttribute modification in MISP via client-supplied identifier |
| CVE-2026-35014 | 5.1 | 13.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter |
| CVE-2026-5783 | 7.6 | 13.5 | Beyaz Computer Software Design Industry and Trade Ltd. Co. | CityPLus | CWE-79 | Reflected XSS in Beyaz Computer's CityPLus |
| CVE-2026-9115 | 4.3 | 13.3 | Google | Chrome | CWE-693 | Insufficient policy enforcement in Service Worker in Google Chrome on prior t… |
| CVE-2026-2955 | 6.4 | 13.2 | wupsales | AI Chatbot & Workflow Automation by AIWU | CWE-79 | AI Chatbot & Workflow Automation by AIWU <= 1.4.14 - Unauthenticated Stored C… |
| CVE-2026-8627 | 6.1 | 12.9 | lykich | Correct Prices | CWE-79 | Correct Prices <= 1.0 - Reflected Cross-Site Scripting via PHP_SELF Parameter |
| CVE-2026-35007 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter |
| CVE-2026-35008 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter |
| CVE-2026-35009 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter |
| CVE-2026-35010 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter |
| CVE-2026-35011 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter |
| CVE-2026-35012 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter |
| CVE-2026-35013 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via street_view.php thelat and theln… |
| CVE-2026-35015 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Para… |
| CVE-2026-35016 | 5.1 | 12.9 | openises | tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter |
| CVE-2026-44933 | 8.5 | 12.7 | SUSE | SUSE Linux Enterprise | CWE-35 | Path Traversal in Plugin Loading in libzypp |
| CVE-2026-9113 | 4.3 | 12.5 | Google | Chrome | CWE-125 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 all… |
| CVE-2026-9116 | 4.3 | 12.5 | Google | Chrome | CWE-693 | Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to… |
| CVE-2026-44924 | 5.4 | 11.2 | n/a | n/a | CWE-79 | InfoScale VIOM 9.1.3 allows XSS. |
| CVE-2026-27424 | 4.3 | 11.0 | WP Chill | Image Photo Gallery Final Tiles Grid | CWE-862 | WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Broken Acce… |
| CVE-2026-22554 | 7.8 | 10.2 | MediaArea | MediaInfoLib | CWE-122 | MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerabi… |
| CVE-2026-44925 | 8.8 | 10.0 | n/a | n/a | CWE-352 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operatio… |
| CVE-2026-45443 | 5.0 | 9.5 | ADD-ONS.ORG | PDF for Elementor Forms + Drag And Drop Template Builder | CWE-862 | WordPress PDF for Elementor Forms + Drag And Drop Template Builder plugin <= … |
| CVE-2026-8419 | 4.3 | 9.1 | submone | Amazon Scraper | CWE-352 | Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scrip… |
| CVE-2026-9123 | 7.5 | 8.6 | Google | Chrome | CWE-122 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, Chrome… |
| CVE-2026-6401 | 4.3 | 8.6 | svil4ok | Bottom Bar | CWE-352 | Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-41054 | 7.8 | 8.3 | SUSE | Container suse/sle-micro-rancher/5.3:latest | CWE-305 | Missing exit out of permission check in haveged could lead to root exploit |
| CVE-2026-9084 | 6.0 | 8.1 | misp | misp | CWE-287 | MISP OIDC authentication bypass via automatic email-based account linking und… |
| CVE-2026-8423 | 4.3 | 7.7 | javibola | JaviBola Custom Theme Test | CWE-352 | JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery |
| CVE-2025-31973 | 9.8 | 7.6 | HCL | BigFix Service Management (SM) | CWE-1395 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insec… |
| CVE-2026-9056 | 5.4 | 7.7 | Talend | Talend Administration Center | — | Security fix for Qlik Talend Administration Center cross-site scripting vulne… |
| CVE-2026-6391 | 6.1 | 7.1 | eazyserver | Sentence To SEO (keywords, description and tags) | CWE-352 | Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request … |
| CVE-2026-8420 | 6.1 | 7.1 | rdbeach | BLOGCHAT Chat System | CWE-352 | BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-… |
| CVE-2026-6405 | 4.3 | 6.5 | simonholliday | Anomify AI – Anomaly Detection and Alerting | CWE-352 | Anomify AI <= 0.3.6 - Cross-Site Request Forgery |
| CVE-2025-11954 | 8.0 | 6.3 | Sitemio Information Technologies Trade Ltd. Co. | WISECP | CWE-352 | CSRF in Sitemio's WISECP |
| CVE-2026-24573 | 6.5 | 6.4 | Themeisle | Visualizer | CWE-79 | WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-6400 | 4.3 | 6.0 | helpstring | Child Height Predictor by Ostheimer | CWE-352 | Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Se… |
| CVE-2026-8418 | 4.3 | 6.0 | askywhale | Games Catalog | CWE-352 | Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post De… |
| CVE-2026-6452 | 4.3 | 5.5 | ktulhu | Bigfishgames Syndicate | CWE-352 | Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset … |
| CVE-2026-8424 | 4.3 | 5.5 | jay_patel | Remove Yellow BGBOX | CWE-352 | Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery |
| CVE-2025-31985 | 6.5 | 5.4 | HCL | BigFix Service Management (SM) | CWE-200 | HCL BigFix Service Management (SM) is affected by a security misconfiguration… |
| CVE-2026-6395 | 6.1 | 5.0 | winking | Word 2 Cash | CWE-352 | Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripti… |
| CVE-2026-29518 | 7.3 | 4.9 | RsyncProject | rsync | CWE-367 | Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write |
| CVE-2023-7346 | 4.1 | 3.9 | Ledger | Ledger Bitcoin app | CWE-682 | Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript |
| CVE-2026-43619 | 7.2 | 3.5 | RsyncProject | rsync | CWE-59 | Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls |
| CVE-2026-40622 | 6.6 | 3.5 | NLnet Labs | Unbound | CWE-346 | Another 'ghost domain names' attack variant |
| CVE-2026-47782 | 4.6 | 3.2 | Siber Systems, Inc. | Android App "RoboForm Password Manager" | CWE-357 | Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handl… |
| CVE-2026-0856 | 7.8 | 2.7 | Mesalvo | Meona Client Launcher Component | CWE-284 | Improper Access Control vulnerability in Mesalvo Meona Client Launcher Compon… |
| CVE-2026-0857 | 6.0 | 1.0 | Mesalvo | Meona Client Launcher Component | CWE-316 | Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo… |
| CVE-2026-25602 | 4.4 | 0.5 | Mesalvo | Meona Client Launcher Component | CWE-345 | Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona… |