| CVE-2026-39835 | 5.3 | 40.8 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-295 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto… |
| CVE-2026-46595 | 10.0 | 40.8 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-863 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org… |
| CVE-2026-42827 | 7.5 | 40.7 | Microsoft | Microsoft 365 Copilot | CWE-77 | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-40597 | 7.6 | 40.5 | mantisbt | mantisbt | CWE-79 | MantisBT has a Content Security Policy bypass via attachments |
| CVE-2026-47280 | 9.8 | 40.2 | Microsoft | Azure Resource Manager | CWE-287 | Azure Resource Manager Elevation of Privilege Vulnerability |
| CVE-2026-46727 | 8.1 | 39.2 | ruby-lang | Ruby | CWE-362 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a… |
| CVE-2026-33843 | 9.8 | 38.9 | Microsoft | Microsoft Entra | CWE-288 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability |
| CVE-2026-46597 | 7.5 | 38.9 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-704 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh |
| CVE-2026-39829 | 7.5 | 38.5 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-347 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto… |
| CVE-2026-9011 | 7.5 | 38.3 | metaphorcreations | Ditty – Responsive News Tickers, Sliders, and Lists | CWE-862 | Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Informat… |
| CVE-2026-40166 | 7.1 | 38.1 | goauthentik | authentik | CWE-200 | authentik: Non-admin user can retrieve confidential OAuth client_secret via /… |
| CVE-2026-40598 | 6.9 | 37.2 | mantisbt | mantisbt | CWE-79 | MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Up… |
| CVE-2026-35430 | 8.8 | 35.5 | Microsoft | Azure Privileged Identity Management (PIM) | CWE-639 | Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability |
| CVE-2026-36228 | 7.3 | 35.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacke… |
| CVE-2026-40596 | 7.2 | 35.4 | mantisbt | mantisbt | CWE-79 | MantisBT is vulnerable to XSS and potential account takeover via user font fa… |
| CVE-2026-41090 | 9.3 | 35.1 | Microsoft | Microsoft 365 Copilot for iOS | CWE-77 | Microsoft Copilot Tampering Vulnerability |
| CVE-2026-39831 | 9.1 | 35.1 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-862 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/… |
| CVE-2026-40607 | 7.5 | 34.9 | mantisbt | mantisbt | CWE-79 | MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column |
| CVE-2026-39833 | 9.1 | 34.4 | golang.org/x/crypto | golang.org/x/crypto/ssh/agent | CWE-862 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent |
| CVE-2026-46598 | 5.3 | 34.4 | golang.org/x/crypto | golang.org/x/crypto/ssh/agent | CWE-129 | Invoking pathological inputs can lead to client panic in golang.org/x/crypto/… |
| CVE-2026-41149 | 5.3 | 33.3 | mermaid-js | mermaid | CWE-94 | Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML … |
| CVE-2026-3294 | 8.7 | 33.0 | TP-Link Systems Inc. | Archer RE650 v1 | CWE-862 | Authentication Logic Vulnerability on Multiple TP-Link Range Extenders |
| CVE-2026-41076 | 8.1 | 32.3 | bestpractical | rt | CWE-287 | RT: LDAP authentication bypass via empty password |
| CVE-2026-9291 | 7.5 | 31.2 | AWS | Amazon Braket Python SDK | CWE-502 | Insecure Deserialization in Amazon Braket SDK Job Results Processing |
| CVE-2026-39828 | 6.3 | 30.0 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-295 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh |
| CVE-2026-41147 | 8.7 | 28.0 | nukeviet | nukeviet | CWE-79 | NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side … |
| CVE-2026-33712 | 10.0 | 27.7 | baptisteArno | typebot.io | CWE-862 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint … |
| CVE-2022-31231 | 7.5 | 27.6 | Dell | ECS | CWE-284 | Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Ide… |
| CVE-2026-41075 | 8.8 | 27.4 | bestpractical | rt | CWE-89 | RT: SQL injection via entry_aggregator parameter in JSON search |
| CVE-2026-5740 | 7.5 | 27.0 | Mattermost | Mattermost | CWE-789 | Unauthenticated WebSocket binary frame causes denial of service in Mattermost… |
| CVE-2026-41148 | 5.3 | 26.7 | mermaid-js | mermaid | CWE-94 | Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection |
| CVE-2026-25680 | 6.5 | 25.5 | golang.org/x/net | golang.org/x/net/html | CWE-400 | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html |
| CVE-2026-37470 | 7.3 | 25.2 | n/a | n/a | CWE-1021 | An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary cod… |
| CVE-2026-9047 | 7.6 | 24.6 | Devolutions | Server | CWE-305 | Improper handling of factor key state in the multi-factor authentication mana… |
| CVE-2026-28444 | 6.5 | 24.4 | baptisteArno | typebot.io | CWE-639 | Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure |
| CVE-2026-44618 | 5.3 | 22.9 | Apache Software Foundation | Apache CXF | CWE-611 | Apache CXF: XXE vulnerability in WS-Transfer functionality |
| CVE-2026-41071 | 5.1 | 22.7 | strukturag | libheif | CWE-125 | libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequen… |
| CVE-2026-42901 | 10.0 | 22.7 | Microsoft | Microsoft Entra | CWE-346 | Microsoft Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-5072 | 6.5 | 22.6 | zephyrproject-rtos | Zephyr | CWE-1335 | ptp: Potential Denial of Service via PTP Interval Shift |
| CVE-2026-32253 | 9.8 | 21.6 | LizardByte | Sunshine | CWE-287 | Sunshine: Authentication bypass via improper client certificate validation |
| CVE-2026-9054 | 9.2 | 21.7 | 9front | 9front | CWE-130 | Invalid IP packets cause a kernel panic |
| CVE-2026-40610 | 5.5 | 20.9 | bentoml | BentoML | CWE-59 | BentoML has Information Disclosure in `bentoml build` via symlink traversal i… |
| CVE-2026-39827 | 6.5 | 20.4 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-924 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/… |
| CVE-2026-8684 | 5.3 | 20.3 | jetmonsters | MotoPress Hotel Booking | CWE-862 | MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated A… |
| CVE-2026-39970 | 8.5 | 20.1 | baptisteArno | typebot.io | CWE-79 | TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Pic… |
| CVE-2026-9053 | 6.9 | 20.1 | 9front | 9front | CWE-434 | Mothra would respect a default value given by a website for HTML file upload … |
| CVE-2026-4834 | 7.5 | 19.7 | weDevs | WP ERP Pro | CWE-89 | WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter |
| CVE-2026-39968 | 7.1 | 19.3 | baptisteArno | typebot.io | CWE-284 | TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint |
| CVE-2026-6864 | 6.1 | 18.4 | manchumahara | CBX 5 Star Rating & Review | CWE-79 | CBX 5 Star Rating & Review <= 1.0.7 - Reflected Cross-Site Scripting via 'pag… |
| CVE-2026-28445 | 8.7 | 17.5 | baptisteArno | typebot.io | CWE-79 | Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in… |
| CVE-2026-39966 | 6.5 | 17.4 | baptisteArno | typebot.io | CWE-863 | TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTyp… |
| CVE-2026-36226 | 6.1 | 17.3 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.1… |
| CVE-2026-5308 | 7.5 | 17.1 | Mattermost | Mattermost | CWE-400 | Missing request body size limits on Zoom plugin HTTP endpoints |
| CVE-2026-41069 | 6.5 | 16.9 | strukturag | libheif | CWE-125 | libheif allows Out-of-bounds vector access leading to invalid dereference (DoS) |
| CVE-2026-4646 | 4.3 | 16.6 | Mattermost | Mattermost | CWE-1287 | Insufficient input validation in GitHub plugin API causes denial of service |
| CVE-2026-7509 | 6.4 | 16.6 | helgatheviking | KIA Subtitle | CWE-79 | KIA Subtitle <= 4.0.1 - [Improper Neutralization of Input During Web Page Gen… |
| CVE-2026-3481 | 6.1 | 16.5 | burlingtonbytes | WP Blockade – Visual Page Builder | CWE-79 | WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter |
| CVE-2026-8477 | 2.7 | 16.4 | Devolutions | Server | CWE-841 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data… |
| CVE-2026-7249 | 4.3 | 16.3 | shapedplugin | Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget | CWE-862 | Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contribut… |
| CVE-2022-34363 | 7.5 | 16.3 | Dell | Unisphere for PowerMax | CWE-285 | Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an autho… |
| CVE-2026-7325 | 7.1 | 16.2 | Devolutions | Server | CWE-918 | Improper authorization in the Active Directory browsing feature in Devolution… |
| CVE-2026-5755 | 6.5 | 16.0 | Mattermost | Mattermost | CWE-400 | Denial of service via crafted TIFF file upload |
| CVE-2026-40295 | 6.1 | 15.5 | heartcombo | devise | CWE-601 | Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Sessi… |
| CVE-2026-39964 | 5.4 | 15.5 | baptisteArno | typebot.io | CWE-79 | TypeBot: Stored XSS via javascript: URI in text bubble links — bot author exe… |
| CVE-2026-39965 | 7.7 | 15.2 | baptisteArno | typebot.io | CWE-918 | TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks |
| CVE-2026-34207 | 7.6 | 15.1 | baptisteArno | typebot.io | CWE-20 | TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP … |
| CVE-2026-7636 | 4.3 | 14.8 | smub | Slider by Soliloquy – Responsive Image Slider for WordPress | CWE-200 | Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclo… |
| CVE-2026-42506 | 6.1 | 14.7 | golang.org/x/net | golang.org/x/net/html | CWE-79 | Invoking incorrect handling of namespaced elements in foreign content in gola… |
| CVE-2026-5171 | 4.3 | 14.5 | Devolutions | Server | CWE-284 | Improper access control in the entry activity log feature in Devolutions Serv… |
| CVE-2026-9264 | 9.3 | 14.2 | Trimble | SketchUp | CWE-94 | Cross-Site Scripting in SketchUp Dynamic Components |
| CVE-2026-9245 | 5.0 | 14.0 | Devolutions | Server | CWE-601 | Improper input validation in the external authentication provider flow in Dev… |
| CVE-2026-2518 | 4.3 | 14.1 | wpxpo | FastX | CWE-862 | FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited… |
| CVE-2026-25606 | 8.7 | 13.3 | Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy | STER | CWE-89 | SQL Injection in STER |
| CVE-2026-8692 | 4.3 | 13.5 | registrationformbuilder | Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder | CWE-862 | Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+)… |
| CVE-2026-5817 | 8.8 | 13.3 | Docker | Docker Desktop | CWE-829 | Docker Model Runner container-to-host code execution via unsandboxed trust_re… |
| CVE-2026-5843 | 8.8 | 13.3 | Docker | Docker Desktop | CWE-829 | Docker Model Runner container-to-host code execution via MLX-LM model_file im… |
| CVE-2026-25681 | 6.1 | 13.2 | golang.org/x/net | golang.org/x/net/html | CWE-1021 | Invoking incorrect handling of character references in DOCTYPE nodes in golan… |
| CVE-2026-27136 | 6.1 | 13.2 | golang.org/x/net | golang.org/x/net/html | CWE-1021 | Invoking duplicate attributes can cause XSS in golang.org/x/net/html |
| CVE-2026-42502 | 6.1 | 13.2 | golang.org/x/net | golang.org/x/net/html | CWE-1021 | Invoking incorrect handling of HTML elements in foreign content in golang.org… |
| CVE-2026-9104 | 6.4 | 12.7 | dartiss | Draft List | CWE-79 | Draft List <= 2.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via… |
| CVE-2026-9247 | 2.4 | 12.6 | Devolutions | Server | CWE-778 | Insufficient logging in the entry export feature in Devolutions Server allows… |
| CVE-2026-8670 | 9.6 | 12.3 | syslink software AG | Avantra | CWE-613 | Insecure session handling on metrics web server |
| CVE-2026-8671 | 7.5 | 12.3 | syslink software AG | Avantra | CWE-532 | Log Files contain encrypted secrets |
| CVE-2026-44409 | 7.5 | 12.3 | ZTE | MU5250 | CWE-862 | Information disclosure vulnerability in ZTE MU5250 |
| CVE-2026-9223 | 4.3 | 11.9 | Devolutions | Server | CWE-284 | Missing authorization in the vault import feature in Devolutions Server 2026.… |
| CVE-2026-9224 | 4.3 | 11.9 | Devolutions | Server | CWE-862 | Missing authorization in the user profile update feature in Devolutions Serve… |
| CVE-2026-9246 | 4.3 | 11.9 | Devolutions | Server | CWE-862 | Improper access control in the entry documentation and attachment features in… |
| CVE-2026-6406 | 8.8 | 11.6 | Docker | Docker Desktop | CWE-863 | Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag |
| CVE-2026-25608 | 2.3 | 11.2 | Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy | STER | CWE-319 | Lack of traffic encryption in STER |
| CVE-2026-9251 | 5.4 | 9.4 | Devolutions | Server | CWE-862 | Missing authorization in the entry status management feature in Devolutions S… |
| CVE-2026-8673 | 9.1 | 9.2 | syslink software AG | Avantra | CWE-523 | Password re-initialization mechanism sends passwords in plain text |
| CVE-2026-9249 | 3.1 | 8.5 | Devolutions | Server | CWE-620 | Unverified password change in Devolutions Server allows an attacker to change… |
| CVE-2026-39967 | 3.1 | 8.5 | baptisteArno | typebot.io | CWE-639 | TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter |
| CVE-2026-9248 | 2.6 | 8.5 | Devolutions | Server | CWE-639 | Authorization bypass in the entry duplication feature in Devolutions Server a… |
| CVE-2026-3636 | 4.3 | 8.3 | Mattermost | Mattermost | CWE-200 | Sanitize team member data returned by API |
| CVE-2026-8347 | 2.3 | 7.3 | Concrete CMS | Concrete CMS | CWE-639 | Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-leve… |
| CVE-2025-26483 | 8.2 | 7.0 | Dell | PowerFlex Manager (Appliance) | CWE-601 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect V… |
| CVE-2026-4635 | 5.3 | 7.0 | Mattermost | Mattermost | CWE-362 | Persistent notification timing attack causing server denial of service |
| CVE-2026-7615 | 4.3 | 6.6 | kasparsd | Widget Context | CWE-352 | Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via '… |
| CVE-2026-41073 | 4.6 | 6.3 | bestpractical | rt | CWE-1236 | RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Ex… |
| CVE-2026-4070 | 4.3 | 6.0 | pftool | Alfie – Feed Plugin | CWE-352 | Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Par… |
| CVE-2026-42626 | 5.9 | 5.7 | n/a | n/a | CWE-400 | HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage co… |
| CVE-2026-40864 | 4.3 | 5.5 | jupyterhub | jupyterhub | CWE-352 | JupyterHub: Cross-origin form POSTs bypass XSRF |
| CVE-2026-3473 | 7.1 | 4.6 | Mattermost | Mattermost | CWE-639 | Improper file ownership validation in the Boards API allows unauthorised file… |
| CVE-2026-8353 | 2.1 | 4.6 | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name i… |
| CVE-2026-8381 | 5.4 | 3.9 | TeamViewer | DEX (On-premises) | CWE-862 | Broken Access Control in TeamViewer DEX Platform (On Premises) |
| CVE-2026-39969 | 6.5 | 3.9 | baptisteArno | typebot.io | CWE-287 | TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification |
| CVE-2026-8997 | 4.8 | 3.9 | vifm | vifm | CWE-122 | Heap Buffer Overflow in vifm |
| CVE-2026-28735 | 5.4 | 3.7 | Mattermost | Mattermost | CWE-863 | GitHub OAuth Scope Validation |
| CVE-2026-42627 | 6.2 | 3.2 | n/a | n/a | CWE-190 | In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumEl… |
| CVE-2025-32749 | 7.5 | 2.8 | Dell | PowerFlex Manager (Appliance) | CWE-276 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informa… |
| CVE-2026-9255 | 8.4 | 2.1 | AWS | Kiro CLI | CWE-862 | Tool Execution Without Authorization via Piped Stdin in Kiro CLI |
| CVE-2026-41074 | 7.1 | 1.9 | bestpractical | rt | CWE-352 | RT has broken CSRF protection for authenticated users |
| CVE-2021-21508 | 6.7 | 1.9 | Dell | VxRail | CWE-532 | Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vul… |
| CVE-2026-39824 | 3.3 | 1.7 | golang.org/x/sys | golang.org/x/sys/windows | CWE-190 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows |
| CVE-2026-8672 | 5.1 | 1.2 | syslink software AG | Avantra | CWE-1393 | Default credentials for internal DB |
| CVE-2025-32746 | 5.5 | 1.1 | Dell | PowerFlex Manager (Appliance) | CWE-922 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of… |
| CVE-2026-8340 | 2.3 | 1.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveV… |
| CVE-2025-32751 | 5.5 | 1.1 | Dell | PowerFlex Manager (Appliance) | CWE-922 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of… |
| CVE-2026-25607 | 5.7 | 0.8 | Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy | STER | CWE-261 | Weak password encoding in STER |
| CVE-2025-32747 | 7.8 | 0.5 | Dell | PowerFlex Manager (Appliance) | CWE-266 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege… |
| CVE-2025-32745 | 6.5 | 0.3 | Dell | PowerFlex Manager (Appliance) | CWE-295 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificat… |
| CVE-2025-46371 | 5.5 | 0.0 | Dell | PowerFlex Manager (Appliance) | CWE-327 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or R… |