| CVE-2026-48689 | 9.8 | 49.3 | n/a | n/a | CWE-787 | FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based … |
| CVE-2026-24212 | 9.8 | 48.4 | NVIDIA | Isaac Launchable | CWE-319 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive in… |
| CVE-2026-42425 | 8.6 | 47.8 | Openkm | OpenKM Community Edition | CWE-89 | OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery |
| CVE-2026-7374 | 9.9 | 45.7 | Red Hat | Red Hat Container Native Virtualization 4.12 | CWE-59 | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via… |
| CVE-2026-3660 | 9.8 | 44.9 | IBM | Engineering Lifecycle Management | CWE-863 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authe… |
| CVE-2026-9560 | 9.4 | 44.7 | OpenVPN Inc | OpenVPN Connect | CWE-78 | Privilege escalation via background service of OpenVPN Connect 3.5.1 through … |
| CVE-2026-48686 | 9.8 | 44.2 | n/a | n/a | CWE-120 | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer over… |
| CVE-2026-44209 | 7.5 | 42.9 | masci | banks | CWE-1336 | Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI |
| CVE-2026-41401 | 7.1 | 41.7 | libyang | libyang | CWE-416 | libyang - Heap Use-After-Free Write in XML Metadata Parsing |
| CVE-2026-9550 | 5.5 | 41.7 | Acrel Electrical | EEMS Enterprise Power Operation and Maintenance Cloud Platform | CWE-22 | Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platfo… |
| CVE-2026-44966 | 9.8 | 40.9 | shepherdwind | velocity.js | CWE-1321 | Velocity.js: Prototype Pollution in #set path assignment |
| CVE-2026-40383 | 7.5 | 40.6 | Joomla! Project | Joomla! CMS | CWE-22 | Joomla! Core - [20260509] - LFI in HTMLView layout parameter |
| CVE-2026-48592 | 5.3 | 40.6 | oban-bg | oban_web | CWE-862 | Missing authorization check on save-job event handler in oban_web |
| CVE-2026-7251 | 9.3 | 40.5 | Eppendorf | BioFlo 320 | CWE-259 | Eppendorf BioFlo 320 Use of hard-coded password |
| CVE-2026-8890 | 8.8 | 40.0 | code100x | code100x | CWE-639 | code100x Mobile API Authentication Bypass via Header Spoofing |
| CVE-2026-40564 | 6.5 | 40.0 | Apache Software Foundation | Apache Flink Kubernetes Operator | CWE-552 | Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file … |
| CVE-2026-9170 | 9.8 | 39.9 | IBM | HTTP Server | CWE-94 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-46624 | 9.9 | 39.5 | twentyhq | twenty | CWE-78 | Twenty: SQL Injection via the timeZone field |
| CVE-2026-44723 | 9.9 | 38.6 | VowpalWabbit | vowpal_wabbit | CWE-78 | Vowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allo… |
| CVE-2026-8855 | 9.8 | 37.8 | IBM | HTTP Server | CWE-94 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-44449 | 9.1 | 37.5 | prolix-oc | Lumiverse | CWE-88 | Lumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape |
| CVE-2026-9538 | 7.5 | 37.3 | BINGOS | Archive::Tar | CWE-789 | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attack… |
| CVE-2026-8047 | 8.7 | 37.0 | CODESYS | CODESYS Control RTE (SL) | CWE-1284 | Out-of-bounds Write in CODESYS Control |
| CVE-2026-40384 | 5.9 | 37.0 | Joomla! Project | Joomla! CMS | CWE-22 | Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint |
| CVE-2026-45721 | 9.0 | 36.4 | xyproto | algernon | CWE-20 | Algernon: handler.lua discovery walks parent directories above the server root |
| CVE-2026-42496 | 9.1 | 35.8 | BINGOS | Archive::Tar | CWE-59 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker con… |
| CVE-2026-9540 | 5.5 | 35.6 | vllm-project | vllm | CWE-404 | vllm-project vllm OpenAI-compatible Serving Path denial of service |
| CVE-2026-42013 | 8.2 | 35.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-295 | Gnutls: gnutls: certificate validation bypass due to oversized subject altern… |
| CVE-2026-39661 | 7.5 | 34.8 | Magentech | SW Core | CWE-98 | WordPress SW Core plugin <= 1.7.18 - Local File Inclusion vulnerability |
| CVE-2026-42497 | 7.5 | 34.8 | BINGOS | Archive::Tar | CWE-59 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker cont… |
| CVE-2026-48593 | 5.9 | 34.8 | oban-bg | oban_web | CWE-400 | Unbounded range expansion in cron describe causes memory exhaustion in oban_web |
| CVE-2026-24162 | 7.8 | 34.7 | NVIDIA | Merlin Transformers4Rec | CWE-502 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker … |
| CVE-2026-44837 | 7.5 | 34.3 | ViewComponent | view_component | CWE-187 | view_component: System Test Entry Point Path Check Allows Sibling Directory E… |
| CVE-2026-44843 | 8.2 | 33.8 | langchain-ai | langchain | CWE-502 | LangChain: Unsafe deserialization of attacker-controlled LangChain objects th… |
| CVE-2026-9521 | 2.9 | 33.3 | fraillt | bitsery | CWE-20 | fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of sp… |
| CVE-2026-44844 | 6.3 | 32.8 | GOVCERT-LU | eml_parser | CWE-674 | eml_parser: Recursion DoS via nested message/rfc822 attachments |
| CVE-2026-44895 | 9.2 | 32.4 | yoda-digital | mcp-gitlab-server | CWE-306 | GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exp… |
| CVE-2026-9517 | 5.5 | 32.1 | hemant6488 | CodeIgniter-StudentManagementSystem | CWE-266 | hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentV… |
| CVE-2026-41917 | 6.9 | 31.9 | Openkm | OpenKM Community Edition | CWE-22 | OpenKM 6.3.12 Local File Inclusion via Admin Scripting |
| CVE-2026-8606 | 7.0 | 31.8 | GitHub | Enterprise Server | CWE-918 | Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package … |
| CVE-2026-8850 | 7.5 | 31.1 | IBM | HTTP Server | CWE-476 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-44450 | 9.9 | 30.8 | prolix-oc | Lumiverse | CWE-88 | Lumiverse: RCE via MCP stdio argument injection |
| CVE-2026-8174 | 5.7 | 30.2 | Zohocorp | Zoho Mail wordpress plugin | CWE-352 | Cross-site Request Forgery |
| CVE-2026-44444 | 9.1 | 30.1 | prolix-oc | Lumiverse | CWE-78 | Lumiverse: Spindle extension install runs untrusted lifecycle scripts before … |
| CVE-2026-4051 | 7.2 | 29.9 | IBM | Engineering Lifecycle Management | CWE-749 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Serve… |
| CVE-2026-44668 | 9.8 | 29.5 | factionsecurity | faction | CWE-306 | Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates |
| CVE-2026-2264 | 9.2 | 29.0 | Google Cloud | Apigee-X | CWE-918 | Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apige… |
| CVE-2026-9495 | 5.5 | 29.1 | n/a | @koa/router | CWE-284 | Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnera… |
| CVE-2026-8854 | 7.5 | 29.0 | IBM | HTTP Server | CWE-825 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-3603 | 7.1 | 28.6 | IBM | Engineering Lifecycle Management | CWE-611 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML e… |
| CVE-2026-42012 | 7.1 | 28.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-295 | Gnutls: gnutls: certificate validation bypass due to improper handling of uri… |
| CVE-2026-40034 | 8.5 | 28.2 | gitoxide | gitoxide | CWE-77 | gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule |
| CVE-2026-35223 | 8.6 | 27.8 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260508] - Improper access check in com_config webservice en… |
| CVE-2026-8046 | 7.2 | 27.8 | CODESYS | CODESYS Control RTE (SL) | CWE-863 | Incorrect Authorization in CODESYS Control |
| CVE-2026-9496 | 7.7 | 27.6 | n/a | pacote | CWE-1333 | Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable t… |
| CVE-2026-43982 | 8.7 | 27.4 | xyproto | algernon | CWE-22 | Algernon: Path traversal file write via savein() |
| CVE-2026-44707 | 6.8 | 27.4 | chatwoot | chatwoot | CWE-283 | Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts |
| CVE-2026-44836 | 6.5 | 27.3 | ViewComponent | view_component | CWE-749 | view_component: Preview Route Can Dispatch Inherited Helper Methods |
| CVE-2026-9605 | 5.5 | 26.9 | GNU | libredwg | CWE-119 | GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow |
| CVE-2026-9518 | 2.1 | 26.5 | hemant6488 | CodeIgniter-StudentManagementSystem | CWE-79 | hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_stude… |
| CVE-2026-9519 | 2.1 | 26.5 | stonith404 | pingvin-share | CWE-79 | stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps … |
| CVE-2026-9520 | 2.1 | 26.5 | blitz-js | blitz | CWE-79 | blitz-js blitz Sign-in LoginForm.tsx cross site scripting |
| CVE-2026-9527 | 2.1 | 26.5 | itsourcecode | Electronic Judging System | CWE-79 | itsourcecode Electronic Judging System judges.php cross site scripting |
| CVE-2026-48126 | 8.2 | 26.4 | xyproto | algernon | CWE-22 | Algernon: Host header path traversal in --domain mode reads files and runs Lu… |
| CVE-2026-48683 | 6.5 | 26.0 | n/a | n/a | CWE-125 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vul… |
| CVE-2026-9523 | 5.5 | 25.8 | Acrel Electrical | EEMS Enterprise Power Operation and Maintenance Cloud Platform | CWE-74 | Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platfo… |
| CVE-2026-46740 | 5.3 | 25.4 | RRWO | Mojolicious::Plugin::Statsd | CWE-93 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric inj… |
| CVE-2026-9603 | 5.5 | 25.4 | SourceCodester | eDoc Doctor Appointment System | CWE-862 | SourceCodester eDoc Doctor Appointment System delete-session.php authorization |
| CVE-2025-11482 | 8.7 | 24.9 | B&R Industrial Automation GmbH | PPT30 Operating System | CWE-770 | Allocation of Resources Without Limits or Throttling in the OPC-UA Server |
| CVE-2026-35221 | 6.9 | 25.0 | Joomla! Project | Joomla! CMS | CWE-89 | Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder |
| CVE-2026-9525 | 5.5 | 24.7 | itsourcecode | Electronic Judging System | CWE-74 | itsourcecode Electronic Judging System edit_judge.php sql injection |
| CVE-2026-9526 | 5.5 | 24.7 | itsourcecode | Electronic Judging System | CWE-74 | itsourcecode Electronic Judging System edit_team.php sql injection |
| CVE-2026-9528 | 5.5 | 24.7 | itsourcecode | Electronic Judging System | CWE-74 | itsourcecode Electronic Judging System delete_judge.php sql injection |
| CVE-2026-9551 | 5.5 | 24.6 | Das | Parking Management System 停车场管理系统 | CWE-74 | Das Parking Management System 停车场管理系统 API Endpoint ExportParkingRecords xp_cm… |
| CVE-2026-9552 | 5.5 | 24.6 | Das | Parking Management System 停车场管理系统 | CWE-74 | Das Parking Management System 停车场管理系统 Search API Endpoint sql injection |
| CVE-2026-44730 | 7.2 | 24.4 | OpenCTI-Platform | opencti | CWE-284 | OpenCTI: Privilege escalation via graphQL API abusable by organization admins… |
| CVE-2026-44832 | 8.7 | 24.2 | grokability | snipe-it | CWE-281 | Snipe-IT: Privilege Escalation via API Permissions Assignment |
| CVE-2026-44788 | 6.5 | 24.0 | adamhathcock | sharpcompress | CWE-22 | SharpCompress: Directory traversal via directory entries in WriteToDirectory … |
| CVE-2025-36220 | 9.8 | 23.6 | IBM | Cloud Pak for Data System - Cyclops | CWE-89 | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2026-35222 | 6.9 | 23.7 | Joomla! Project | Joomla! CMS | CWE-89 | Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags |
| CVE-2026-48691 | 9.8 | 23.4 | n/a | n/a | CWE-190 | FastNetMon Community Edition through 1.2.9 contains an integer overflow in th… |
| CVE-2026-45728 | 7.5 | 22.8 | xyproto | algernon | CWE-209 | Algernon: Single-file mode unconditionally enables debug mode |
| CVE-2026-45082 | 7.6 | 22.6 | karakeep-app | karakeep | CWE-918 | Karakeep has a SSRF Protection Bypass via Redirect Handling |
| CVE-2026-48896 | 8.2 | 22.2 | Joomla! Project | Joomla! CMS | CWE-287 | Joomla! Core - [20260511] - MFA Authentication Bypass |
| CVE-2026-43935 | 8.1 | 22.3 | e107inc | e107 | CWE-20 | e107: Host Header Injection in e107 password reset enables phishing |
| CVE-2026-48685 | 6.5 | 22.1 | n/a | n/a | CWE-130 | FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access be… |
| CVE-2026-48904 | 8.2 | 21.7 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260514] - Privilege escalation through com_users webservice… |
| CVE-2026-9580 | 5.5 | 21.6 | n/a | JeecgBoot | CWE-266 | JeecgBoot selectDepart LoginController.selectDepart access control |
| CVE-2026-9562 | 5.5 | 21.3 | sambitraj | STUDENT-MANAGEMENT-SYSTEM | CWE-266 | sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control |
| CVE-2026-44502 | 4.3 | 21.1 | bugsink | bugsink | CWE-918 | Bugsink: SSRF bypass in `validate_webhook_url` |
| CVE-2026-48688 | 7.5 | 20.8 | n/a | n/a | CWE-125 | FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds re… |
| CVE-2026-9566 | 2.1 | 20.7 | teableio | teable | CWE-79 | teableio teable Sign-up LoginPage.tsx cross site scripting |
| CVE-2026-44775 | 6.9 | 20.5 | Kareadita | Kavita | CWE-306 | Kavita: No authentication at /api/Reader/image |
| CVE-2026-8620 | 7.5 | 20.4 | IBM | Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty | CWE-444 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-44214 | 5.3 | 20.1 | rexxars | eventsource-encoder | CWE-93 | eventsource-encoder: SSE event injection via unsanitized event and id fields |
| CVE-2026-44847 | 7.5 | 19.3 | 1Panel-dev | MaxKB | CWE-287 | MaxKB: Webhook Trigger Authentication Bypass |
| CVE-2025-36221 | 7.5 | 19.1 | IBM | Cloud Pak for Data System - Cyclops | CWE-1392 | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2026-48898 | 8.2 | 19.0 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260513] - Privilege escalation through com_users batch task |
| CVE-2026-48684 | 6.5 | 18.4 | n/a | n/a | CWE-125 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in … |
| CVE-2025-71310 | 1.8 | 18.4 | BackdropCMS | GDPR cookies module for Backdrop CMS | CWE-80 | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficien… |
| CVE-2026-8834 | 8.0 | 17.8 | IBM | HTTP Server | CWE-122 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-9544 | 5.5 | 17.8 | Shenzhen Sixun Software | Sixun Shanghui Group Business Management System | CWE-74 | Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayCo… |
| CVE-2026-9573 | 5.5 | 17.8 | itsourcecode | Student Transcript Processing System | CWE-74 | itsourcecode Student Transcript Processing System index.php sql injection |
| CVE-2026-9574 | 5.5 | 17.8 | itsourcecode | Student Transcript Processing System | CWE-74 | itsourcecode Student Transcript Processing System trans.php sql injection |
| CVE-2026-9575 | 5.5 | 17.8 | itsourcecode | Student Transcript Processing System | CWE-74 | itsourcecode Student Transcript Processing System index.php sql injection |
| CVE-2026-44729 | 8.7 | 17.6 | twentyhq | twenty | CWE-79 | Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Con… |
| CVE-2026-44749 | 4.3 | 17.6 | SAP_SE | SAP Gateway | CWE-497 | Information Disclosure vulnerability in SAP Gateway |
| CVE-2026-39642 | 5.3 | 17.3 | SpabRice | Nyla | CWE-80 | WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability |
| CVE-2026-9584 | 5.5 | 17.1 | code-projects | Project Management System | CWE-74 | code-projects Project Management System Login chk.php sql injection |
| CVE-2026-9606 | 5.5 | 17.1 | itsourcecode | Courier Management System | CWE-74 | itsourcecode Courier Management System manage_user.php sql injection |
| CVE-2026-48902 | 9.8 | 16.8 | Joomla! Project | Joomla! CMS | CWE-319 | Joomla! Core - [20260518] - Transport encryption downgrade for password and u… |
| CVE-2026-8835 | 7.3 | 16.9 | IBM | HTTP Server | CWE-822 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-44776 | 5.9 | 16.7 | Kareadita | Kavita | CWE-639 | Kavita: IDOR in /api/Download/* |
| CVE-2025-14361 | 7.1 | 16.3 | AA-Team | Woocommerce Envato Affiliates | CWE-862 | WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Settings Change vul… |
| CVE-2026-36239 | 4.3 | 16.3 | n/a | n/a | CWE-79 | PbootCMS v.3.2.11 contains a code injection vulnerability in its site configu… |
| CVE-2026-9524 | 5.3 | 16.1 | xianrendzw | EasyReport | CWE-74 | xianrendzw EasyReport REST Endpoint execute sql injection |
| CVE-2026-24590 | 5.3 | 16.1 | VideoWhisper.com | Paid Videochat Turnkey Site | CWE-862 | WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Broken Access Contro… |
| CVE-2026-48901 | 7.5 | 16.0 | Joomla! Project | Joomla! CMS | CWE-524 | Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter … |
| CVE-2026-9583 | 2.1 | 15.6 | SourceCodester | CET Automated Grading System with AI Predictive Analytics | CWE-200 | SourceCodester CET Automated Grading System with AI Predictive Analytics SQL … |
| CVE-2026-48694 | 8.1 | 14.5 | n/a | n/a | CWE-77 | FastNetMon Community Edition through 1.2.9 contains a configuration injection… |
| CVE-2026-4795 | 6.5 | 14.5 | Zyxel | GS1200-5v3 firmware | CWE-862 | A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions t… |
| CVE-2026-48899 | 5.3 | 14.6 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins |
| CVE-2026-48692 | 8.1 | 14.4 | n/a | n/a | CWE-306 | FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port … |
| CVE-2026-42335 | 6.3 | 14.3 | 1Panel-dev | MaxKB | CWE-918 | MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy |
| CVE-2026-39655 | 5.3 | 14.2 | TeconceTheme | Mayosis Core | CWE-862 | WordPress Mayosis Core plugin <= 5.4.7 - Broken Access Control vulnerability |
| CVE-2026-44451 | 9.3 | 14.0 | prolix-oc | Lumiverse | CWE-693 | Lumiverse: TSX component sandbox escape via DOM ref and string-split identifi… |
| CVE-2026-44708 | 6.1 | 13.8 | lepture | mistune | CWE-79 | Mistune Math Plugin XSS Escape Bypass |
| CVE-2026-44897 | 6.1 | 13.8 | lepture | mistune | CWE-79 | Mistune Heading ID Attribute Injection XSS |
| CVE-2026-44898 | 6.1 | 13.8 | lepture | mistune | CWE-79 | Mistune TOC Anchor Injection XSS |
| CVE-2026-44899 | 6.1 | 13.8 | lepture | mistune | CWE-79 | Mistune Image Directive CSS Injection Vulnerability |
| CVE-2026-44706 | 8.5 | 13.6 | chatwoot | chatwoot | CWE-89 | Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribu… |
| CVE-2026-48864 | 7.8 | 13.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompre… |
| CVE-2026-8647 | 4.8 | 13.0 | MIK | Crypt::ScryptKDF | CWE-338 | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number … |
| CVE-2026-9604 | 2.1 | 13.0 | n/a | JeecgBoot | CWE-266 | JeecgBoot AiragModelController access control |
| CVE-2026-24190 | 7.8 | 12.9 | NVIDIA | GeForce | CWE-862 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in the k… |
| CVE-2026-38587 | 4.3 | 12.9 | n/a | n/a | CWE-639 | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ON… |
| CVE-2026-46431 | 4.3 | 12.6 | xyproto | algernon | CWE-942 | Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * |
| CVE-2026-9568 | 2.3 | 12.6 | n/a | ThingsBoard | CWE-74 | ThingsBoard YAML provision getGatewayDockerComposeFile code injection |
| CVE-2026-44831 | 5.4 | 12.5 | grokability | snipe-it | CWE-79 | Snipe-IT: XSS vulnerability in component notes |
| CVE-2026-24638 | 4.3 | 12.4 | Webful Creations | RepairBuddy | CWE-862 | WordPress RepairBuddy plugin <= 4.1121 - Broken Access Control vulnerability |
| CVE-2026-44667 | 8.7 | 11.6 | factionsecurity | faction | CWE-79 | Faction: Stored XSS in Remediation Verification Attachment Filename Preview R… |
| CVE-2026-44669 | 8.7 | 11.6 | factionsecurity | faction | CWE-79 | Faction: Stored XSS in Assessment Attachment Filename Preview Rendering |
| CVE-2026-48897 | 8.2 | 11.7 | Joomla! Project | Joomla! CMS | CWE-287 | Joomla! Core - [20260512] - MFA Authentication Bypass |
| CVE-2026-9579 | 2.1 | 11.4 | n/a | JeecgBoot | CWE-266 | JeecgBoot SysUser userEdit user.getUsername access control |
| CVE-2026-9581 | 2.1 | 11.4 | n/a | JeecgBoot | CWE-266 | JeecgBoot add access control |
| CVE-2026-25104 | 7.8 | 11.0 | MediaArea | MediaInfoLib | CWE-191 | MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability |
| CVE-2026-25713 | 7.8 | 11.0 | MediaArea | MediaInfoLib | CWE-122 | MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability |
| CVE-2026-44213 | 6.5 | 11.1 | open-telemetry | opentelemetry-dotnet-contrib | CWE-295 | OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a pro… |
| CVE-2026-45412 | 6.3 | 11.1 | 1Panel-dev | MaxKB | CWE-918 | MaxKB: Unauthenticated SSRF via Workflow Template Import |
| CVE-2026-42337 | 5.3 | 11.1 | 1Panel-dev | MaxKB | CWE-862 | MaxKB: Broken Access Control in MaxKB OSS URL Fetch API |
| CVE-2026-24192 | 7.8 | 10.9 | NVIDIA | GeForce | CWE-681 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker co… |
| CVE-2026-8676 | 8.8 | 10.5 | silabs.com | Simplicity SDK | CWE-290 | An attacker is able to downgrade the security of a Bluetooth LE connection by… |
| CVE-2026-44905 | 7.5 | 10.5 | riebl | vanetza | CWE-248 | Vanetza: Remote Denial of Service via Uncaught OER Encoding Exception in Cryp… |
| CVE-2026-9564 | 1.9 | 10.4 | SourceCodester | Hospitals Patient Records Management System | CWE-79 | SourceCodester/oretnom23 Hospitals Patient Records Management System view_pat… |
| CVE-2026-44896 | 5.3 | 10.0 | lepture | mistune | CWE-79 | Mistune: XSS via unescaped figclass/figwidth in Figure directive |
| CVE-2026-8856 | 9.1 | 9.7 | IBM | HTTP Server | CWE-400 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-24193 | 7.8 | 9.9 | NVIDIA | GeForce | CWE-787 | NVIDIA Display Driver for Windows and Linux contains a vulnerability where an… |
| CVE-2026-8852 | 7.5 | 9.8 | IBM | HTTP Server | CWE-617 | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-46430 | 4.3 | 9.8 | xyproto | algernon | CWE-668 | Algernon: Auto-refresh SSE event server binds to all interfaces by default on… |
| CVE-2026-42448 | 3.5 | 9.7 | magic-wormhole | magic-wormhole | CWE-22 | wormhole receive, with --output pointing at an existing directory can be path… |
| CVE-2026-9542 | 2.1 | 9.7 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System add_staff.php sql injection |
| CVE-2026-44985 | 8.7 | 9.6 | amir20 | dozzle | CWE-346 | Dozzle: Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpoints bypas… |
| CVE-2025-36148 | 6.1 | 9.3 | IBM | Financial Transaction Manager for SWIFT Services for Multiplatforms | CWE-79 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vu… |
| CVE-2026-43936 | 4.3 | 9.3 | e107inc | e107 | CWE-918 | e107: Server-Side Request Forgery (SSRF) in the remote file fetcher |
| CVE-2026-25426 | 5.3 | 9.1 | Magepeople inc. | Taxi Booking Manager for WooCommerce | CWE-862 | WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.1 - Broken Acces… |
| CVE-2025-68708 | 2.4 | 8.9 | n/a | n/a | CWE-288 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local a… |
| CVE-2026-24187 | 8.8 | 8.7 | NVIDIA | GeForce | CWE-416 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker co… |
| CVE-2026-42336 | 5.1 | 8.6 | 1Panel-dev | MaxKB | CWE-367 | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch |
| CVE-2025-68711 | 2.4 | 8.5 | n/a | n/a | CWE-288 | AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz)… |
| CVE-2025-36126 | 7.6 | 8.3 | IBM | Cognos Analytics | CWE-79 | IBM Cognos Analytics is affected by Cross-site scripting. |
| CVE-2026-44314 | 5.3 | 8.4 | traccar | traccar | CWE-863 | Traccar: Missing edit authorization on device image upload allows read-only u… |
| CVE-2026-43988 | 7.5 | 8.2 | riebl | vanetza | CWE-248 | Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing |
| CVE-2026-43981 | 8.2 | 8.1 | xyproto | algernon | CWE-362 | Algernon: Race Condition in handle() shared LState |
| CVE-2026-25900 | 6.9 | 8.0 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260501] - XSS in feed modules |
| CVE-2026-30894 | 6.9 | 8.0 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260503] - XSS in com_contenthistory |
| CVE-2025-14290 | 5.4 | 8.1 | IBM | webMethods Integration (on prem) -Integration Server | CWE-918 | IBM webMethods Integration Sever is vulnerable to server-side request forgery |
| CVE-2026-44903 | 5.1 | 8.1 | prometheus | prometheus | CWE-79 | Prometheus: Stored XSS via crafted histogram bucket label values in the heatm… |
| CVE-2026-43934 | 6.5 | 8.0 | e107inc | e107 | CWE-284 | e107: Broken Access Control in e107 comment edit allows cross-user comment mo… |
| CVE-2025-68710 | 2.4 | 7.7 | n/a | n/a | CWE-288 | Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9… |
| CVE-2026-47728 | 4.3 | 7.6 | bugsink | bugsink | CWE-862 | Bugsink: Project scoping missing in sourcemap and debug-file lookup |
| CVE-2025-68709 | 5.2 | 7.5 | n/a | n/a | CWE-79 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local a… |
| CVE-2026-25901 | 6.9 | 7.3 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260502] - XSS in com_associations |
| CVE-2026-30895 | 6.9 | 7.3 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260504] - XSS in readmore links |
| CVE-2025-33221 | 6.0 | 7.3 | NVIDIA | GeForce | CWE-20 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in the k… |
| CVE-2026-3314 | 4.6 | 7.3 | Hitachi | Hitachi Ops Center Analyzer | CWE-549 | Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi… |
| CVE-2026-47202 | 9.3 | 6.8 | Kareadita | Kavita | CWE-287 | Kavita: Pre-Auth Account Takeover |
| CVE-2026-27427 | 6.5 | 6.9 | Dylan Kuhn | Geo Mashup | CWE-79 | WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-8479 | 6.9 | 6.7 | Hitachi Energy | RTU500 series CMU firmware | CWE-476 | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL… |
| CVE-2026-9541 | 1.9 | 6.7 | n/a | Squirrel | CWE-119 | Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow |
| CVE-2026-24200 | 7.0 | 6.5 | NVIDIA | Virtual GPU Manager | CWE-416 | NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, whe… |
| CVE-2026-7451 | 7.8 | 6.3 | Autodesk | 3ds Max | CWE-787 | TIF File Parsing Out-of-Bounds Write in Autodesk 3ds Max |
| CVE-2026-7452 | 7.8 | 6.3 | Autodesk | 3ds Max | CWE-120 | WRL File Parsing Memory Corruption in Autodesk 3ds Max |
| CVE-2026-24196 | 7.1 | 6.4 | NVIDIA | GeForce | CWE-125 | NVIDIA Display Driver for Linux contains a vulnerability where a user could c… |
| CVE-2025-36145 | 5.3 | 6.3 | IBM | watsonx.data | CWE-923 | Multiple Vulnerabilities in watsonx.data |
| CVE-2026-48697 | 7.4 | 6.0 | n/a | n/a | CWE-295 | FastNetMon Community Edition through 1.2.9 does not verify TLS certificates o… |
| CVE-2026-44833 | 7.1 | 6.0 | grokability | snipe-it | CWE-601 | Snipe-IT: Open redirect vulnerability |
| CVE-2026-47672 | 6.5 | 5.9 | oviva-ag | epa4all-client | CWE-306 | epa4all-client: Unauthenticated REST API for Patient Record Writes |
| CVE-2026-24195 | 5.5 | 5.9 | NVIDIA | Guest driver | CWE-20 | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user… |
| CVE-2026-9572 | 1.9 | 5.8 | n/a | GPAC | CWE-401 | GPAC MP4Box media.c Media_GetSample memory leak |
| CVE-2026-24197 | 6.5 | 5.6 | NVIDIA | GeForce | CWE-1188 | NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instanc… |
| CVE-2026-48900 | 6.4 | 5.7 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler |
| CVE-2026-9582 | 2.1 | 5.5 | SourceCodester | CET Automated Grading System with AI Predictive Analytics | CWE-352 | SourceCodester CET Automated Grading System with AI Predictive Analytics cros… |
| CVE-2026-27331 | 6.3 | 5.4 | Magepeople inc. | WpTravelly | CWE-862 | WordPress WpTravelly plugin <= 2.1.5 - Broken Access Control vulnerability |
| CVE-2026-24198 | 5.6 | 5.2 | NVIDIA | GeForce | CWE-200 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an advance… |
| CVE-2026-7450 | 5.5 | 5.1 | Autodesk | 3ds Max | CWE-476 | PAR File Parsing NULL Pointer Dereference in Autodesk 3ds Max |
| CVE-2026-7453 | 5.5 | 5.1 | Autodesk | 3ds Max | CWE-674 | WRL File Parsing Memory Exhaustion in Autodesk 3ds Max |
| CVE-2026-24520 | 4.3 | 5.2 | bPlugins | Tiktok Feed | CWE-862 | WordPress Tiktok Feed plugin <= 1.0.24 - Broken Access Control vulnerability |
| CVE-2026-25444 | 4.3 | 5.2 | Magepeople inc. | WpBookingly | CWE-862 | WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability |
| CVE-2026-47715 | 3.1 | 5.1 | bugsink | bugsink | CWE-639 | Bugsink: Issue event views can show an event from another project if its UUID… |
| CVE-2026-24194 | 7.8 | 4.9 | NVIDIA | GeForce | CWE-281 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode lay… |
| CVE-2026-44983 | 7.3 | 4.8 | servo | smallbitvec | CWE-122 | smallbitvec: Safe API Triggered Heap Buffer Overflow via Integer Overflow |
| CVE-2025-46307 | 5.5 | 4.7 | Apple | macOS | CWE-284 | A logic issue was addressed with improved restrictions. This issue is fixed i… |
| CVE-2026-48903 | 6.9 | 4.6 | Joomla! Project | Joomla! Framework Filter package | CWE-79 | Joomla! Framework - [20260519] - Inadequate content filtering within the chec… |
| CVE-2026-48905 | 6.9 | 4.6 | Joomla! Project | Joomla! Framework Filter package | CWE-79 | Joomla! Framework - [20260520] - Inadequate content filtering within the clea… |
| CVE-2026-47716 | 3.1 | 4.4 | bugsink | bugsink | CWE-639 | Bugsink: Issue bulk actions can affect another project’s issue if its UUID is… |
| CVE-2026-25112 | 7.8 | 4.3 | Genetec Inc. | Genetec RabbitMQ | CWE-732 | A high-severity vulnerability in the deployment of Genetec RabbitMQ that allo… |
| CVE-2026-24201 | 5.8 | 4.1 | NVIDIA | Virtual GPU Manager | CWE-787 | NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, whe… |
| CVE-2026-9529 | 1.9 | 4.1 | GNU | LibreDWG | CWE-404 | GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer derefe… |
| CVE-2026-9530 | 1.9 | 4.1 | GNU | LibreDWG | CWE-119 | GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds |
| CVE-2025-43289 | 5.5 | 3.7 | Apple | macOS | CWE-285 | A logic issue was addressed with improved validation. This issue is fixed in … |
| CVE-2026-45574 | 8.1 | 3.7 | oviva-ag | epa4all-client | CWE-295 | epa4all-client: TLS Certificate Validation Disabled in Production |
| CVE-2026-24191 | 7.8 | 3.7 | NVIDIA | GeForce | CWE-367 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker … |
| CVE-2025-46280 | 5.5 | 3.5 | Apple | macOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2025-43306 | 7.8 | 3.4 | Apple | macOS | CWE-269 | A logic issue was addressed with improved checks. This issue is fixed in macO… |
| CVE-2025-43451 | 5.5 | 3.4 | Apple | macOS | CWE-284 | A permissions issue was addressed by removing the vulnerable code. This issue… |
| CVE-2026-46620 | 6.5 | 3.2 | e107inc | e107 | CWE-285 | e107: CSRF in comment.php moderation endpoints via token-optional validation … |
| CVE-2026-7454 | 7.8 | 3.2 | Autodesk | 3ds Max | CWE-120 | WRL File Parsing Memory Corruption in Autodesk 3ds Max |
| CVE-2026-44410 | 3.8 | 3.2 | ZTE | ZXUniPOS NDS-LTE | CWE-1240 | Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE |
| CVE-2025-43290 | 5.5 | 3.0 | Apple | macOS | CWE-732 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-48693 | 5.5 | 2.7 | n/a | n/a | CWE-59 | FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink a… |
| CVE-2026-44728 | 7.8 | 2.6 | babel | babel | CWE-94 | Improper Control of Generation of Code when compiling specifically crafted ma… |
| CVE-2026-24182 | 6.5 | 2.6 | NVIDIA | GeForce | CWE-667 | NVIDIA Display Driver for Windows and Linux contains a vulnerability where an… |
| CVE-2026-48696 | 6.2 | 2.6 | n/a | n/a | CWE-120 | FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different… |
| CVE-2026-44468 | 8.5 | 2.5 | CODESYS | CODESYS Development System | CWE-276 | Incorrect Default Permissions in CODESYS Development System |
| CVE-2026-45834 | 5.5 | 2.4 | Linux | Linux | CWE-476 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() |
| CVE-2026-45835 | 5.5 | 2.4 | Linux | Linux | CWE-476 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() |
| CVE-2026-45836 | 5.5 | 2.4 | Linux | Linux | CWE-476 | Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() |
| CVE-2026-44900 | 8.1 | 2.2 | oviva-ag | epa4all-client | CWE-295 | epa4all-client: VAU Signature bypass |
| CVE-2026-45575 | 7.4 | 2.0 | oviva-ag | epa4all-client | CWE-347 | epa4all-client: Improper Verification of Cryptographic Signature |
| CVE-2026-44443 | 4.8 | 2.0 | prolix-oc | Lumiverse | CWE-362 | Lumiverse: Sign-up nonce race condition allows unauthorized account registration |
| CVE-2026-48690 | 7.1 | 1.9 | n/a | n/a | CWE-122 | FastNetMon Community Edition through 1.2.9 contains an integer overflow vulne… |
| CVE-2026-9567 | 1.9 | 1.8 | n/a | GPAC | CWE-404 | GPAC MP4Box isom_intern.c MergeFragment null pointer dereference |
| CVE-2025-13755 | 5.5 | 1.4 | IBM | Db2 | CWE-532 | IBM® Db2® is vulnerable to credential exposure in db2diag when executing spec… |
| CVE-2026-35220 | 4.6 | 1.4 | Joomla! Project | Joomla! CMS | CWE-352 | Joomla! Core - [20260505] - CSRF in user activation endpoint |
| CVE-2026-44469 | 8.5 | 1.2 | CODESYS | CODESYS Development System | CWE-276 | Incorrect Default Permissions in CODESYS Development System |
| CVE-2025-46284 | 7.0 | 1.1 | Apple | macOS | CWE-362 | A race condition was addressed with additional validation. This issue is fixe… |
| CVE-2026-7310 | 4.4 | 1.1 | Hitachi Energy | MACH HiDraw | CWE-122 | A heap-based buffer overflow vulnerability exists in XML parser functionality… |
| CVE-2026-24199 | 4.7 | 0.6 | NVIDIA | GeForce | CWE-362 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, … |
| CVE-2026-45413 | 6.9 | 0.3 | 1Panel-dev | MaxKB | CWE-328 | MaxKB: Unsalted MD5 Password Hashing |
| CVE-2026-41164 | 4.4 | 0.1 | nuts-foundation | nuts-node | CWE-345 | nuts-node: JWT type confusion in v1 access token introspection allows VP repl… |