| CVE-2026-45261 | 9.3 | 41.5 | gitbutlerapp | gitbutler | CWE-94 | GitButler: Link injection via forge integration enables arbitrary script exec… |
| CVE-2026-32997 | 8.6 | 41.4 | Veeam | Backup and Replication | CWE-36 | A vulnerability allowing an authenticated user with the Backup Administrator … |
| CVE-2026-46185 | 9.1 | 41.3 | Linux | Linux | CWE-125 | smb/client: fix out-of-bounds read in symlink_data() |
| CVE-2026-49127 | 8.8 | 41.2 | MusicPlayerDaemon | MPD | CWE-193 | Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be |
| CVE-2026-8697 | 8.7 | 41.2 | TP-Link Systems Inc. | Archer C64 v1.0 | CWE-306 | Improper Authentication Rate Limiting on TP-Link's Archer C64 |
| CVE-2026-49238 | 8.4 | 40.9 | Canonical | Multipass | CWE-22 | SFTP Server VM Escape in Canonical Multipass |
| CVE-2026-7048 | 6.5 | 40.8 | 10web | Photo Gallery by 10Web – Mobile-Friendly Image Gallery | CWE-89 | Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection… |
| CVE-2026-41184 | 6.0 | 40.8 | Tigera | Calico | CWE-532 | ServiceAccount token disclosure via install-cni container logs |
| CVE-2026-49128 | 8.7 | 40.6 | MusicPlayerDaemon | MPD | CWE-22 | Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling |
| CVE-2026-46177 | 7.5 | 40.6 | Linux | Linux | — | ipmi: Add limits to event and receive message requests |
| CVE-2026-46110 | 7.5 | 40.6 | Linux | Linux | CWE-476 | net: stmmac: Prevent NULL deref when RX memory exhausted |
| CVE-2026-46115 | 9.8 | 40.0 | Linux | Linux | — | block: add pgmap check to biovec_phys_mergeable |
| CVE-2026-44477 | 9.4 | 39.3 | cloudnative-pg | cloudnative-pg | CWE-250 | CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL sup… |
| CVE-2026-46155 | 9.1 | 39.2 | Linux | Linux | CWE-125 | smb/client: fix out-of-bounds read in smb2_compound_op() |
| CVE-2026-9801 | 4.9 | 39.2 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-1284 | Keycloak: keycloak: denial of service via malformed ldap password policy resp… |
| CVE-2026-43898 | 10.0 | 38.8 | nyariv | SandboxJS | CWE-94 | SandboxJS: Sandbox escape via Function.caller leakage of internal call op |
| CVE-2026-41565 | 7.5 | 38.6 | MIK | CryptX | CWE-121 | CryptX versions before 0.088_001 for Perl have a stack buffer overflow in fou… |
| CVE-2026-46114 | 7.5 | 38.5 | Linux | Linux | CWE-476 | RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads |
| CVE-2026-34311 | 9.8 | 38.1 | Oracle Corporation | Oracle Hospitality OPERA 5 Property Services | — | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of … |
| CVE-2026-45344 | 8.1 | 37.8 | Kovah | LinkAce | CWE-74 | LinkAce: Setup database password newline injection enables pre-auth RCE on un… |
| CVE-2026-33590 | 8.5 | 37.5 | Portainer | Portainer Community Edition | CWE-276 | Insecure default permissions in Portainer CE |
| CVE-2026-9009 | 8.8 | 37.1 | CodeRevolution | Crawlomatic Multipage Scraper Post Generator | CWE-434 | Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author… |
| CVE-2026-44462 | 8.8 | 36.5 | zed-industries | zed | CWE-184 | Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Perm… |
| CVE-2026-7634 | 7.2 | 36.3 | veronalabs | SlimStat Analytics | CWE-79 | SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting vi… |
| CVE-2026-46775 | 9.9 | 35.9 | Oracle Corporation | Oracle REST Data Services | CWE-400 | Vulnerability in Oracle REST Data Services (component: Core). Supported versi… |
| CVE-2026-46137 | 9.8 | 35.5 | Linux | Linux | CWE-362 | mptcp: pm: ADD_ADDR rtx: fix potential data-race |
| CVE-2026-46124 | 7.5 | 35.5 | Linux | Linux | — | isofs: validate block number from NFS file handle in isofs_export_iget |
| CVE-2026-9094 | 9.8 | 35.0 | Casdoor | Casdoor | — | CVE-2026-9094 |
| CVE-2026-7802 | 8.8 | 34.8 | shabti | Frontend Admin by DynamiApps | CWE-862 | Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticat… |
| CVE-2026-9803 | 5.3 | 34.8 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-125 | Keycloak: keycloak: denial of service via malformed authorization header |
| CVE-2026-44881 | 8.5 | 34.7 | portainer | portainer | CWE-59 | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update |
| CVE-2026-9939 | 8.8 | 34.3 | Google | Chrome | CWE-122 | Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 al… |
| CVE-2026-9097 | 9.8 | 33.7 | Casdoor | Casdoor | — | CVE-2026-9097 |
| CVE-2026-32998 | 9.4 | 33.5 | Veeam | Service Provider Console | CWE-233 | This vulnerability in Veeam Service Provider Console allows for remote code e… |
| CVE-2026-46135 | 9.8 | 32.9 | Linux | Linux | CWE-362 | nvmet-tcp: fix race between ICReq handling and queue teardown |
| CVE-2026-48526 | 7.4 | 32.7 | jpadilla | pyjwt | CWE-287 | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens whe… |
| CVE-2026-35672 | 8.7 | 31.5 | thorsten | phpMyFAQ | CWE-1188 | phpMyFAQ - Authentication Bypass via Empty API Token |
| CVE-2026-9952 | 8.8 | 31.5 | Google | Chrome | CWE-416 | Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-32847 | 8.7 | 30.7 | HKUDS | DeepCode | CWE-22 | DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py |
| CVE-2026-7526 | 4.3 | 30.8 | smub | PDF Embedder | CWE-200 | PDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via… |
| CVE-2026-45288 | 9.8 | 30.6 | JasperFx | marten | CWE-89 | Marten has an SQL injection vulnerability in its full-text search regConfig p… |
| CVE-2026-45311 | 9.6 | 30.6 | Hmbown | CodeWhale | CWE-94 | CodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval |
| CVE-2026-9872 | 9.6 | 30.5 | Google | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.21… |
| CVE-2026-40914 | 4.3 | 30.3 | Apache Software Foundation | Apache Artemis Stomp Protocol | CWE-863 | Apache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Addres… |
| CVE-2026-48525 | 5.3 | 30.1 | jpadilla | pyjwt | CWE-400 | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload… |
| CVE-2026-9828 | 2.9 | 30.1 | QOS.CH Sarl | logback | CWE-502 | Logback deserialization whitelist bypass for java.lang and java.util |
| CVE-2026-45076 | 5.1 | 29.9 | element-hq | synapse | CWE-20 | Synapse pagination denial of service |
| CVE-2026-9884 | 8.8 | 29.9 | Google | Chrome | CWE-416 | Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 all… |
| CVE-2026-44543 | 8.7 | 29.9 | rancher | local-path-provisioner | CWE-269 | Local Path Provisioner: HelperPod Template Injection |
| CVE-2026-48116 | 8.8 | 29.7 | Mintplex-Labs | anything-llm | CWE-77 | AnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-fi… |
| CVE-2026-5737 | 6.5 | 29.7 | bensibley | Independent Analytics – WordPress Analytics Plugin | CWE-918 | Independent Analytics <= 2.14.9 - Unauthenticated Server-Side Request Forgery… |
| CVE-2026-9093 | 9.8 | 29.6 | Casdoor | Casdoor | — | CVE-2026-9093 |
| CVE-2026-44593 | 8.7 | 29.3 | esm-dev | esm.sh | CWE-22 | esm.sh: Legacy Route Path Traversal Can Lead to RCE |
| CVE-2026-30761 | 7.3 | 28.9 | n/a | n/a | CWE-434 | An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php co… |
| CVE-2026-9962 | 8.8 | 28.6 | Google | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a r… |
| CVE-2026-9795 | 7.3 | 28.5 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-266 | Keycloak: keycloak: privilege escalation via improper scope mapping enforcement |
| CVE-2026-46839 | 9.9 | 28.3 | Oracle Corporation | Oracle REST Data Services | CWE-284 | Vulnerability in Oracle REST Data Services (component: Core). Supported versi… |
| CVE-2026-7651 | 5.3 | 28.0 | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | CWE-639 | User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecur… |
| CVE-2026-44657 | 7.5 | 28.0 | mantisbt | mantisbt | CWE-79 | MantisBT: Stored XSS in File Download |
| CVE-2026-9798 | 4.3 | 27.8 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-305 | Keycloak: keycloak: brute-force protection bypass in ciba flow |
| CVE-2026-44849 | 9.4 | 27.7 | portainer | portainer | CWE-862 | Portainer: Endpoint security bypass via Swarm service create/update |
| CVE-2026-2374 | 7.2 | 27.6 | robertpeake | Login No Captcha reCAPTCHA | CWE-79 | Login No Captcha reCAPTCHA <= 1.8.0 - Unauthenticated Stored Cross-Site Scrip… |
| CVE-2026-41141 | 6.5 | 27.6 | espocrm | espocrm | CWE-639 | EspoCRM: IDOR in EmailTemplate Prepare Endpoint Leaks Entity Data via Email A… |
| CVE-2026-45017 | 8.2 | 26.5 | jg-rp | liquid | CWE-22 | Python Liquid: Absolute paths escape filesystem loader search path |
| CVE-2026-48524 | 3.7 | 26.5 | jpadilla | pyjwt | CWE-460 | PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled k… |
| CVE-2026-44882 | 8.1 | 26.4 | portainer | portainer | CWE-863 | Portainer: Kubernetes middleware continues after token validation failure, by… |
| CVE-2026-37266 | 8.0 | 26.2 | n/a | n/a | CWE-98 | An issue in Responsive File Manager Responsive FileManager Version 9.14.0 all… |
| CVE-2026-7552 | 5.3 | 26.2 | cyberhobo | Geo Mashup | CWE-862 | Geo Mashup <= 1.13.19 - Missing Authorization to Unauthenticated Plugin Setti… |
| CVE-2026-42399 | 6.5 | 26.1 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-42400 | 6.5 | 26.1 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-8980 | 9.3 | 26.0 | Mennekes | Amtron | CWE-269 | Privilege Escalation |
| CVE-2026-9794 | 5.3 | 26.0 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-209 | Keycloak: keycloak: information disclosure via saml ecp endpoint |
| CVE-2026-46819 | 9.1 | 25.9 | Oracle Corporation | Oracle Internet Procurement Connector | CWE-284 | Vulnerability in the Oracle Internet Procurement Connector product of Oracle … |
| CVE-2026-9096 | 7.5 | 25.9 | Casdoor | Casdoor | — | CVE-2026-9096 |
| CVE-2026-42999 | 8.8 | 25.8 | OpenStack | Keystone | CWE-863 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBA… |
| CVE-2026-44848 | 9.4 | 25.7 | portainer | portainer | CWE-862 | Portainer: Missing authorization on Docker plugin endpoints allows host RCE |
| CVE-2026-46833 | 9.0 | 25.7 | Oracle Corporation | Oracle Database Server | — | Vulnerability in the Net Service component of Oracle Database Server. Support… |
| CVE-2026-43000 | 8.8 | 25.6 | OpenStack | Keystone | CWE-863 | An issue was discovered in OpenStack Keystone before 29.0.2. When combined wi… |
| CVE-2026-44672 | 9.3 | 25.4 | mapfish | mapfish-print | CWE-94 | mapfish-print: Remote Code Injection (RCE) in Dynamic table |
| CVE-2026-9910 | 8.8 | 25.4 | Google | Chrome | CWE-125 | Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216… |
| CVE-2026-8915 | 8.8 | 25.2 | Samsung Open Source | Escargot | CWE-787 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Over… |
| CVE-2026-35675 | 8.8 | 25.2 | thorsten | phpMyFAQ | CWE-307 | phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/use… |
| CVE-2026-41185 | 6.0 | 25.1 | Tigera | Calico | CWE-532 | ServiceAccount token disclosure via Azure IPAM CNI plugin logs |
| CVE-2026-9091 | 5.3 | 25.0 | Casdoor | Casdoor | — | CVE-2026-9091 |
| CVE-2026-44594 | 7.5 | 24.9 | esm-dev | esm.sh | CWE-22 | esm.sh: Path Traversal via package.json browser field allows reading arbitrar… |
| CVE-2026-6816 | 5.1 | 24.8 | Drupal | TFA Basic Plugins | CWE-267 | TFA Basic Plugins - Access Bypass |
| CVE-2026-9938 | 8.8 | 24.7 | Google | Chrome | CWE-94 | Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 a… |
| CVE-2026-10013 | 8.8 | 24.7 | Google | Chrome | CWE-416 | Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed … |
| CVE-2024-47096 | 5.1 | 24.7 | Follet School Solutions | Destiny | CWE-79 | Reflected Cross-Site Scripting in Follet School Solutions Destiny |
| CVE-2024-47097 | 5.1 | 24.7 | Follet School Solutions | Destiny | CWE-79 | Reflected Cross-Site Scripting in Follet School Solutions Destiny |
| CVE-2026-45323 | 9.6 | 24.4 | jpettitt | meshcore-card | CWE-79 | MeshCore Card: XSS vulnerability through meshcore node name |
| CVE-2026-9645 | 9.9 | 24.3 | ScadaBR | ScadaBR | CWE-78 | ScadaBR Authenticated Remote Code Execution |
| CVE-2026-9092 | 9.1 | 24.3 | Casdoor | Casdoor | — | CVE-2026-9092 |
| CVE-2026-46509 | 8.2 | 24.4 | ranfdev | deepobj | CWE-1321 | deepobj: Improperly Controlled Modification of Object Prototype Attributes ('… |
| CVE-2026-44883 | 7.7 | 24.3 | portainer | portainer | CWE-598 | Portainer: JWT accepted in URL query leaks tokens to logs and referers |
| CVE-2026-32999 | 9.0 | 24.0 | WebPros | Comet Backup | CWE-94 | Insufficient character filtering in backup agent signing module on Comet Back… |
| CVE-2026-9878 | 8.8 | 23.9 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-44796 | 6.5 | 23.9 | nautobot | nautobot | CWE-400 | Nautobot: Object bulk rename UI actions vulnerable to denial of service by cr… |
| CVE-2026-45044 | 8.8 | 23.7 | rustfs | rustfs | CWE-306 | RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unau… |
| CVE-2026-44973 | 8.1 | 23.7 | go-git | go-billy | CWE-22 | Billy: Path traversal vulnerabilities |
| CVE-2026-47136 | 6.9 | 23.7 | rustfs | rustfs | CWE-200 | RustFS: Unauthenticated RustFS console license endpoint exposes license metadata |
| CVE-2026-30760 | 7.3 | 23.5 | n/a | n/a | CWE-20 | An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attacke… |
| CVE-2026-45343 | 8.5 | 23.2 | Kovah | LinkAce | CWE-79 | LinkAce - Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit … |
| CVE-2026-9927 | 8.8 | 22.9 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9928 | 8.8 | 22.9 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.2… |
| CVE-2026-9941 | 8.8 | 22.9 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9945 | 8.8 | 22.9 | Google | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 a… |
| CVE-2026-9947 | 8.8 | 22.9 | Google | Chrome | CWE-416 | Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remo… |
| CVE-2026-42998 | 8.8 | 22.9 | OpenStack | Keystone | CWE-863 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone app… |
| CVE-2026-35671 | 8.7 | 22.9 | thorsten | phpMyFAQ | CWE-266 | phpMyFAQ - Insecure Direct Object Reference in User Password API |
| CVE-2026-46125 | 8.8 | 22.8 | Linux | Linux | CWE-416 | wifi: mac80211: remove station if connection prep fails |
| CVE-2026-9873 | 8.8 | 22.6 | Google | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-42398 | 7.7 | 22.5 | Elastic | Kibana | CWE-918 | Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network … |
| CVE-2026-9802 | 6.8 | 22.6 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-613 | Keycloak: keycloak: unauthorized account access via replayed refresh tokens a… |
| CVE-2026-9015 | 4.3 | 22.6 | equalizedigital | Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance | CWE-862 | Equalize Digital Accessibility Checker <= 1.42.0 - Missing Authorization to A… |
| CVE-2026-44655 | 8.6 | 22.3 | mantisbt | mantisbt | CWE-79 | MantisBT: Stored XSS on Move Attachments Admin Page |
| CVE-2026-9095 | 8.1 | 22.4 | Casdoor | Casdoor | CWE-294 | CVE-2026-9095 |
| CVE-2026-44465 | 8.6 | 22.2 | zed-industries | zed | CWE-78 | Zed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned … |
| CVE-2026-9976 | 8.8 | 22.1 | Google | Chrome | CWE-94 | Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 … |
| CVE-2026-9995 | 8.8 | 22.1 | Google | Chrome | CWE-416 | Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-45364 | 7.3 | 22.0 | better-auth | better-auth | CWE-307 | Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable … |
| CVE-2026-49299 | 5.3 | 22.0 | OpenStack | Neutron | CWE-863 | In OpenStack Neutron before 28.0.1, the tagging controller enforces plural po… |
| CVE-2026-7052 | 7.2 | 21.8 | htplugins | HT Contact Form – Drag & Drop Form Builder for WordPress | CWE-79 | HT Contact Form <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting via Fi… |
| CVE-2026-41160 | 4.3 | 21.7 | espocrm | espocrm | CWE-284 | EspoCRM: Broken Access Control / IDOR in Note Pinning API allows unauthorized… |
| CVE-2026-9879 | 8.8 | 21.6 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed… |
| CVE-2026-9883 | 8.8 | 21.6 | Google | Chrome | CWE-416 | Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-9896 | 8.8 | 21.6 | Google | Chrome | CWE-787 | Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-9897 | 8.8 | 21.6 | Google | Chrome | CWE-416 | Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remo… |
| CVE-2026-9969 | 8.8 | 21.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-6427 | 6.4 | 21.6 | a3rev | a3 Lazy Load | CWE-79 | a3 Lazy Load <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-37579 | 7.3 | 21.5 | n/a | n/a | CWE-502 | An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute ar… |
| CVE-2026-46822 | 9.9 | 20.8 | Oracle Corporation | Oracle iAssets | CWE-284 | Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (compo… |
| CVE-2026-46826 | 8.8 | 20.8 | Oracle Corporation | Oracle Payroll | CWE-306 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-32995 | 7.5 | 20.8 | Rocket.Chat | Rocket.Chat | CWE-284 | The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0,… |
| CVE-2026-46198 | 8.8 | 20.6 | Linux | Linux | CWE-190 | batman-adv: fix integer overflow on buff_pos |
| CVE-2026-49129 | 6.9 | 20.6 | MusicPlayerDaemon | MPD | CWE-918 | Music Player Daemon < 0.24.11 SSRF via CurlInputPlugin |
| CVE-2026-47759 | 5.4 | 20.6 | tinymce | tinymce | CWE-79 | TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- pref… |
| CVE-2026-47762 | 5.4 | 20.6 | tinymce | tinymce | CWE-79 | TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comm… |
| CVE-2026-41897 | 5.3 | 20.6 | mantisbt | mantisbt | CWE-79 | MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Field |
| CVE-2026-9957 | 8.8 | 20.4 | Google | Chrome | CWE-416 | Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remo… |
| CVE-2026-9968 | 8.8 | 20.5 | Google | Chrome | CWE-472 | Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-9973 | 8.8 | 20.5 | Google | Chrome | CWE-787 | Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-9963 | 7.5 | 20.2 | Google | Chrome | CWE-457 | Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allo… |
| CVE-2026-46138 | 8.1 | 20.1 | Linux | Linux | CWE-125 | Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_com… |
| CVE-2026-44798 | 7.1 | 20.1 | nautobot | nautobot | CWE-471 | Nautobot: GitRepository.current_head field should not be writable through RES… |
| CVE-2026-33464 | 6.5 | 19.9 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-46212 | 8.8 | 19.8 | Linux | Linux | CWE-416 | batman-adv: bla: prevent use-after-free when deleting claims |
| CVE-2026-46834 | 7.5 | 19.8 | Oracle Corporation | Oracle Database Server | CWE-400 | Vulnerability in the Net Service component of Oracle Database Server. Support… |
| CVE-2026-46835 | 7.5 | 19.8 | Oracle Corporation | Oracle Database Server | CWE-400 | Vulnerability in the Net Service component of Oracle Database Server. Support… |
| CVE-2026-46829 | 7.5 | 19.7 | Oracle Corporation | Oracle REST Data Services | CWE-400 | Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported v… |
| CVE-2026-9917 | 6.5 | 19.2 | Google | Chrome | CWE-457 | Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.21… |
| CVE-2026-49094 | 6.5 | 19.2 | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-45039 | 9.8 | 19.0 | rustfs | rustfs | CWE-798 | RustFS: Internode RPC HMAC secret falls back to public default credential, en… |
| CVE-2026-46837 | 8.8 | 19.0 | Oracle Corporation | Oracle Flow Manufacturing | CWE-269 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S… |
| CVE-2026-9792 | 6.5 | 19.0 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-280 | Keycloak: keycloak: security restriction bypass allows unauthorized ropc toke… |
| CVE-2026-9893 | 8.3 | 18.9 | Google | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-35277 | 8.1 | 18.9 | Oracle Corporation | Oracle REST Data Services | CWE-400 | Vulnerability in Oracle REST Data Services (component: Core). Supported versi… |
| CVE-2026-46824 | 9.9 | 18.4 | Oracle Corporation | Oracle Universal Work Queue | CWE-269 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business… |
| CVE-2026-47761 | 5.4 | 18.4 | tinymce | tinymce | CWE-79 | TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce… |
| CVE-2026-43979 | 5.0 | 18.3 | LearningCircuit | local-deep-research | CWE-79 | Local Deep Research: HTML Injection via Unescaped User Input in PDF Export (`… |
| CVE-2026-46238 | 8.8 | 18.1 | Linux | Linux | — | batman-adv: stop caching unowned originator pointers in BAT IV |
| CVE-2026-49095 | 6.5 | 18.1 | Elastic | Kibana | CWE-20 | Improper Input Validation in Kibana Fleet Leading to Privilege Escalation |
| CVE-2026-46821 | 7.7 | 18.0 | Oracle Corporation | Oracle Financials Common Modules | CWE-284 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus… |
| CVE-2026-10005 | 7.5 | 17.9 | Google | Chrome | CWE-416 | Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.… |
| CVE-2026-46818 | 7.4 | 17.9 | Oracle Corporation | Oracle Payments | CWE-284 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-45374 | 9.6 | 17.8 | Hmbown | CodeWhale | CWE-94 | CodeWhale: task_create Insecure Defaults Enable RCE via Prompt Injection in P… |
| CVE-2026-42071 | 7.2 | 17.9 | mantisbt | mantisbt | CWE-862 | MantisBT: Private Bugnote Attachment Content Leak via REST API |
| CVE-2026-49130 | 6.9 | 17.8 | MusicPlayerDaemon | MPD | CWE-93 | Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx |
| CVE-2026-47676 | 5.3 | 17.8 | honojs | hono | CWE-444 | Hono: app.mount() strips mount prefix using undecoded path, causing incorrect… |
| CVE-2026-9940 | 8.8 | 17.7 | Google | Chrome | CWE-122 | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowe… |
| CVE-2026-46232 | 8.1 | 17.6 | Linux | Linux | — | HID: playstation: Clamp num_touch_reports |
| CVE-2026-9806 | 6.3 | 17.6 | misp | cti-transmute | CWE-79 | Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Mal… |
| CVE-2026-42070 | 5.3 | 17.7 | mantisbt | mantisbt | CWE-863 | MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API |
| CVE-2026-46843 | 5.3 | 17.6 | Oracle Corporation | Oracle REST Data Services | CWE-400 | Vulnerability in Oracle REST Data Services (component: Core). Supported versi… |
| CVE-2026-44461 | 8.6 | 17.5 | zed-industries | zed | CWE-78 | Zed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / W… |
| CVE-2026-5343 | 7.4 | 17.5 | Drupal | SAML SSO - Service Provider | CWE-754 | SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2… |
| CVE-2026-44884 | 6.0 | 17.5 | portainer | portainer | CWE-862 | Portainer: Missing authorization on custom template file endpoint exposes tem… |
| CVE-2026-9983 | 8.8 | 17.2 | Google | Chrome | CWE-843 | Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-9901 | 7.5 | 17.2 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9909 | 7.5 | 17.2 | Google | Chrome | CWE-472 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a r… |
| CVE-2026-9922 | 7.5 | 17.2 | Google | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed… |
| CVE-2026-9934 | 7.5 | 17.2 | Google | Chrome | CWE-416 | Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-9956 | 7.5 | 17.2 | Google | Chrome | CWE-416 | Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed… |
| CVE-2026-9923 | 8.8 | 17.0 | Google | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-10007 | 8.8 | 16.9 | Google | Chrome | CWE-416 | Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remo… |
| CVE-2026-10015 | 8.8 | 16.9 | Google | Chrome | CWE-472 | Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-10016 | 8.8 | 16.9 | Google | Chrome | CWE-416 | Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remo… |
| CVE-2026-46827 | 8.8 | 16.6 | Oracle Corporation | Oracle Payroll | CWE-269 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-7621 | 4.3 | 16.6 | smtp2go | SMTP2GO for WordPress – Email Made Easy | CWE-862 | SMTP2GO for WordPress <= 1.16.0 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-44394 | 8.1 | 16.5 | OpenStack | Keystone | CWE-863 | An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone fed… |
| CVE-2026-6455 | 8.1 | 16.3 | yudiz | WP Contact Form 7 DB Handler | CWE-352 | WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary… |
| CVE-2026-9912 | 6.5 | 16.3 | Google | Chrome | CWE-200 | Inappropriate implementation in GPU in Google Chrome on Android prior to 148.… |
| CVE-2026-9953 | 6.5 | 16.3 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed … |
| CVE-2026-46526 | 5.0 | 16.3 | LearningCircuit | local-deep-research | CWE-918 | Local Deep Research: SSRF bypass in `safe_get` |
| CVE-2026-9037 | 9.3 | 16.1 | XCharge | C6 | CWE-494 | Download of code without integrity check in XCharge C6 |
| CVE-2026-9915 | 8.3 | 16.0 | Google | Chrome | CWE-122 | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowe… |
| CVE-2026-9924 | 8.3 | 16.0 | Google | Chrome | CWE-122 | Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778… |
| CVE-2026-9926 | 8.3 | 16.0 | Google | Chrome | CWE-122 | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowe… |
| CVE-2026-9891 | 9.0 | 16.0 | Google | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed… |
| CVE-2026-47674 | 5.3 | 15.8 | honojs | hono | CWE-185 | Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 |
| CVE-2026-9875 | 9.6 | 15.7 | Google | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.2… |
| CVE-2026-9876 | 9.6 | 15.7 | Google | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 a… |
| CVE-2026-9886 | 9.6 | 15.7 | Google | Chrome | CWE-416 | Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowe… |
| CVE-2026-9918 | 9.6 | 15.8 | Google | Chrome | CWE-269 | Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216… |
| CVE-2026-9967 | 9.6 | 15.7 | Google | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-9961 | 8.8 | 15.7 | Google | Chrome | CWE-416 | Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 all… |
| CVE-2026-9965 | 8.8 | 15.7 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed… |
| CVE-2026-3173 | 6.5 | 15.8 | mr2p | Meta Field Block – Display custom fields in the Block Editor without coding | CWE-639 | Meta Field Block <= 1.5.1 - Insecure Direct Object Reference to Authenticated… |
| CVE-2026-8689 | 4.3 | 15.7 | themeisle | Visualizer: Tables and Charts Manager for WordPress | CWE-862 | Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Auth… |
| CVE-2026-35676 | 8.8 | 15.5 | thorsten | phpMyFAQ | CWE-640 | phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint |
| CVE-2026-45041 | 8.7 | 15.3 | rustfs | rustfs | CWE-321 | RustFS: Hard-coded RSA private key in license verifier permits arbitrary lice… |
| CVE-2026-45373 | 7.4 | 15.2 | Hmbown | CodeWhale | CWE-918 | CodeWhale: SSRF IPV6 bypass |
| CVE-2026-9908 | 6.5 | 15.0 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed … |
| CVE-2026-33463 | 5.3 | 15.0 | Elastic | Kibana | CWE-672 | Operation on a Resource after Expiration or Termination in Kibana Leading to … |
| CVE-2026-9921 | 4.3 | 15.0 | Google | Chrome | CWE-457 | Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.21… |
| CVE-2026-9935 | 4.3 | 15.0 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-9914 | 8.3 | 15.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-33462 | 7.3 | 14.8 | Elastic | Kibana | CWE-22 | Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts |
| CVE-2026-44797 | 8.5 | 14.7 | nautobot | nautobot | CWE-918 | Nautobot: Webhook definitions could be used for server-side request forgery (… |
| CVE-2026-9960 | 7.5 | 14.7 | Google | Chrome | CWE-472 | Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-9874 | 9.6 | 14.6 | Google | Chrome | CWE-416 | Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-45058 | 9.4 | 14.5 | electerm | electerm | CWE-94 | electerm: Import unsafe bookmark data could lead to unsafe operation when cli… |
| CVE-2026-9978 | 8.8 | 14.5 | Google | Chrome | CWE-416 | Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-9984 | 8.8 | 14.5 | Google | Chrome | CWE-416 | Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allo… |
| CVE-2026-9992 | 8.8 | 14.5 | Google | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-10021 | 8.8 | 14.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in USB in Google Chrome prior to 1… |
| CVE-2026-45306 | 6.5 | 14.6 | pyload | pyload | CWE-706 | pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session … |
| CVE-2026-9913 | 4.3 | 14.6 | Google | Chrome | CWE-125 | Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.21… |
| CVE-2026-9964 | 8.1 | 14.4 | Google | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 a… |
| CVE-2026-44466 | 8.6 | 14.2 | zed-industries | zed | CWE-78 | Zed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool Permissions |
| CVE-2026-44463 | 7.8 | 14.3 | zed-industries | zed | CWE-78 | Zed: Allowlist Bypass via Environment Variable Injection in Terminal Tool Per… |
| CVE-2026-9813 | 6.2 | 14.3 | flowintel | flowintel | CWE-918 | FlowIntel external reference URL probe allows server-side request forgery |
| CVE-2026-8682 | 4.3 | 14.3 | hasanazizul | 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On | CWE-862 | 3D Viewer <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) Arb… |
| CVE-2026-45296 | 7.7 | 14.1 | openreplay | openreplay | CWE-284 | OpenReplay: Cross-tenant information disclosure in app_apikey projectKey rout… |
| CVE-2026-9098 | 9.1 | 14.1 | Casdoor | Casdoor | — | CVE-2026-9098 |
| CVE-2026-9038 | 8.6 | 14.1 | XCharge | C6 | CWE-121 | Stack-based buffer overflow in XCharge C6 |
| CVE-2026-10006 | 7.5 | 14.1 | Google | Chrome | CWE-362 | Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote at… |
| CVE-2026-9880 | 8.3 | 13.8 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in WebGL in Google Chrome prior to… |
| CVE-2026-9885 | 8.3 | 13.8 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome on Mac prio… |
| CVE-2026-9898 | 8.3 | 13.8 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in GPU in Google Chrome on Android… |
| CVE-2026-46820 | 8.5 | 13.7 | Oracle Corporation | Oracle Financials Common Modules | CWE-284 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus… |
| CVE-2026-46215 | 7.8 | 13.7 | Linux | Linux | CWE-416 | drm: Set old handle to NULL before prime swap in change_handle |
| CVE-2026-47074 | 8.7 | 13.5 | ex-aws | ex_aws_sns | CWE-295 | ex_aws_sns SigningCertURL not validated in verify_message/1 |
| CVE-2026-9972 | 8.3 | 13.6 | Google | Chrome | CWE-457 | Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 … |
| CVE-2026-45310 | 7.4 | 13.5 | Hmbown | CodeWhale | CWE-918 | CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool |
| CVE-2026-9658 | 7.3 | 13.6 | RRWO | Plack::Middleware::Security::Common | CWE-113 | Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not b… |
| CVE-2026-9999 | 8.8 | 13.4 | Google | Chrome | CWE-269 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.… |
| CVE-2026-45342 | 7.1 | 13.4 | Kovah | LinkAce | CWE-639 | LinkAce: IDOR in Update Policies Allows Any Authenticated User to Overwrite O… |
| CVE-2026-9958 | 8.8 | 13.3 | Google | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a r… |
| CVE-2026-6720 | 7.2 | 13.3 | Tigera | Calico | CWE-532 | Calicoctl leaks cluster credentials to stderr when verbose logging is enabled |
| CVE-2026-10008 | 6.5 | 13.3 | Google | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 … |
| CVE-2026-9877 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9916 | 8.3 | 13.1 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed… |
| CVE-2026-9925 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9931 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remo… |
| CVE-2026-9932 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 a… |
| CVE-2026-9936 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed… |
| CVE-2026-9937 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allo… |
| CVE-2026-9948 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome on Mac prior to 148.0.7778.216 allow… |
| CVE-2026-9949 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 al… |
| CVE-2026-9951 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remot… |
| CVE-2026-9933 | 7.5 | 13.1 | Google | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-4334 | 6.4 | 13.0 | 3uu | Shariff Wrapper | CWE-79 | Shariff Wrapper <= 4.6.20 - Authenticated (Contributor+) Cross-Site Scripting |
| CVE-2026-45023 | 5.4 | 13.0 | Significant-Gravitas | AutoGPT | CWE-770 | AutoGPT: Credit system bypassed via direct block execution in POST /api/block… |
| CVE-2026-48522 | 4.2 | 13.0 | jpadilla | pyjwt | CWE-441 | PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file:/… |
| CVE-2026-10003 | 7.5 | 12.9 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-10009 | 7.5 | 12.9 | Google | Chrome | CWE-472 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a r… |
| CVE-2026-9882 | 6.5 | 12.8 | Google | Chrome | CWE-190 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-47713 | 4.3 | 12.7 | Mintplex-Labs | anything-llm | CWE-285 | AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping … |
| CVE-2026-9887 | 8.8 | 12.5 | Google | Chrome | CWE-416 | Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9228 | 4.3 | 12.5 | jetmonsters | Timetable and Event Schedule by MotoPress | CWE-639 | Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object … |
| CVE-2026-9919 | 4.3 | 12.5 | Google | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.2… |
| CVE-2026-46828 | 8.1 | 12.3 | Oracle Corporation | Oracle Payroll | CWE-284 | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo… |
| CVE-2026-47675 | 5.3 | 12.3 | honojs | hono | CWE-113 | Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Coo… |
| CVE-2026-7862 | 8.6 | 12.2 | Unknown | Eupago Gateway For Woocommerce | CWE-284 | Eupago Gateway For Woocommerce < 4.7.2 - Unauthenticated Arbitrary Refund Ini… |
| CVE-2026-46841 | 5.3 | 12.1 | Oracle Corporation | Oracle REST Data Services | CWE-200 | Vulnerability in Oracle REST Data Services (component: General). Supported ve… |
| CVE-2026-9791 | 4.3 | 12.1 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-863 | Keycloak-rhel9: organization data leak after feature disabled in keycloak |
| CVE-2026-9888 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216… |
| CVE-2026-9889 | 8.3 | 11.9 | Google | Chrome | CWE-125 | Out of bounds read and write in Dawn in Google Chrome on Android prior to 148… |
| CVE-2026-9890 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allo… |
| CVE-2026-9894 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remo… |
| CVE-2026-9895 | 8.3 | 11.9 | Google | Chrome | CWE-125 | Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-9899 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9900 | 8.3 | 11.9 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed… |
| CVE-2026-9902 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allo… |
| CVE-2026-9904 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9905 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in Accessibility in Google Chrome on Windows prior to 148.0.77… |
| CVE-2026-9906 | 8.3 | 11.9 | Google | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-9966 | 8.3 | 11.9 | Google | Chrome | CWE-472 | Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 a… |
| CVE-2026-9970 | 8.3 | 11.9 | Google | Chrome | CWE-416 | Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9975 | 8.3 | 11.9 | Google | Chrome | CWE-125 | Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.21… |
| CVE-2026-9954 | 7.5 | 11.9 | Google | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-9241 | 4.3 | 11.9 | realmag777 | FOX – Currency Switcher Professional for WooCommerce | CWE-639 | FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated… |
| CVE-2026-46823 | 7.7 | 11.7 | Oracle Corporation | Oracle Public Sector Financials (International) | CWE-863 | Vulnerability in the Oracle Public Sector Financials (International) product … |
| CVE-2026-9920 | 3.1 | 11.7 | Google | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 … |
| CVE-2026-9907 | 4.3 | 11.4 | Google | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.21… |
| CVE-2026-9911 | 4.3 | 11.4 | Google | Chrome | CWE-472 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-9929 | 4.3 | 11.4 | Google | Chrome | CWE-200 | Inappropriate implementation in WebGL in Google Chrome on Android prior to 14… |
| CVE-2026-9943 | 4.3 | 11.4 | Google | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.2… |
| CVE-2026-9946 | 8.3 | 11.1 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-9974 | 8.3 | 11.1 | Google | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-45042 | 7.1 | 11.1 | rustfs | rustfs | CWE-863 | RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source |
| CVE-2026-8990 | 5.3 | 11.1 | View Concept | Kidsview | CWE-288 | Authentication Bypass in Kidsview |
| CVE-2026-45297 | 5.3 | 11.1 | openreplay | openreplay | CWE-285 | Cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} ca… |
| CVE-2026-44850 | 8.5 | 10.9 | portainer | portainer | CWE-863 | Portainer: Bind-mount restriction bypass via HostConfig.Mounts |
| CVE-2026-9892 | 8.3 | 10.9 | Google | Chrome | CWE-269 | Inappropriate implementation in Skia in Google Chrome on Android prior to 148… |
| CVE-2026-7660 | 6.1 | 10.8 | davidanderson | Easy Updates Manager | CWE-79 | Easy Updates Manager <= 9.0.20 - Reflected Cross-Site Scripting via 'paged' P… |
| CVE-2026-45410 | 5.3 | 10.8 | mauriceboe | TREK | CWE-203 | Time-based user enumeration in TREK authentication endpoint |
| CVE-2026-46830 | 5.3 | 10.9 | Oracle Corporation | Oracle REST Data Services | CWE-200 | Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported v… |
| CVE-2026-45021 | 5.1 | 10.7 | kumahq | kuma | CWE-346 | Kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + Loca… |
| CVE-2026-9881 | 9.0 | 10.5 | Google | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 a… |
| CVE-2026-46166 | 8.8 | 10.5 | Linux | Linux | CWE-416 | wifi: mac80211: use safe list iteration in radar detect work |
| CVE-2026-9090 | 9.1 | 10.3 | Casdoor | Casdoor | — | CVE-2026-9090 |
| CVE-2026-45348 | 8.7 | 10.0 | pyload | pyload | CWE-79 | pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js … |
| CVE-2026-49093 | 7.7 | 10.1 | Elastic | Kibana | CWE-918 | Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network … |
| CVE-2026-47673 | 6.5 | 10.0 | honojs | hono | CWE-285 | Hono: JWT middleware accepts any Authorization scheme, not only Bearer |
| CVE-2026-9942 | 5.0 | 10.0 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-9950 | 3.1 | 10.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in iOS in Google Chrome on iOS pri… |
| CVE-2026-10020 | 8.3 | 9.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Skia in Google Chrome on Androi… |
| CVE-2026-9944 | 3.1 | 9.8 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a… |
| CVE-2026-9955 | 4.3 | 9.4 | Google | Chrome | CWE-200 | Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.77… |
| CVE-2026-9807 | 4.3 | 9.3 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-45403 | 2.5 | 9.3 | Mintplex-Labs | anything-llm | CWE-59 | AnythingLLM: filesystem-copy-file follows nested symlinks and copies files fr… |
| CVE-2026-9981 | 6.5 | 9.0 | Google | Chrome | CWE-200 | Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216… |
| CVE-2026-9996 | 6.5 | 9.0 | Google | Chrome | CWE-125 | Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 … |
| CVE-2026-10018 | 6.5 | 9.0 | Google | Chrome | CWE-472 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-47760 | 5.4 | 9.1 | tinymce | tinymce | CWE-79 | TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass th… |
| CVE-2026-9930 | 4.3 | 9.0 | Google | Chrome | CWE-787 | Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 a… |
| CVE-2026-10019 | 8.8 | 8.9 | Google | Chrome | CWE-472 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a … |
| CVE-2026-9796 | 6.5 | 8.5 | Red Hat | Red Hat build of Keycloak 26.6 | CWE-367 | Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (to… |
| CVE-2026-9039 | 8.6 | 8.4 | XCharge | C6 | CWE-1188 | Initialization of a resource with an insecure default in XCharge C6 |
| CVE-2026-10000 | 8.3 | 8.4 | Google | Chrome | CWE-416 | Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.2… |
| CVE-2026-10014 | 8.3 | 8.4 | Google | Chrome | CWE-416 | Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216… |
| CVE-2026-10017 | 8.3 | 8.4 | Google | Chrome | CWE-125 | Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allow… |
| CVE-2026-9977 | 8.3 | 8.3 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in WebShare in Google Chrome on An… |
| CVE-2026-9982 | 8.3 | 8.3 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-46842 | 5.3 | 8.2 | Oracle Corporation | Oracle REST Data Services | CWE-284 | Vulnerability in Oracle REST Data Services (component: Core). Supported versi… |
| CVE-2026-9994 | 8.3 | 8.0 | Google | Chrome | CWE-416 | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 al… |
| CVE-2026-9985 | 5.3 | 8.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Chrom… |
| CVE-2026-44358 | 8.2 | 8.0 | espressif | shared-github-dangerjs | CWE-427 | Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action En… |
| CVE-2026-10028 | 4.3 | 7.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-835 | Glib-networking: infinite loop in glib-networking gnutls backend allows remot… |
| CVE-2026-10002 | 8.8 | 7.9 | Google | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a r… |
| CVE-2026-9997 | 8.3 | 7.6 | Google | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-44794 | 5.4 | 7.5 | nautobot | nautobot | CWE-862 | Nautobot: REST API permits creation of GenericForeignKey references to object… |
| CVE-2026-46561 | 5.0 | 7.3 | pyload | pyload | CWE-918 | pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API |
| CVE-2026-9988 | 8.3 | 7.0 | Google | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 al… |
| CVE-2026-9998 | 8.3 | 7.0 | Google | Chrome | CWE-472 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a r… |
| CVE-2026-10001 | 8.3 | 7.0 | Google | Chrome | CWE-416 | Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216… |
| CVE-2026-10012 | 8.3 | 7.0 | Google | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem… |
| CVE-2026-9990 | 7.5 | 7.0 | Google | Chrome | CWE-416 | Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.… |
| CVE-2026-46152 | 8.8 | 6.4 | Linux | Linux | CWE-1058 | wifi: mac80211: drop stray 'static' from fast-RX rx_result |
| CVE-2026-9673 | 5.5 | 6.3 | n/a | json-2-csv | CWE-1236 | Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerab… |
| CVE-2026-9993 | 8.3 | 6.1 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a re… |
| CVE-2026-10004 | 6.5 | 6.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Passwords in Google Chrome prio… |
| CVE-2026-10011 | 3.1 | 6.0 | Google | Chrome | CWE-200 | Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216… |
| CVE-2026-9903 | 5.0 | 5.8 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Site Isolation in Google Chrome… |
| CVE-2026-9971 | 5.4 | 5.6 | Google | Chrome | CWE-79 | Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.77… |
| CVE-2026-9793 | 7.5 | 5.4 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-347 | Keycloak: keycloak: security policy bypass in jwe-encrypted request object pr… |
| CVE-2026-9646 | 6.1 | 5.5 | ScadaBR | ScadaBR | CWE-80 | ScadaBR Unauthenticated Reflected Cross-Site Scripting |
| CVE-2026-9644 | 6.4 | 5.3 | nhadjidimitrov | LiveSmart Video Chat Live Video Chat | CWE-79 | LiveSmart Video Chat <= 1.2 - Authenticated (Contributor+) Stored Cross-Site … |
| CVE-2026-46113 | 8.8 | 5.1 | Linux | Linux | CWE-416 | KVM: x86: Fix shadow paging use-after-free due to unexpected GFN |
| CVE-2026-32996 | 7.3 | 5.0 | Veeam | Backup and Replication | CWE-532 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Priv… |
| CVE-2026-45307 | 6.1 | 5.0 | murtaza-nasir | speakr | CWE-601 | Speakr: Open redirect in is_safe_url via parser mismatch on next parameter |
| CVE-2026-9789 | 8.5 | 4.8 | Acer | NitrorSense V3 | CWE-22 | NitroSense V3: Security Vulnerability Information |
| CVE-2026-45040 | 5.3 | 4.9 | rustfs | rustfs | CWE-312 | RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in R… |
| CVE-2026-10022 | 7.5 | 4.8 | Google | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an atta… |
| CVE-2026-9986 | 4.2 | 4.2 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in OptimizationGuide in Google Chr… |
| CVE-2026-46189 | 7.8 | 4.2 | Linux | Linux | CWE-415 | RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path |
| CVE-2026-46145 | 7.8 | 4.0 | Linux | Linux | CWE-787 | RDMA/mana: Validate rx_hash_key_len |
| CVE-2026-46176 | 7.8 | 4.0 | Linux | Linux | CWE-825 | RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() |
| CVE-2026-46123 | 7.7 | 4.0 | Linux | Linux | CWE-787 | Bluetooth: virtio_bt: clamp rx length before skb_put |
| CVE-2026-46150 | 7.1 | 4.0 | Linux | Linux | — | fanotify: fix false positive on permission events |
| CVE-2026-46205 | 7.8 | 3.9 | Linux | Linux | — | staging: media: atomisp: Disallow all private IOCTLs |
| CVE-2026-49237 | 7.8 | 4.0 | Canonical | Multipass | CWE-276 | Local Privilege Escalation in Canonical Multipass |
| CVE-2026-4377 | 6.0 | 3.9 | D-Link Corporation | DWR-X1820 | CWE-1391 | Use of Weak Credentials in D-Link DWR-X1820 router |