| CVE-2026-35193 | 2.3 | 29.0 | djangoproject | Django | CWE-524 | Potential exposure of private data via missing Vary: Authorization in UpdateC… |
| CVE-2026-48587 | 2.3 | 28.5 | djangoproject | Django | CWE-1023 | Potential exposure of private data via whitespace padding in Vary header |
| CVE-2025-14771 | 7.3 | 27.8 | ABB | T-MAC Plus | CWE-552 | File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Serve… |
| CVE-2026-46266 | 9.1 | 27.6 | Linux | Linux | — | inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP |
| CVE-2026-42317 | 7.0 | 27.6 | glpi-project | glpi | CWE-862 | GLPI vulnerable to arbitrary files deletion by technician |
| CVE-2026-42321 | 8.4 | 27.3 | glpi-project | glpi | CWE-79 | GLPI has stored XSS in asset locks |
| CVE-2026-37460 | 7.5 | 26.4 | n/a | n/a | CWE-20 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRR… |
| CVE-2026-44545 | 7.5 | 25.6 | djangoproject | daphne | CWE-770 | Unbounded WebSocket message and frame sizes can cause unauthenticated remote … |
| CVE-2026-5078 | 5.3 | 25.4 | morgan | morgan | CWE-117 | morgan vulnerable to Log Forging via unneutralized control characters in :rem… |
| CVE-2026-46244 | 9.1 | 25.0 | Linux | Linux | CWE-823 | netfilter: nft_inner: Fix IPv6 inner_thoff desync |
| CVE-2022-31114 | 5.1 | 22.9 | Laravel-Backpack | CRUD | CWE-79 | backpack/crud Vulnerable to Cross-site Scripting |
| CVE-2026-10694 | 5.5 | 22.8 | SourceCodester | Online Food Ordering System | CWE-73 | SourceCodester Online Food Ordering System index.php include file inclusion |
| CVE-2026-26378 | 5.4 | 22.6 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote a… |
| CVE-2026-36748 | 9.0 | 22.2 | n/a | n/a | CWE-79 | RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS… |
| CVE-2024-47263 | 4.1 | 22.3 | Synology | Hyper Backup | CWE-22 | An improper limitation of a pathname to a restricted directory ('Path Travers… |
| CVE-2026-10771 | 5.5 | 21.9 | crmeb | crmeb_java | CWE-918 | crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.ge… |
| CVE-2025-14772 | 7.3 | 21.7 | ABB | T-MAC Plus | CWE-639 | Broken Access Control in ABB T-MAC Plus web application |
| CVE-2025-70101 | 6.5 | 21.7 | n/a | n/a | CWE-125 | An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_exte… |
| CVE-2026-42318 | 7.0 | 21.7 | glpi-project | glpi | CWE-862 | GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint |
| CVE-2026-47324 | 5.1 | 21.6 | ProjectsAndPrograms | school-management-system | CWE-79 | Stored XSS in Multiple Points in ProjectsAndPrograms school-management-system |
| CVE-2026-10705 | 2.3 | 21.2 | n/a | dask | CWE-400 | dask HLL hyperloglog.py nunique_approx resource consumption |
| CVE-2026-8404 | 2.3 | 20.9 | djangoproject | Django | CWE-178 | Potential exposure of private data via case-sensitive Cache-Control directive… |
| CVE-2026-10704 | 5.5 | 20.5 | SourceCodester | Pizzafy E-Commerce System | CWE-74 | SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_c… |
| CVE-2026-37462 | 7.5 | 20.4 | n/a | n/a | CWE-190 | An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) … |
| CVE-2026-40495 | 6.9 | 20.3 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling version exposed via asset cache buster |
| CVE-2024-47273 | 4.3 | 20.2 | Synology | Hyper Backup | CWE-22 | An improper limitation of a pathname to a restricted directory ('Path Travers… |
| CVE-2026-39107 | 6.3 | 19.2 | n/a | n/a | CWE-79 | A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface… |
| CVE-2026-46447 | 7.7 | 18.1 | OpenStack | Ironic | CWE-669 | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script… |
| CVE-2026-42839 | 4.8 | 17.9 | Frappe | ERPNext | CWE-79 | ERPNext 16.16.0 - Stored XSS in POS cart item rendering |
| CVE-2026-41032 | 7.5 | 17.8 | Phoenix Contact | CHARX SEC-3150 | CWE-200 | Phoenix Contact: Unauthenticated log download vulnerability in the firmware o… |
| CVE-2026-43924 | 4.8 | 17.7 | FOSSBilling | FOSSBilling | CWE-601 | FOSSBilling has an open redirect via administrator-configured redirect targets |
| CVE-2026-36604 | 6.5 | 17.1 | n/a | n/a | CWE-350 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not vali… |
| CVE-2026-9334 | 7.3 | 16.9 | RURBAN | Cpanel::JSON::XS | CWE-843 | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via dupli… |
| CVE-2026-44281 | 7.0 | 16.7 | glpi-project | glpi | CWE-862 | GLPI vulnerable to unauthorized reading of a specific asset object |
| CVE-2026-8889 | 7.5 | 16.5 | Securly | Securly Chrome Extension | CWE-407 | CVE-2026-8889 |
| CVE-2026-47325 | 6.9 | 16.5 | ProjectsAndPrograms | school-management-system | CWE-1391 | Weak password policy in ProjectsAndPrograms school-management-system |
| CVE-2026-6873 | 2.3 | 16.0 | djangoproject | Django | CWE-347 | Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_… |
| CVE-2026-26379 | 6.5 | 15.7 | n/a | n/a | CWE-918 | Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulner… |
| CVE-2026-42840 | 5.1 | 15.7 | Frappe | ERPNext | CWE-79 | ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template l… |
| CVE-2026-10703 | 2.1 | 15.8 | EIPStackGroup | OpENer | CWE-119 | EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequest… |
| CVE-2026-8876 | 7.3 | 15.5 | Securly | Securly Chrome Extension | CWE-798 | CVE-2026-8876 |
| CVE-2026-42320 | 5.9 | 15.2 | glpi-project | glpi | CWE-862 | GLPI vulnerable to arbitrary file access |
| CVE-2026-22054 | 5.3 | 14.9 | NETAPP | Active IQ Config Advisor | CWE-259 | Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that c… |
| CVE-2026-22055 | 5.3 | 14.9 | NETAPP | Active IQ OneCollect | CWE-259 | Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could… |
| CVE-2025-15656 | 8.8 | 14.3 | Mojoomla | School Management | CWE-266 | WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerabi… |
| CVE-2025-15655 | 7.6 | 14.1 | Mojoomla | School Management | CWE-89 | WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability |
| CVE-2026-36611 | 7.3 | 14.2 | n/a | n/a | CWE-200 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of… |
| CVE-2026-26824 | 6.5 | 13.8 | n/a | n/a | CWE-457 | libxls through version 1.6.3 contains a use of uninitialized memory vulnerabi… |
| CVE-2026-26825 | 5.3 | 12.0 | n/a | n/a | CWE-908 | A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsi… |
| CVE-2026-10693 | 2.1 | 12.0 | SourceCodester | Online Boat Reservation System | CWE-266 | SourceCodester Online Boat Reservation System Administrative Endpoint imprope… |
| CVE-2026-36603 | 8.1 | 11.6 | n/a | n/a | CWE-306 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of… |
| CVE-2026-8878 | 7.5 | 11.6 | Securly | Securly Chrome Extension | CWE-326 | CVE-2026-8878 |
| CVE-2026-10729 | 1.2 | 10.7 | Thinkst Applied Research | Canarytokens | CWE-74 | HTML injection in the notification email for "Slow Redirect" and "Cloned Webs… |
| CVE-2026-8722 | 6.5 | 10.6 | TEAM | Net::Async::Statsd::Client | CWE-93 | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injec… |
| CVE-2019-25720 | 7.1 | 10.1 | Dräger | SC 6002XL | CWE-1286 | Dräger SC Monitoring Devices DoS via Malformed Network Packet |
| CVE-2026-6657 | 8.8 | 9.7 | jupyter | jupyter/jupyter | CWE-346 | CORS Origin Validation Bypass in jupyter-server |
| CVE-2026-40290 | 7.8 | 8.6 | OP-TEE | optee_os | CWE-416 | OP-TEE has a Use-After-Free race in FF-A shared-memory teardown |
| CVE-2026-37700 | 4.1 | 8.5 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote att… |
| CVE-2026-20233 | 6.1 | 8.3 | Cisco | Cisco Webex Meetings | CWE-79 | Cisco Webex Meetings Cross-Site Scripting Vulnerability |
| CVE-2026-36607 | 8.8 | 8.0 | n/a | n/a | CWE-307 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauth… |
| CVE-2026-36608 | 8.8 | 8.0 | n/a | n/a | CWE-441 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP A… |
| CVE-2025-14773 | 7.2 | 7.9 | ABB | T-MAC Plus | CWE-79 | Stored Cross-Site Scripting in ABB T-MAC Plus web application |
| CVE-2025-14774 | 7.2 | 7.9 | ABB | T-MAC Plus | CWE-863 | Communication analysis between the Card Reader and TP2CardReaderService daemon |
| CVE-2026-20175 | 6.1 | 7.8 | Cisco | Cisco Finesse | CWE-73 | Cisco Finesse File Inclusion Vulnerability |
| CVE-2026-36460 | 4.8 | 7.9 | n/a | n/a | CWE-79 | Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Sit… |
| CVE-2026-10722 | 1.9 | 7.7 | cilium | ebpf | CWE-189 | cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpe… |
| CVE-2026-36605 | 6.5 | 7.5 | n/a | n/a | CWE-400 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable… |
| CVE-2026-7888 | 8.4 | 7.2 | Concrete CMS | Concrete CMS | CWE-502 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserializ… |
| CVE-2026-44546 | 5.3 | 7.0 | djangoproject | daphne | CWE-444 | Header injection via WebSocket upgrade parser differential allows ASGI scope … |
| CVE-2026-36609 | 7.3 | 6.2 | n/a | n/a | CWE-327 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static… |
| CVE-2026-36602 | 4.3 | 6.3 | n/a | n/a | CWE-200 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses ker… |
| CVE-2026-36615 | 4.3 | 6.3 | n/a | n/a | CWE-200 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumen… |
| CVE-2026-8881 | 7.5 | 5.9 | Securly | Securly Chrome Extension | — | CVE-2026-8881 |
| CVE-2025-70100 | 5.5 | 5.8 | n/a | n/a | CWE-369 | A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/… |
| CVE-2026-36613 | 4.3 | 5.5 | n/a | n/a | CWE-125 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of… |
| CVE-2026-36618 | 4.3 | 5.5 | n/a | n/a | CWE-200 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.… |
| CVE-2026-45702 | 5.5 | 5.2 | OP-TEE | optee_os | CWE-843 | OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic |
| CVE-2026-7666 | 2.3 | 4.7 | djangoproject | Django | CWE-319 | Potential unencrypted email transmission via STARTTLS in the SMTP backend |
| CVE-2026-36610 | 5.9 | 4.5 | n/a | n/a | CWE-319 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS crede… |
| CVE-2025-71314 | 5.5 | 4.4 | Linux | Linux | — | drm/panthor: Recover from panthor_gpu_flush_caches() failures |
| CVE-2025-15654 | 7.1 | 4.4 | Fox-themes | Prague | CWE-79 | WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-36612 | 6.4 | 3.8 | n/a | n/a | CWE-307 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by d… |
| CVE-2026-8874 | 7.1 | 3.6 | Securly | Securly Chrome Extension | CWE-319 | CVE-2026-8874 |
| CVE-2026-36574 | 7.8 | 3.6 | n/a | n/a | CWE-427 | A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 al… |
| CVE-2026-36616 | 5.9 | 3.6 | n/a | n/a | CWE-798 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded W… |
| CVE-2026-46253 | 7.8 | 3.5 | Linux | Linux | CWE-787 | pstore/ram: fix buffer overflow in persistent_ram_save_old() |
| CVE-2026-46251 | 8.4 | 3.2 | Linux | Linux | — | btrfs: fix block_group_tree dirty_list corruption |
| CVE-2023-52951 | 5.9 | 3.1 | Synology | Synology Note Station Client | CWE-319 | A cleartext transmission of sensitive information vulnerability in Synology N… |
| CVE-2026-46270 | 8.4 | 3.0 | Linux | Linux | CWE-416 | power: supply: rt9455: Fix use-after-free in power_supply_changed() |
| CVE-2026-46250 | 7.3 | 2.9 | Linux | Linux | — | MIPS: Work around LLVM bug when gp is used as global register variable |
| CVE-2026-46246 | 7.8 | 2.7 | Linux | Linux | CWE-416 | power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler |
| CVE-2022-49036 | 7.8 | 2.5 | Synology | Synology Active Backup for Business Recovery Media Creator | CWE-829 | An inclusion of functionality from untrusted control sphere vulnerability in … |
| CVE-2022-49042 | 7.8 | 2.5 | Synology | Synology Hyper Backup Explorer | CWE-829 | An inclusion of functionality from untrusted control sphere vulnerability in … |
| CVE-2026-46247 | 5.5 | 2.5 | Linux | Linux | — | clk: qcom: gfx3d: add parent to parent request map |
| CVE-2026-46267 | 7.8 | 2.3 | Linux | Linux | CWE-416 | nfc: hci: shdlc: Stop timers and work before freeing context |
| CVE-2026-46248 | 5.5 | 2.3 | Linux | Linux | — | wifi: ath12k: clear stale link mapping of ahvif->links_map |
| CVE-2026-46259 | 7.8 | 2.2 | Linux | Linux | — | procfs: fix missing RCU protection when reading real_parent in do_task_stat() |
| CVE-2026-46260 | 7.8 | 2.1 | Linux | Linux | CWE-125 | ipv6: Fix out-of-bound access in fib6_add_rt2node(). |
| CVE-2026-46263 | 7.8 | 2.1 | Linux | Linux | CWE-125 | drm/amd/display: Fix out-of-bounds stream encoder index v3 |
| CVE-2026-10775 | 1.1 | 2.2 | sgl-project | SGLang | CWE-404 | sgl-project SGLang Cache data_hash denial of service |
| CVE-2026-46271 | 7.8 | 2.1 | Linux | Linux | — | wifi: ath12k: do WoW offloads only on primary link |
| CVE-2026-44682 | 7.3 | 1.8 | Acronis | Acronis DeviceLock DLP | CWE-427 | Local privilege escalation due to DLL hijacking vulnerability. The following … |
| CVE-2026-50033 | 7.3 | 1.8 | Acronis | Acronis DeviceLock DLP | CWE-427 | Local privilege escalation due to DLL hijacking vulnerability. The following … |
| CVE-2026-46249 | 5.5 | 1.8 | Linux | Linux | — | octeontx2-af: Fix PF driver crash with kexec kernel booting |
| CVE-2026-46254 | 5.5 | 1.7 | Linux | Linux | — | AppArmor: Allow apparmor to handle unaligned dfa tables |
| CVE-2026-46255 | 5.5 | 1.7 | Linux | Linux | — | dmaengine: fsl-edma: don't explicitly disable clocks in .remove() |
| CVE-2026-46261 | 5.5 | 1.7 | Linux | Linux | CWE-476 | spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe() |
| CVE-2026-46268 | 5.5 | 1.6 | Linux | Linux | — | PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition |
| CVE-2026-46269 | 5.5 | 1.6 | Linux | Linux | CWE-476 | pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree |
| CVE-2026-46264 | 8.8 | 1.6 | Linux | Linux | CWE-416 | drm/xe/pf: Fix sysfs initialization |
| CVE-2026-46245 | 5.5 | 1.4 | Linux | Linux | CWE-476 | drm/amd/display: Fix dc_link NULL handling in HPD init |
| CVE-2025-71313 | 5.5 | 1.3 | Linux | Linux | CWE-476 | PCI: endpoint: Add missing NULL check for alloc_workqueue() |
| CVE-2025-60477 | 5.0 | 1.3 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex func… |
| CVE-2026-42061 | 7.3 | 1.2 | Acronis | Acronis DeviceLock DLP | CWE-250 | Local privilege escalation due to excessive permissions assigned to child pro… |
| CVE-2026-44609 | 7.3 | 1.2 | Acronis | Acronis DeviceLock DLP | CWE-427 | Local privilege escalation due to EXE hijacking vulnerability. The following … |
| CVE-2026-10783 | 1.1 | 1.3 | gradio-app | gradio | CWE-327 | gradio-app gradio Audio Cache Key save_audio_to_cache weak hash |
| CVE-2026-36606 | 7.1 | 1.2 | n/a | n/a | CWE-798 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts conf… |
| CVE-2025-41259 | 7.3 | 1.0 | sbabic | SWUpdate | CWE-367 | SWUpdate Untrusted Script Execution via Signed Update TOCTOU |
| CVE-2026-46257 | 5.5 | 1.0 | Linux | Linux | CWE-908 | clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is calle… |
| CVE-2026-46258 | 5.5 | 1.0 | Linux | Linux | CWE-476 | gpio: cdev: Avoid NULL dereference in linehandle_create() |
| CVE-2026-46256 | 5.5 | 1.0 | Linux | Linux | CWE-667 | NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages |
| CVE-2026-45614 | 4.7 | 0.8 | OP-TEE | optee_os | CWE-347 | OP-TEE vulnerable to ECDH private key recovery |
| CVE-2026-46252 | 5.5 | 0.6 | Linux | Linux | CWE-667 | regulator: core: fix locking in regulator_resolve_supply() error path |
| CVE-2026-46262 | 5.5 | 0.6 | Linux | Linux | CWE-667 | ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr_mode_put() |
| CVE-2026-46272 | 4.7 | 0.5 | Linux | Linux | CWE-362 | coresight: tmc-etr: Fix race condition between sysfs and perf mode |
| CVE-2026-10766 | 1.1 | 0.1 | n/a | mlrun | CWE-327 | mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash … |