| CVE-2026-47633 | 7.5 | 44.5 | Microsoft | Microsoft Cost Management | CWE-200 | Microsoft Cost Management Information Disclosure Vulnerability |
| CVE-2026-9860 | 8.8 | 44.0 | vanyukov | Offload, AI & Optimize with Cloudflare Images | CWE-434 | Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Auth… |
| CVE-2026-56022 | 6.9 | 43.7 | Webmin | Webmin | CWE-308 | Webmin MFA bypass |
| CVE-2026-8024 | 9.3 | 43.6 | iba | ibaPDA | CWE-502 | Deserialization vulnerability in ibaPDA and ibaDatCoordinator |
| CVE-2026-8100 | 8.6 | 43.4 | Progress Chef | Chef360 | CWE-23 | Impact A security issue has been identified in Chef 360 that could allow unau… |
| CVE-2026-48937 | 7.5 | 42.6 | nodejs | node | CWE-400 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data … |
| CVE-2025-32392 | 8.7 | 42.4 | Significant-Gravitas | AutoGPT | CWE-400 | AutoGPT has a DoS vulnerability in LoopVideoBlock |
| CVE-2026-55205 | 6.9 | 42.0 | nesquena | hermes-webui | CWE-770 | Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow … |
| CVE-2026-54017 | 7.7 | 41.9 | open-webui | open-webui | CWE-22 | Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path t… |
| CVE-2026-44688 | 8.4 | 41.0 | Eclipse Foundation | Eclipse Theia | CWE-829 | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed worksp… |
| CVE-2026-46580 | 8.4 | 41.0 | Eclipse Foundation | Eclipse Theia | CWE-829 | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompt… |
| CVE-2026-54105 | 6.9 | 40.8 | Government Accountability Office | Electronic Protest Docketing System (EPDS) | CWE-639 | U.S. GAO EPDS and CBCA EDS user information disclosure |
| CVE-2026-56020 | 9.2 | 40.3 | Webmin | Webmin | CWE-290 | Webmin HTTP header authentication bypass |
| CVE-2026-54106 | 5.1 | 40.0 | Government Accountability Office | Electronic Protest Docketing System (EPDS) | CWE-940 | U.S. GAO EPDS and CBCA EDS network access control bypass |
| CVE-2026-10736 | 4.9 | 39.9 | themeum | Tutor LMS – eLearning and online course solution | CWE-89 | Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data'… |
| CVE-2026-55204 | 8.7 | 39.6 | haproxy | haproxy | CWE-476 | HAProxy - NULL Pointer Dereference in hpack_dht_insert Function |
| CVE-2026-47846 | 9.8 | 39.5 | Bitnami | bitnami/cassandra | CWE-798 | Bitnami Cassandra container images are affected by a retained default superus… |
| CVE-2026-12045 | 9.4 | 39.5 | pgadmin.org | pgAdmin 4 | CWE-77 | pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writ… |
| CVE-2026-56021 | 6.9 | 39.1 | Webmin | Webmin | CWE-185 | Webmin information disclosure via regex pattern |
| CVE-2026-11982 | 5.1 | 39.0 | Grav | grav-plugin-api | CWE-79 | Stored XSS via missing XSS safety check in Admin2 Pages API partial validation |
| CVE-2026-11360 | 4.9 | 39.0 | algolplus | Advanced Order Export For WooCommerce | CWE-89 | Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager… |
| CVE-2026-49252 | 9.9 | 38.7 | deepstreamIO | deepstream.io | CWE-1321 | deepstream is vulnerable to prototype pollution |
| CVE-2026-38718 | 7.5 | 37.9 | n/a | n/a | CWE-120 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlie… |
| CVE-2026-43994 | 9.8 | 37.4 | coturn | coturn | CWE-120 | Coturn: Stack buffer overflow in decode_oauth_token_gcm() |
| CVE-2026-56077 | 7.1 | 37.0 | PraisonAI | PraisonAI | CWE-668 | PraisonAI - Information Disclosure via Shared MultiAgentLedger State |
| CVE-2026-54419 | 9.3 | 36.8 | claudiopizzillo | PIAF-HMS | CWE-89 | PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query |
| CVE-2025-32422 | 8.7 | 35.7 | Significant-Gravitas | AutoGPT | CWE-400 | AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock |
| CVE-2025-32424 | 8.7 | 35.7 | Significant-Gravitas | AutoGPT | CWE-400 | AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock |
| CVE-2025-32437 | 8.7 | 35.7 | Significant-Gravitas | AutoGPT | CWE-400 | AutoGPT has a DoS vulnerability in MediaDurationBlock |
| CVE-2026-50141 | 7.1 | 35.6 | woodpecker-ci | woodpecker | CWE-290 | Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent imperson… |
| CVE-2026-56099 | 6.9 | 35.3 | openbsd | src | CWE-125 | OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input |
| CVE-2026-48716 | 8.7 | 35.2 | HKUDS | nanobot | CWE-22 | nanobot: Path traversal via unsanitized WhatsApp document fileName enables ar… |
| CVE-2026-9692 | 5.3 | 35.0 | HAYAJO | Mojolicious::Sessions::Storable | CWE-338 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate sessi… |
| CVE-2026-44942 | 6.5 | 34.8 | SUSE | libzypp | CWE-24 | libzypp .repo files can have an optional path which can lead to path traversa… |
| CVE-2026-32174 | 8.8 | 34.2 | Microsoft | Azure AI Bot Service | CWE-287 | Azure Bot Service Elevation of Privilege Vulnerability |
| CVE-2026-44691 | 8.4 | 34.0 | Eclipse Foundation | Eclipse Theia | CWE-829 | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspa… |
| CVE-2025-10560 | 9.3 | 32.0 | Silver Leaf Technologies, Inc. | Worksnaps.net Worksnaps | CWE-798 | Hardcoded cloud credentials in Worksnaps client application binaries expose p… |
| CVE-2026-49205 | 6.5 | 31.6 | thorsten | phpMyFAQ | CWE-862 | phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-2442… |
| CVE-2025-32436 | 7.1 | 31.3 | Significant-Gravitas | AutoGPT | CWE-400 | AutoGPT has a DoS vulnerability in AddAudioToVideoBlock |
| CVE-2026-12407 | 8.8 | 30.7 | oleksandrz | E2Pdf – Export Pdf Tool for WordPress | CWE-862 | E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary… |
| CVE-2026-56012 | 8.5 | 28.8 | David Lingren | Media LIbrary Assistant | CWE-89 | WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability |
| CVE-2026-42488 | 8.1 | 28.4 | Xen | Xen | CWE-119 | x86: mismatched mapcache metadata |
| CVE-2026-12093 | 5.3 | 28.2 | wpinsider-1 | Simple Membership | CWE-862 | Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitra… |
| CVE-2026-52866 | 7.1 | 27.8 | Apollo Pharmacy | Blood Glucose Monitoring System (Model No. APG-01 BT) | CWE-862 | Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Missing Authorization |
| CVE-2026-55203 | 9.0 | 27.8 | haproxy | haproxy | CWE-190 | HAProxy - Integer Overflow in FCGI Demux Record Length Field |
| CVE-2026-11776 | 4.9 | 27.5 | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | CWE-89 | Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection… |
| CVE-2026-11777 | 4.9 | 27.5 | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | CWE-89 | Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection… |
| CVE-2026-12120 | 5.3 | 26.0 | fireplugins | FireBox Popups – Increase Sales and Grow Your Email List | CWE-200 | FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in '… |
| CVE-2026-46699 | 7.6 | 25.9 | conda-forge | conda-smithy | CWE-284 | conda-smithy vulnerable to misrouted repository invitation by conda-forge-web… |
| CVE-2026-12050 | 5.3 | 25.0 | pgadmin.org | pgAdmin 4 | CWE-89 | pgAdmin 4: SQL injection in named restore point endpoint |
| CVE-2026-11357 | 4.3 | 25.0 | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | CWE-200 | Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information … |
| CVE-2026-55237 | 8.8 | 24.6 | Significant-Gravitas | AutoGPT | CWE-87 | AutoGPT SignUp Page has DOM-Based XSS and Open Redirect |
| CVE-2026-8811 | 7.1 | 24.6 | SEPPmail AG | Secure Email Gateway | CWE-22 | Path traversal in PDF generation module |
| CVE-2026-40457 | 2.1 | 24.6 | LMS | LMS | CWE-79 | Reflected XSS in LMS |
| CVE-2026-47847 | 5.3 | 24.0 | Bitnami | bitnami/mariadb-galera | CWE-798 | Bitnami MariaDB Galera container images and Helm chart are affected by a hard… |
| CVE-2026-22551 | 6.7 | 23.9 | Eclipse Foundation | Eclipse Theia | CWE-201 | In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown imag… |
| CVE-2026-10029 | 5.3 | 23.7 | eventkoi | Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets | CWE-862 | Event Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensiti… |
| CVE-2026-22674 | 4.8 | 23.6 | hashgraph | guardian | CWE-79 | Hashgraph Guardian Stored XSS via branding companyName field |
| CVE-2026-54222 | 8.6 | 23.1 | UBB Systems | UBB.threads | CWE-89 | Blind SQL Injection in UBB.threads |
| CVE-2026-9158 | 5.2 | 23.0 | Eclipse Foundation | Eclipse 4diac | CWE-416 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE co… |
| CVE-2026-54219 | 5.1 | 21.9 | UBB Systems | UBB.threads | CWE-79 | Stored XSS in UBB.threads |
| CVE-2026-54221 | 5.1 | 21.8 | UBB Systems | UBB.threads | CWE-79 | Reflected XSS in UBB.threads |
| CVE-2026-45696 | 8.3 | 21.8 | AcademySoftwareFoundation | openexr | CWE-122 | OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS) |
| CVE-2026-11395 | 7.2 | 21.4 | mariovalney | CF7 to Webhook | CWE-918 | CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7… |
| CVE-2025-58175 | 8.2 | 21.2 | geoserver | org.geoserver.web:gs-web-app | CWE-20 | GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML E… |
| CVE-2026-55740 | 9.3 | 20.6 | Nur-Alam39 | bus-ticket | CWE-89 | SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter |
| CVE-2026-12111 | 4.3 | 20.1 | codepeople | Appointment Booking Calendar | CWE-200 | Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensiti… |
| CVE-2026-54224 | 7.1 | 19.6 | UBB Systems | UBB.threads | CWE-405 | Denial of Service in UBB.threads |
| CVE-2026-12102 | 2.7 | 19.6 | stiofansisland | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | CWE-639 | UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor… |
| CVE-2026-8668 | 2.3 | 19.3 | Progress Chef | Chef360 | CWE-523 | Hardcoded credentials in embedded content |
| CVE-2026-11358 | 4.4 | 18.4 | themeisle | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More | CWE-79 | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fon… |
| CVE-2026-10623 | 4.3 | 16.9 | pressprimer | PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin | CWE-639 | PressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated… |
| CVE-2026-12527 | 6.0 | 15.7 | Shenzhen Liandian Communication Technology LTD | V380 IP Camera / AppFHE1_V1.0.6.0 | CWE-306 | A broken authorization boundary in the RTSP media delivery pipeline of Shenzh… |
| CVE-2026-10023 | 4.3 | 15.7 | dokaninc | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy | CWE-639 | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Ins… |
| CVE-2026-43915 | 5.4 | 15.3 | coturn | coturn | CWE-79 | Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN use… |
| CVE-2026-48617 | 1.8 | 15.4 | nodejs | node | CWE-284 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.rep… |
| CVE-2026-9199 | 4.3 | 15.1 | equalizedigital | Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance | CWE-862 | Equalize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to A… |
| CVE-2026-11784 | 4.3 | 13.8 | optimole | Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization | CWE-352 | Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Op… |
| CVE-2026-49454 | 9.1 | 13.5 | szTheory | relyra | CWE-287 | Relyra SAML SignatureValue not cryptographically verified -> authentication b… |
| CVE-2026-12049 | 5.3 | 12.5 | pgadmin.org | pgAdmin 4 | CWE-601 | pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated … |
| CVE-2026-40455 | 8.6 | 12.3 | LMS | LMS | CWE-89 | SQL Injection in LMS |
| CVE-2026-9815 | 6.5 | 12.2 | Unknown | MagicForm | — | MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE |
| CVE-2026-11791 | 5.0 | 11.8 | Red Hat | Red Hat Directory Server 11 | CWE-416 | 389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swa… |
| CVE-2026-12137 | 6.1 | 11.6 | phppoet | SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager | CWE-79 | SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Sit… |
| CVE-2026-12048 | 9.3 | 11.5 | pgadmin.org | pgAdmin 4 | CWE-79 | pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through… |
| CVE-2026-50034 | 7.1 | 11.3 | Apollo Pharmacy | Blood Glucose Monitoring System (Model No. APG-01 BT) | CWE-319 | Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmiss… |
| CVE-2026-11402 | 6.4 | 10.9 | bplugins | Services Section Block – Showcase Service Details in Grid or Columns | CWE-79 | Services Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-42490 | 6.5 | 10.2 | Xen | Xen | CWE-667 | domctl lock open to abuse |
| CVE-2026-44663 | 7.1 | 10.1 | AcademySoftwareFoundation | openexr | CWE-190 | OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow |
| CVE-2026-2021 | 6.4 | 10.1 | contrid | Slideshow Gallery LITE | CWE-79 | Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-25865 | 8.5 | 9.9 | Yandex | Punto Switcher | CWE-428 | Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec |
| CVE-2026-12098 | 6.4 | 9.7 | blubrry | PowerPress Podcasting plugin by Blubrry | CWE-79 | PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) … |
| CVE-2026-12136 | 6.4 | 8.7 | phppoet | SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager | CWE-79 | SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Cont… |
| CVE-2026-54220 | 8.6 | 8.6 | UBB Systems | UBB.threads | CWE-352 | Cross-Site Request Forgery in UBB.threads |
| CVE-2026-11718 | 9.3 | 8.3 | Google | MCP Toolbox for Databases (googleapis/mcp-toolbox) | CWE-287 | An authentication bypass vulnerability exists in the generic opaque token val… |
| CVE-2026-8039 | 6.4 | 8.0 | dijitul | Fancy Testimonials | CWE-79 | Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting |
| CVE-2026-11717 | 9.3 | 7.5 | Google | MCP Toolbox for Databases (googleapis/mcp-toolbox) | CWE-287 | An authentication bypass vulnerability exists in the generic opaque token val… |
| CVE-2026-56024 | 6.5 | 7.4 | Saad Iqbal | WP EasyPay | CWE-352 | WordPress WP EasyPay plugin <= 4.5.0 - Cross Site Request Forgery (CSRF) vuln… |
| CVE-2026-48980 | 6.3 | 7.3 | mcdope | pam_usb | CWE-454 | pam_usb: getenv() used in PAM context allows environment variable injection i… |
| CVE-2026-55746 | 7.0 | 6.9 | Cotonti | Cotonti | CWE-79 | Cotonti stored XSS via PFS folder title |
| CVE-2026-47833 | 6.9 | 6.4 | Cloud Foundry Foundation | bpm-release | CWE-59 | setupBpmLogs follows symlink for bpm.log open and chown — container-to-host p… |
| CVE-2026-56074 | 6.8 | 6.3 | PraisonAI | PraisonAI | CWE-863 | PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching |
| CVE-2026-48985 | 5.5 | 6.0 | mcdope | pam_usb | CWE-476 | pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Retur… |
| CVE-2026-12505 | 7.8 | 5.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-250 | Cifs-utils: local privilege escalation via forged cifs.spnego key description… |
| CVE-2026-48981 | 6.7 | 5.1 | mcdope | pam_usb | CWE-611 | pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c |
| CVE-2026-55742 | 9.4 | 4.8 | Cotonti | Cotonti | CWE-352 | Cotonti CSRF in admin.rights.php allows privilege escalation |
| CVE-2026-55392 | 6.7 | 4.8 | nilfs-dev | nilfs-utils | CWE-1284 | NILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_… |
| CVE-2026-55741 | 8.7 | 4.5 | Cotonti | Cotonti | CWE-352 | Cotonti CSRF in admin.config.php allows unauthorized configuration changes |
| CVE-2026-55744 | 8.6 | 4.6 | Cotonti | Cotonti | CWE-352 | Cotonti CSRF in PFS allows forced arbitrary file upload |
| CVE-2026-12039 | 5.7 | 4.5 | Docker | Docker Sandboxes | CWE-923 | Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution |
| CVE-2026-48984 | 4.7 | 4.4 | mcdope | pam_usb | CWE-14 | pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic mater… |
| CVE-2026-11719 | 8.6 | 4.3 | Google | MCP Toolbox for Databases (googleapis/mcp-toolbox) | CWE-862 | An authenticated authorization bypass vulnerability exists in MCP Toolbox for… |
| CVE-2026-48986 | 4.7 | 3.9 | mcdope | pam_usb | CWE-835 | pam_usb: Infinite loop DoS in process-tree walk when parent process exits dur… |
| CVE-2026-12539 | 5.7 | 3.8 | Docker | Docker Sandboxes | CWE-665 | Docker Sandboxes ICMP egress restriction bypass after daemon restart |
| CVE-2026-28573 | 10.0 | 3.7 | Google | Android | CWE-862 | In AndroidManifest.xml, there is a possible persistent denial of service due … |
| CVE-2026-56007 | 5.9 | 3.7 | OceanWP | Ocean Product Sharing | CWE-79 | WordPress Ocean Product Sharing plugin <= 2.2.2 - Cross Site Scripting (XSS) … |
| CVE-2026-50643 | 5.1 | 3.7 | rui314 | 8cc | CWE-125 | Out‑of‑Bounds Read in 8cc |
| CVE-2026-12047 | 4.8 | 3.6 | pgadmin.org | pgAdmin 4 | CWE-79 | pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via … |
| CVE-2026-56009 | 5.9 | 3.5 | Bricksable | Bricksable for Bricks Builder | CWE-79 | WordPress Bricksable for Bricks Builder plugin <= 1.6.83 - Cross Site Scripti… |
| CVE-2026-12390 | 8.4 | 3.5 | AzeoTech | DAQFactory | CWE-843 | Access of resource using incompatible type ('type confusion') in AzeoTech DAQ… |
| CVE-2026-48982 | 5.8 | 2.0 | mcdope | pam_usb | CWE-362 | pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race |
| CVE-2026-48983 | 5.8 | 1.3 | mcdope | pam_usb | CWE-367 | pam_usb: TOCTOU race condition in pad directory creation allows symlink subst… |
| CVE-2026-11958 | 7.3 | 1.1 | ANSSI | DFIR-ORC | CWE-427 | Local privilege escalation in ANSSI’s DFIR-ORC |
| CVE-2026-55745 | 5.3 | 0.9 | Cotonti | Cotonti | CWE-352 | Cotonti CSRF in PFS folder edit allows unauthorized folder modification |
| CVE-2026-42487 | 7.9 | 0.8 | Xen | Xen | CWE-362 | x86 HVM I/O port list traversal |
| CVE-2026-42489 | 5.3 | 0.2 | Xen | Xen | CWE-667 | domctl lock open to abuse |