| CVE-2026-50023 | 9.6 | 46.8 | yt-dlp | yt-dlp | CWE-641 | yt-dlp: Dangerous file type creation via insufficient filename sanitization (… |
| CVE-2026-53753 | 10.0 | 46.3 | unclecode | crawl4ai | CWE-94 | Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Dock… |
| CVE-2023-54365 | 8.7 | 44.3 | Traefik | Traefik | CWE-400 | Traefik - Denial of Service via HTTP/2 Request Handling |
| CVE-2026-45135 | 8.1 | 40.6 | caddyserver | caddy | CWE-20 | Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PH… |
| CVE-2026-12866 | 9.2 | 40.3 | n/a | expr-eval | CWE-94 | All versions of the package expr-eval are vulnerable to Code Execution via th… |
| CVE-2026-49465 | 6.0 | 40.3 | n8n-io | n8n | CWE-22 | n8n: Git Node Clone and Push Operations Bypass File Sandbox |
| CVE-2026-52844 | 7.5 | 39.2 | caddyserver | caddy | CWE-22 | Caddy: Windows `file_server` path authorization bypass via encoded backslash |
| CVE-2025-61018 | 7.5 | 39.1 | n/a | n/a | CWE-89 | An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v… |
| CVE-2025-61020 | 7.5 | 39.1 | n/a | n/a | CWE-89 | An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource … |
| CVE-2025-61023 | 7.5 | 39.1 | n/a | n/a | CWE-89 | An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 … |
| CVE-2025-61028 | 7.5 | 39.1 | n/a | n/a | CWE-89 | An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.1… |
| CVE-2026-35019 | 9.2 | 38.9 | NetComm Wireless Pty Ltd | NF20MESH | CWE-321 | NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass |
| CVE-2026-55447 | 9.6 | 38.6 | langflow-ai | langflow | CWE-61 | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit |
| CVE-2026-44959 | 8.8 | 38.4 | Revive | Adserver | CWE-94 | A missing validation of user input exists when saving delivery limitations in… |
| CVE-2025-71341 | 7.6 | 38.4 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via Undetected profile.Profile.runctx |
| CVE-2026-50193 | 6.3 | 38.0 | FasterXML | jackson-databind | CWE-400 | jackson-databind: Deeply nested JsonNode throws StackOverflowError for toStri… |
| CVE-2026-11972 | 8.2 | 37.0 | Python Software Foundation | CPython | CWE-252 | tarfile opened in streaming mode mishandles EOF |
| CVE-2026-52673 | 6.5 | 36.4 | n/a | n/a | CWE-89 | SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote atta… |
| CVE-2026-13007 | 8.7 | 36.0 | tenable | Tenable Identity Exposure | CWE-306 | Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure |
| CVE-2026-54305 | 8.9 | 35.9 | n8n-io | n8n | CWE-200 | n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints |
| CVE-2026-55654 | 3.7 | 35.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Openssh: heap out-of-bounds read in red hat enterprise linux versions of open… |
| CVE-2026-54314 | 6.3 | 35.6 | n8n-io | n8n | CWE-409 | n8n: Denial of Service via ZIP decompression in webhook workflow |
| CVE-2026-41862 | 8.8 | 35.3 | Spring | Spring Statemachine | CWE-502 | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis an… |
| CVE-2026-11807 | 9.6 | 34.7 | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-862 | Eda-server: websocket missing authorization allows credential theft via activ… |
| CVE-2026-48520 | 6.1 | 34.1 | langflow-ai | langflow | CWE-73 | Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read |
| CVE-2026-27604 | 10.0 | 34.0 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Ac… |
| CVE-2026-54762 | 5.9 | 33.9 | traefik | traefik | CWE-636 | Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolut… |
| CVE-2026-50574 | 9.6 | 33.8 | yt-dlp | yt-dlp | CWE-74 | yt-dlp: Arbitrary code execution via manifest downloads with aria2c |
| CVE-2026-54309 | 8.8 | 33.6 | n8n-io | n8n | CWE-306 | n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control S… |
| CVE-2026-54316 | 6.0 | 33.6 | anthropics | claude-code | CWE-183 | Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domai… |
| CVE-2026-54310 | 6.5 | 32.6 | n8n-io | n8n | CWE-89 | n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes |
| CVE-2025-55639 | 6.5 | 31.4 | n/a | n/a | CWE-476 | GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the … |
| CVE-2025-71370 | 7.6 | 31.1 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execW… |
| CVE-2026-11772 | 5.1 | 30.9 | DRIMO | DRIMO CMS | CWE-79 | Reflected XSS in DRIMO CMS |
| CVE-2026-56248 | 8.7 | 29.0 | Cap-go | capgo | CWE-400 | Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy |
| CVE-2026-33760 | 8.8 | 28.8 | langflow-ai | langflow | CWE-639 | Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpo… |
| CVE-2026-56222 | 8.6 | 28.7 | Capgo | Capgo | CWE-639 | Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /… |
| CVE-2026-49444 | 7.1 | 28.7 | n8n-io | n8n | CWE-20 | n8n: Python sandbox escape |
| CVE-2026-54304 | 7.1 | 28.5 | n8n-io | n8n | CWE-200 | n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host |
| CVE-2025-71337 | 8.7 | 28.2 | Flowise | Flowise | CWE-620 | Flowise - Unverified Email Change via Account Profile Endpoint |
| CVE-2025-61019 | 7.5 | 28.1 | n/a | n/a | CWE-89 | An issue in the sqlo_key_part_best component of openlink virtuoso-opensource … |
| CVE-2025-61021 | 7.5 | 28.1 | n/a | n/a | CWE-89 | An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensou… |
| CVE-2025-61022 | 7.5 | 28.1 | n/a | n/a | CWE-89 | An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v… |
| CVE-2025-61024 | 7.5 | 28.1 | n/a | n/a | CWE-89 | An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7… |
| CVE-2025-61025 | 7.5 | 28.1 | n/a | n/a | CWE-89 | An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.1… |
| CVE-2025-61027 | 7.5 | 28.1 | n/a | n/a | CWE-89 | An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 … |
| CVE-2025-61029 | 7.5 | 28.1 | n/a | n/a | CWE-89 | An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 … |
| CVE-2026-42867 | 6.5 | 27.9 | langflow-ai | langflow | CWE-22 | Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint |
| CVE-2026-54307 | 8.5 | 27.8 | n8n-io | n8n | CWE-863 | n8n: Credential Exfiltration via Permission Bypass |
| CVE-2026-55446 | 7.5 | 27.8 | langflow-ai | langflow | CWE-400 | Langflow: Unauthenticated DoS through multipart form boundary file upload |
| CVE-2026-54515 | 5.3 | 27.6 | FasterXML | jackson-databind | CWE-915 | jackson-databind: Case-insensitive deserialization bypasses per-property @Jso… |
| CVE-2026-56115 | 8.7 | 27.4 | garybowers | bootimus | CWE-862 | Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass |
| CVE-2026-9733 | 9.1 | 26.8 | HAYAJO | Mojolicious::Plugin::Web::Auth::OAuth2 | CWE-338 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an… |
| CVE-2026-44956 | 0.0 | 26.9 | Revive | Adserver | CWE-79 | Low‑privileged users could use their Full Name as a vector for a stored XSS a… |
| CVE-2026-44960 | 0.0 | 26.9 | Revive | Adserver | CWE-79 | A stored XSS can be exploited by leveraging the usernames as an attack vector… |
| CVE-2026-44961 | 0.0 | 26.7 | Revive | Adserver | CWE-287 | The XML‑RPC API addUser method has a validation bypass introduced in the fix … |
| CVE-2026-49402 | 8.1 | 26.4 | denoland | deno | CWE-78 | Deno: Command Injection via spawnSync & spawn on Windows |
| CVE-2026-54018 | 7.7 | 26.4 | open-webui | open-webui | CWE-918 | Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects |
| CVE-2026-54019 | 6.5 | 26.4 | open-webui | open-webui | CWE-862 | Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode |
| CVE-2026-56322 | 8.7 | 26.3 | Capgo | Capgo | CWE-200 | Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Pa… |
| CVE-2026-44792 | 8.9 | 26.0 | n8n-io | n8n | CWE-89 | n8n: Source Control Pull SQL Injection |
| CVE-2026-55249 | 8.8 | 26.0 | rtk-ai | rtk | CWE-78 | @rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync T… |
| CVE-2026-47385 | 5.3 | 25.2 | nocodb | nocodb | CWE-22 | NocoDB: Path Traversal via SQLite Source Filename |
| CVE-2025-71382 | 7.1 | 25.0 | ArtifexSoftware | mupdf | CWE-674 | MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering |
| CVE-2026-45732 | 8.3 | 24.9 | n8n-io | n8n | CWE-639 | n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints |
| CVE-2026-34917 | 4.3 | 24.9 | Revive | Adserver | CWE-287 | Low‑privileged session IDs generated for the web admin console could be reuse… |
| CVE-2026-54022 | 5.3 | 24.8 | open-webui | open-webui | CWE-706 | Open WebUI: Any authenticated user can read other users' private notes via So… |
| CVE-2026-54761 | 6.0 | 24.6 | traefik | traefik | CWE-284 | Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute o… |
| CVE-2026-54311 | 6.0 | 24.3 | n8n-io | n8n | CWE-488 | n8n: Merge Node SQL Mode Prototype Pollution |
| CVE-2026-10521 | 8.6 | 24.0 | MB connect line | mbCONNECT24 | CWE-425 | Authenticated unintended access to critical program parameters |
| CVE-2026-47381 | 6.9 | 24.1 | nocodb | nocodb | CWE-290 | NocoDB: Cross-Workspace Integration Use in Connection Test |
| CVE-2026-54588 | 9.6 | 24.0 | poweradmin | poweradmin | CWE-20 | Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, … |
| CVE-2026-34914 | 8.3 | 23.5 | Revive | Adserver | CWE-89 | A missing sanitisation of user input in the zone-include.php script of Revive… |
| CVE-2026-46552 | 5.8 | 23.3 | nocodb | nocodb | CWE-285 | NocoDB: Shared-base link access can invite arbitrary users as persistent base… |
| CVE-2026-47384 | 5.3 | 23.2 | nocodb | nocodb | CWE-89 | NocoDB: SQL Injection via Column Title in Bulk GroupBy |
| CVE-2025-71365 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Dete… |
| CVE-2025-71376 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.Aut… |
| CVE-2026-54517 | 5.3 | 22.2 | FasterXML | jackson-databind | CWE-863 | jackson-databind: @JsonView bypass for setterless creator properties |
| CVE-2026-53931 | 6.9 | 22.1 | nocodb | nocodb | CWE-441 | NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint |
| CVE-2026-53926 | 6.3 | 22.1 | nocodb | nocodb | CWE-613 | NocoDB: OAuth Tokens Persist Through Security Events |
| CVE-2026-54312 | 7.2 | 21.9 | n8n-io | n8n | CWE-1321 | n8n: Microsoft SQL Node Prototype Pollution |
| CVE-2026-56225 | 8.7 | 21.7 | Capgo | Capgo | CWE-269 | Capgo - Authorization Bypass in API Key Management via App-Limited Keys |
| CVE-2026-54010 | 8.3 | 21.7 | open-webui | open-webui | CWE-284 | Open WebUI: Forged chat-file link allows cross-user file read and deletion |
| CVE-2026-54317 | 7.6 | 21.7 | home-assistant | core | CWE-200 | Home Assistant: Konnected alarm-panel switch state and zone topology disclose… |
| CVE-2026-52845 | 8.1 | 21.6 | caddyserver | caddy | CWE-287 | Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` |
| CVE-2026-55653 | 6.5 | 21.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-415 | Openssh: double free in red hat enterprise linux versions of openssh dh-gex c… |
| CVE-2026-53622 | 7.8 | 21.4 | traefik | traefik | CWE-288 | Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and … |
| CVE-2026-47383 | 7.4 | 21.4 | nocodb | nocodb | CWE-79 | NocoDB: Stored Cross-Site Scripting via Row Comments |
| CVE-2026-53929 | 5.1 | 21.4 | nocodb | nocodb | CWE-79 | NocoDB: Stored Cross-Site Scripting via Secure Attachment |
| CVE-2026-53930 | 5.1 | 21.3 | nocodb | nocodb | CWE-918 | NocoDB: Server-Side Request Forgery via Base Migration URL |
| CVE-2026-11820 | 6.5 | 21.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-532 | Community.general: community.general nexmo — api credentials exposed in get u… |
| CVE-2026-54014 | 4.3 | 21.1 | open-webui | open-webui | CWE-22 | Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/ope… |
| CVE-2026-56968 | 5.3 | 21.1 | GNU | GNU SASL | CWE-908 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_… |
| CVE-2026-54516 | 5.3 | 20.8 | FasterXML | jackson-databind | CWE-915 | jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private f… |
| CVE-2026-23513 | 7.1 | 20.6 | FOSSBilling | FOSSBilling | CWE-863 | FOSSBilling: Broken Authorization in Client Transaction and Order Listings |
| CVE-2026-53927 | 5.1 | 20.7 | nocodb | nocodb | CWE-918 | NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL |
| CVE-2026-48491 | 7.8 | 20.4 | traefik | traefik | CWE-288 | Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-front… |
| CVE-2026-54308 | 6.3 | 20.1 | n8n-io | n8n | CWE-290 | n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node |
| CVE-2026-54324 | 6.5 | 19.8 | daytonaio | daytona | CWE-639 | Daytona: Cross-tenant data leak in notification WebSocket gateway via unverif… |
| CVE-2026-44958 | 5.4 | 19.8 | Revive | Adserver | CWE-284 | An access control bypass allows an advertiser‑level user to activate or deact… |
| CVE-2026-56243 | 8.6 | 19.7 | Capgo | Capgo | CWE-288 | Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane |
| CVE-2026-12891 | 4.3 | 19.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob r… |
| CVE-2026-50019 | 7.4 | 19.0 | yt-dlp | yt-dlp | CWE-200 | yt-dlp: File Downloader cookie leak with curl |
| CVE-2026-53754 | 7.5 | 18.9 | unclecode | crawl4ai | CWE-918 | Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT6… |
| CVE-2026-54009 | 6.5 | 18.9 | open-webui | open-webui | CWE-639 | Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field |
| CVE-2025-64105 | 5.1 | 18.5 | FOSSBilling | FOSSBilling | CWE-639 | FOSSBilling: IDOR Vulnerability in Support Ticket Creation |
| CVE-2026-54518 | 6.5 | 18.4 | FasterXML | jackson-databind | CWE-863 | jackson-databind: @JsonView bypass for unwrapped creator parameters in jackso… |
| CVE-2026-47376 | 5.1 | 18.1 | nocodb | nocodb | CWE-79 | NocoDB: Reflected Cross-Site Scripting via Password Reset Token |
| CVE-2026-54313 | 6.5 | 17.9 | n8n-io | n8n | CWE-89 | n8n: NoSQL Injection in MongoDB Node Find And Replace Operation |
| CVE-2026-54306 | 6.3 | 17.7 | n8n-io | n8n | CWE-1321 | n8n: Prototype Pollution enables confused-deputy execution via public webhooks |
| CVE-2026-54016 | 4.3 | 17.8 | open-webui | open-webui | CWE-639 | Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Kno… |
| CVE-2026-56784 | 8.6 | 17.6 | openremote | openremote | CWE-639 | OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint |
| CVE-2026-56371 | 6.9 | 17.5 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in TXT File Processing via Texture Attribute |
| CVE-2026-12958 | 8.5 | 17.3 | Amazon Web Services | Language Servers for AWS | CWE-61 | Arbitrary file write in Language Servers for AWS |
| CVE-2026-54257 | 9.3 | 16.9 | electron | electron | CWE-120 | Electron: Buffer performs incorrect byte length calculations resulting in hea… |
| CVE-2026-47379 | 6.9 | 16.9 | nocodb | nocodb | CWE-200 | NocoDB: Plaintext Password Comparison in Shared Views |
| CVE-2026-54321 | 7.0 | 16.4 | daytonaio | daytona | CWE-613 | Daytona: Public sandbox previews remain accessible for up to one hour after b… |
| CVE-2026-56234 | 6.9 | 16.2 | Capgo | Capgo | CWE-307 | Capgo - Password Spraying via Public-Key Accessible Credential Validation End… |
| CVE-2026-56762 | 6.9 | 16.2 | Hono | Hono | CWE-20 | Hono - Missing Cookie Name Validation in setCookie() |
| CVE-2026-8379 | 7.5 | 15.9 | Unknown | Frontend File Manager Plugin | — | Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download |
| CVE-2026-34913 | 4.3 | 15.8 | Revive | Adserver | CWE-284 | A missing access control check when linking trackers to campaigns through the… |
| CVE-2026-44957 | 4.3 | 15.8 | Revive | Adserver | CWE-284 | A missing access control check when invoking various modify methods in the XM… |
| CVE-2026-56785 | 8.4 | 15.7 | FlatPress | FlatPress | CWE-79 | FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact For… |
| CVE-2026-53928 | 6.3 | 15.6 | nocodb | nocodb | CWE-613 | NocoDB: Refresh Tokens Persist Through Password Recovery |
| CVE-2026-46553 | 2.1 | 15.3 | nocodb | nocodb | CWE-770 | NocoDB: Attachment Size Limit Bypass via Upload-by-URL |
| CVE-2026-54012 | 7.1 | 15.2 | open-webui | open-webui | CWE-284 | Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion |
| CVE-2026-47279 | 6.9 | 15.3 | nocodb | nocodb | CWE-284 | NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints |
| CVE-2026-47378 | 6.9 | 15.3 | nocodb | nocodb | CWE-639 | NocoDB: Hidden Column Exposure in Public Shared View Endpoints |
| CVE-2026-12969 | 5.3 | 15.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes … |
| CVE-2026-47377 | 5.1 | 15.3 | nocodb | nocodb | CWE-601 | NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin |
| CVE-2026-8163 | 8.8 | 14.9 | Unknown | Infility Global | — | Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter |
| CVE-2026-53662 | 9.6 | 14.7 | immich-app | immich | CWE-79 | immich: One-click account takeover via XSS in login page continue redirect |
| CVE-2026-46551 | 6.5 | 14.6 | nocodb | nocodb | CWE-770 | NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Servi… |
| CVE-2026-34912 | 4.3 | 14.7 | Revive | Adserver | CWE-284 | A missing access control check when linking banners or campaigns to a zone th… |
| CVE-2026-10711 | 8.8 | 14.5 | AKIN Software Computer Import Export Industry and Trade Ltd. | CafePlus | CWE-306 | RCE in Akınsoft's CafePlus |
| CVE-2026-47387 | 8.4 | 14.5 | nocodb | nocodb | CWE-79 | NocoDB: Stored Cross-Site Scripting via Form View Redirect URL |
| CVE-2026-56701 | 7.1 | 14.4 | Grav | Grav | CWE-611 | Grav - XML External Entity Injection via SVG Upload |
| CVE-2026-54008 | 8.5 | 14.2 | open-webui | open-webui | CWE-918 | Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` |
| CVE-2026-56695 | 7.1 | 14.1 | HKUDS | OpenHarness | CWE-862 | OpenHarness - Cross-Session Disclosure via /resume and /summary Commands |
| CVE-2026-54011 | 5.4 | 14.2 | open-webui | open-webui | CWE-79 | Open WebUI: Stored XSS in Mermaid Markdown Preview |
| CVE-2026-44089 | 9.4 | 14.0 | Totolink | EX1200L | CWE-121 | Buffer Overflow in Totolink EX1200L router |
| CVE-2026-47693 | 6.9 | 13.9 | poweradmin | poweradmin | CWE-1236 | Poweradmin: CSV Injection in log export endpoints allows formula execution in… |
| CVE-2026-10609 | 6.8 | 13.5 | Red Hat | Logging Subsystem for Red Hat OpenShift | CWE-862 | Openshift/cluster-logging-operator: cluster logging operator creates and forw… |
| CVE-2026-34915 | 6.1 | 13.3 | Revive | Adserver | CWE-79 | A missing sanitisation of user input in the zone-include.php script of Revive… |
| CVE-2026-12957 | 8.5 | 13.2 | Amazon Web Services | Language Servers for AWS | CWE-732 | Arbitrary Code Execution in Language Servers for AWS |
| CVE-2026-7842 | 6.8 | 13.3 | Unknown | Infility Global | — | Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter |
| CVE-2026-4983 | 5.4 | 13.2 | Eclipse Foundation | Eclipse Open VSX | CWE-79 | Open VSX Registry does not sanitize SVG files uploaded as extension icons pri… |
| CVE-2026-54514 | 5.3 | 12.6 | FasterXML | jackson-databind | CWE-918 | jackson-databind: InetSocketAddress deserialization triggers eager DNS resolu… |
| CVE-2026-11833 | 8.2 | 12.4 | Yokogawa Electric Corporation | FAST/TOOLS | CWE-319 | Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web… |
| CVE-2026-54301 | 7.0 | 12.3 | n8n-io | n8n | CWE-79 | n8n: Same-Origin XSS in Respond to Webhook Node |
| CVE-2026-56696 | 5.3 | 12.3 | HKUDS | OpenHarness | CWE-862 | OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands |
| CVE-2026-54320 | 8.4 | 12.1 | daytonaio | daytona | CWE-287 | Daytona: Cross-tenant organization takeover via invitation acceptance with an… |
| CVE-2025-62180 | 7.1 | 12.2 | Pegasystems | Pega Infinity | CWE-639 | Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an autho… |
| CVE-2026-47375 | 6.0 | 12.1 | nocodb | nocodb | CWE-89 | NocoDB: Postgres SQL Injection in Formula `ARRAYSORT` |
| CVE-2026-56275 | 6.0 | 12.1 | Flowise | Flowise | CWE-918 | Flowise - Server-Side Request Forgery via Execute Flow Base URL |
| CVE-2026-56402 | 7.1 | 11.9 | nanocoai | nanoclaw | CWE-862 | NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Han… |
| CVE-2026-54302 | 7.0 | 11.4 | n8n-io | n8n | CWE-79 | n8n: Stored XSS in Chat Trigger Node |
| CVE-2026-54021 | 6.3 | 11.5 | open-webui | open-webui | CWE-863 | Open WebUI: Authenticated users can target arbitrary configured Ollama backen… |
| CVE-2026-47388 | 2.3 | 11.4 | nocodb | nocodb | CWE-639 | NocoDB: Missing Ownership Check in MCP Attachment Read |
| CVE-2026-47382 | 5.3 | 11.1 | nocodb | nocodb | CWE-918 | NocoDB: Server-Side Request Forgery via Database Connection Host |
| CVE-2026-54006 | 4.3 | 11.0 | open-webui | open-webui | CWE-639 | Open WebUI: Calendar event re-parenting allows writing events into another us… |
| CVE-2026-54013 | 7.6 | 10.4 | open-webui | open-webui | CWE-79 | Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open W… |
| CVE-2026-54015 | 6.4 | 9.9 | open-webui | open-webui | CWE-284 | Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read … |
| CVE-2026-47380 | 6.3 | 9.7 | nocodb | nocodb | CWE-208 | NocoDB: User Enumeration via Sign-In Timing |
| CVE-2026-47386 | 6.3 | 9.9 | nocodb | nocodb | CWE-362 | NocoDB: OAuth Authorization Code Race Condition |
| CVE-2026-46554 | 2.3 | 9.7 | nocodb | nocodb | CWE-613 | NocoDB: Stale Auth Cache After API Token Deletion |
| CVE-2026-4610 | 6.4 | 9.6 | metagauss | ProfileGrid – User Profiles, Groups and Communities | CWE-79 | ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Script… |
| CVE-2026-56263 | 5.3 | 9.5 | Crawl4AI | Crawl4AI | CWE-79 | Crawl4AI - Stored Cross-Site Scripting in Monitor Dashboard |
| CVE-2026-55423 | 6.1 | 8.8 | langflow-ai | langflow | CWE-613 | Langflow: Logout button does not clear session |
| CVE-2026-52846 | 4.2 | 8.8 | caddyserver | caddy | CWE-116 | Caddy: stripHTML template function bypass |
| CVE-2026-56116 | 7.1 | 8.7 | NetworkConfiguration | dhcpcd | CWE-401 | dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling |
| CVE-2026-49401 | 8.4 | 8.6 | denoland | deno | CWE-41 | Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS) |
| CVE-2026-54322 | 7.7 | 8.4 | daytonaio | daytona | CWE-639 | Daytona: Cross-org IDOR in organization role update/delete — any org owner ca… |
| CVE-2020-9711 | 5.5 | 8.4 | Adobe | Acrobat Reader | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2020-9713 | 5.5 | 8.4 | Adobe | Acrobat Reader | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-56376 | 6.3 | 8.3 | ImageMagick | ImageMagick | CWE-416 | ImageMagick - Heap Use-After-Free in Meta Coder |
| CVE-2026-55517 | 4.3 | 8.2 | denoland | deno | CWE-248 | Deno: Denial of service via non-ASCII bytes in WebSocket response headers |
| CVE-2026-48493 | 5.5 | 8.1 | grokability | snipe-it | CWE-863 | Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assi… |
| CVE-2020-9695 | 7.8 | 8.0 | Adobe | Acrobat Reader | CWE-787 | Acrobat Reader | Out-of-bounds Write (CWE-787) |
| CVE-2026-54303 | 6.8 | 7.5 | n8n-io | n8n | CWE-79 | n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhoo… |
| CVE-2026-46548 | 4.3 | 7.4 | nocodb | nocodb | CWE-918 | NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discor… |
| CVE-2026-54007 | 7.1 | 7.2 | open-webui | open-webui | CWE-346 | Open WebUI: Cross-origin postMessage confirmation bypass via action:submit |
| CVE-2026-56113 | 6.0 | 7.3 | NetworkConfiguration | dhcpcd | CWE-416 | dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW |
| CVE-2026-56114 | 6.0 | 7.3 | NetworkConfiguration | dhcpcd | CWE-787 | dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage() |
| CVE-2026-54319 | 4.2 | 6.9 | daytonaio | daytona | CWE-22 | Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into… |
| CVE-2026-49406 | 5.5 | 6.8 | denoland | deno | CWE-22 | Deno: BYONM module resolution allows `package.json` main path traversal to by… |
| CVE-2026-56694 | 5.3 | 6.9 | nanocoai | nanoclaw | CWE-863 | NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback |
| CVE-2026-44726 | 9.1 | 6.6 | denoland | deno | CWE-319 | Deno: TLS retry copies stale upgrade hook, risking plaintext traffic |
| CVE-2026-45692 | 3.8 | 6.4 | caddyserver | caddy | CWE-187 | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Nor… |
| CVE-2026-8172 | 7.1 | 5.6 | Unknown | Simple Basic Contact Form | — | Simple Basic Contact Form <= 20250114 - Reflected XSS |
| CVE-2026-55766 | 4.8 | 5.4 | guzzle | psr7 | CWE-93 | guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization |
| CVE-2026-46547 | 6.1 | 5.2 | nocodb | nocodb | CWE-79 | NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL |
| CVE-2026-56815 | 7.4 | 5.2 | rasta-mouse | pwnlift | CWE-61 | pwnlift before d7a9544, in a privileged deployment, contains a symlink follow… |
| CVE-2026-5818 | 7.2 | 5.2 | Caliptra | Core Runtime Firmware | CWE-253 | MCU Firmware Update Authentication Bypass on Caliptra Core |
| CVE-2026-12112 | 7.8 | 5.0 | Red Hat | Red Hat Satellite 6.18 | CWE-287 | Foreman-mcp-server: mcp server: active session hijacking via insecure session… |
| CVE-2026-9073 | 6.2 | 5.0 | Red Hat | Red Hat Satellite 6.18 | CWE-532 | Foreman-mcp-server: mcp server: insecure sensitive http header sanitization |
| CVE-2026-55736 | 5.9 | 4.9 | ash-project | ash | CWE-915 | Private action arguments can be set by user input in Ash |
| CVE-2026-46549 | 2.0 | 4.8 | nocodb | nocodb | CWE-863 | NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation |
| CVE-2026-49440 | 7.4 | 4.6 | denoland | deno | CWE-325 | Deno: Miller-Rabin Primality Test Allows Zero Rounds |
| CVE-2026-10857 | 6.1 | 4.6 | AKIN Software Computer Import Export Industry and Trade Ltd. | e-Commerce | CWE-79 | Reflected XSS in Akinsoft's e-Commerce |
| CVE-2026-57053 | 2.5 | 4.6 | GNU | libidn | CWE-1284 | GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memor… |
| CVE-2026-12163 | 4.8 | 4.3 | Fortra | File Integrity Monitoring (FIM) | CWE-79 | Stored XSS in Fortra File Integrity Monitoring (FIM) |
| CVE-2026-49411 | 6.5 | 4.2 | denoland | deno | CWE-284 | Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny… |
| CVE-2026-50221 | 5.3 | 4.2 | OpenStack | Swift | CWE-918 | In OpenStack Swift before 2.37.2, proxy-server does not strip internal update… |
| CVE-2026-55767 | 5.8 | 4.1 | guzzle | guzzle | CWE-346 | Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle |
| CVE-2026-57062 | 2.9 | 4.0 | GnuPG | GnuPG | CWE-1284 | CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 m… |
| CVE-2026-7574 | 8.7 | 3.7 | Anthropic | Claude Desktop Cowork | CWE-353 | Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use |
| CVE-2026-0864 | 4.1 | 3.8 | Python Software Foundation | CPython | CWE-74 | Configuration Injection via Carriage Return (\r) in write() method |
| CVE-2026-54318 | 7.1 | 3.7 | home-assistant | core | CWE-926 | Home Assistant: Exported BroadcastReceiver allows local apps to spoof device … |
| CVE-2026-8378 | 5.4 | 3.2 | Unknown | Frontend File Manager Plugin | — | Frontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scriptin… |
| CVE-2026-54326 | 2.5 | 3.2 | earendil-works | pi | CWE-79 | Pi: Potential XSS in HTML session exports via Markdown URL sanitization bypass |
| CVE-2026-56692 | 6.8 | 3.1 | nanocoai | nanoclaw | CWE-59 | NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttac… |
| CVE-2026-54555 | 7.8 | 2.9 | rtk-ai | rtk | CWE-863 | rtk: Permission-gate bypass in rtk rewrite auto-allow via unsplit shell separ… |
| CVE-2026-6458 | 5.1 | 2.9 | Caliptra | Core Runtime Firmware | CWE-325 | AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AA… |
| CVE-2026-11819 | 5.5 | 2.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-532 | Community.general: community.general keyring_info — os keyring passphrase ret… |
| CVE-2026-54325 | 4.4 | 2.0 | earendil-works | pi | CWE-829 | Pi loads project-local extensions without approval |
| CVE-2026-54323 | 5.9 | 2.0 | daytonaio | daytona | CWE-295 | Daytona: Git credential leak via git clone with TLS verification disabled |
| CVE-2026-12892 | 4.4 | 2.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds rea… |
| CVE-2026-54328 | 7.3 | 1.8 | earendil-works | pi | CWE-379 | Pi: Predictable temporary extension install paths allow local privilege escal… |
| CVE-2026-56693 | 6.8 | 1.7 | nanocoai | nanoclaw | CWE-602 | NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System… |
| CVE-2026-55568 | 5.9 | 1.3 | guzzle | guzzle | CWE-311 | Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext |
| CVE-2026-56301 | 6.8 | 1.1 | Nuxt | Nuxt | CWE-276 | Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux |
| CVE-2026-49859 | 5.2 | 1.0 | denoland | deno | CWE-693 | Deno: `fetch()` API sandbox bypass via missing DNS resolution check |
| CVE-2026-49860 | 5.2 | 1.0 | denoland | deno | CWE-918 | Deno: WebSocket API sandbox bypass via missing post-DNS check |
| CVE-2026-12164 | 4.4 | 1.0 | Fortra | File Integrity Monitoring (FIM) | CWE-266 | Privilege Escalation in Fortra File Integrity Monitoring (FIM) |
| CVE-2026-46550 | 5.4 | 0.9 | nocodb | nocodb | CWE-614 | NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags |
| CVE-2026-49983 | 5.2 | 0.9 | denoland | deno | CWE-863 | Deno: process.loadEnvFile() bypasses env permission checks and mutates proces… |
| CVE-2025-15619 | 3.5 | 0.9 | HCLSoftware | Connections | CWE-284 | HCL Connections is vulnerable to broken access control |
| CVE-2026-56117 | 5.7 | 0.7 | NetworkConfiguration | dhcpcd | CWE-416 | dhcpcd Heap Use-After-Free via Control Socket Handling |
| CVE-2026-55655 | 6.1 | 0.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-923 | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in… |
| CVE-2025-13162 | 4.1 | 0.3 | ABB | Control Builder A | CWE-427 | Advant Master Online Builder DLL vulnerability |
| CVE-2026-45792 | 6.9 | 0.2 | rtk-ai | rtk | CWE-345 | RTK improperly trusts project-local filter configuration, allowing silent tam… |
| CVE-2026-54327 | 2.2 | 0.1 | earendil-works | pi | CWE-367 | Pi: Race condition in auth.json writes could expose stored credentials |