| CVE-2026-7829 | 7.2 | 44.5 | uvnc | UltraVNC | CWE-787 | UltraVNC repeater authenticated out-of-bounds write in rule parser via oversi… |
| CVE-2026-54399 | 7.5 | 44.2 | Apache Software Foundation | Apache HttpComponents Core | CWE-400 | Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Conf… |
| CVE-2026-20213 | 7.5 | 44.1 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability |
| CVE-2026-20214 | 7.5 | 44.1 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability |
| CVE-2026-57516 | 8.6 | 43.6 | Anyscale, Inc | Ray | CWE-502 | Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader |
| CVE-2026-34108 | 9.3 | 43.4 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34110 | 9.3 | 43.4 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34111 | 9.3 | 43.4 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34116 | 9.3 | 43.4 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-58399 | 8.7 | 43.1 | antonio-castellon | module-auth | CWE-287 | @acastellon/auth has an authentication bypass via spoofable headers in valida… |
| CVE-2026-34109 | 9.3 | 42.8 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34112 | 9.3 | 42.8 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34113 | 9.3 | 42.8 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34114 | 9.3 | 42.8 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34115 | 9.3 | 42.8 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-34117 | 9.3 | 42.8 | guardian | language-system | CWE-78 | Guardian Language-System Unauthenticated OS Command Injection via id Paramete… |
| CVE-2026-52186 | 9.8 | 42.2 | n/a | n/a | CWE-89 | SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows… |
| CVE-2026-7831 | 7.6 | 42.1 | uvnc | UltraVNC | CWE-193 | UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing |
| CVE-2026-58454 | 7.7 | 41.9 | JAIOTlink | C492A-W6 Wi-Fi IP Camera | CWE-94 | JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint |
| CVE-2026-11387 | 9.8 | 41.5 | cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | CWE-287 | SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Passw… |
| CVE-2026-24270 | 9.8 | 41.3 | NVIDIA | AIStore framework | CWE-290 | NVIDIA AIStore framework contains a vulnerability where an attacker could byp… |
| CVE-2025-15646 | 9.8 | 41.3 | BPS | HTML::Gumbo | CWE-125 | HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confu… |
| CVE-2026-20215 | 7.5 | 40.6 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability |
| CVE-2026-20216 | 7.5 | 40.6 | Cisco | Cisco Secure Endpoint | CWE-770 | ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability |
| CVE-2026-20217 | 7.5 | 40.6 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerab… |
| CVE-2026-20243 | 7.5 | 40.6 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV ALZ Archive Processing Denial of Service Vulnerability |
| CVE-2026-20244 | 7.5 | 40.6 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV DMG File Processing Denial of Service Vulnerability |
| CVE-2026-24264 | 7.5 | 39.4 | NVIDIA | Triton Inference Server | CWE-409 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-34099 | 9.3 | 38.0 | guardian | language-system | CWE-89 | Guardian Language-System Unauthenticated SQL Injection via id Parameter in jo… |
| CVE-2026-6687 | 7.6 | 37.9 | ChaN | FatFs | CWE-121 | FatFs Stack Buffer Overflow via Uncapped exFAT Label Length |
| CVE-2026-50521 | 8.3 | 37.8 | Microsoft | Microsoft Edge (Chromium-based) | CWE-416 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-52190 | 7.5 | 37.5 | n/a | n/a | CWE-121 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-24266 | 7.5 | 37.1 | NVIDIA | Triton Inference Server | CWE-416 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-6683 | 4.6 | 35.8 | ChaN | FatFs | CWE-369 | FatFs Divide-by-Zero in exFAT Sync |
| CVE-2026-6684 | 4.6 | 35.8 | ChaN | FatFs | CWE-835 | FatFs Infinite Loop in GPT Partition Scan |
| CVE-2026-6682 | 7.6 | 35.7 | ChaN | FatFs | CWE-190 | FatFs Integer Overflow in FAT32 Volume Mount |
| CVE-2026-6688 | 7.6 | 35.7 | ChaN | FatFs | CWE-120 | FatFs Buffer Overflow via Unbounded LFN Filename Copy |
| CVE-2026-7839 | 9.1 | 35.5 | uvnc | UltraVNC | CWE-798 | UltraVNC repeater ships hardcoded default admin password allowing unauthentic… |
| CVE-2026-14265 | 7.7 | 34.7 | AWS | AWS Advanced JDBC Wrapper | CWE-502 | RCE via Deserialization in AWS Advanced JDBC Wrapper |
| CVE-2026-6070 | 9.1 | 34.0 | cmsjunkie | WP-BusinessDirectory – Business directory plugin for WordPress | CWE-73 | WP-BusinessDirectory <= 4.0.1 - Unauthenticated Arbitrary File Deletion via P… |
| CVE-2026-58451 | 7.1 | 34.1 | horde | imp | CWE-22 | Horde IMP < 7.0.1 Path Traversal via Compose.php img src |
| CVE-2026-53355 | 9.8 | 33.1 | Linux | Linux | CWE-476 | net: rds: clear i_sends on setup unwind |
| CVE-2026-44042 | 3.7 | 32.0 | uvnc | UltraVNC | CWE-193 | UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check |
| CVE-2026-6686 | 4.6 | 30.9 | ChaN | FatFs | CWE-908 | FatFs Use of Uninitialized Clusters After Seek Past EOF |
| CVE-2026-34100 | 9.3 | 30.4 | guardian | language-system | CWE-89 | Guardian Language-System Unauthenticated SQL Injection via id Parameter in me… |
| CVE-2026-34101 | 9.3 | 30.4 | guardian | language-system | CWE-89 | Guardian Language-System Unauthenticated SQL Injection via id Parameter in te… |
| CVE-2026-34102 | 9.3 | 30.4 | guardian | language-system | CWE-89 | Guardian Language-System Unauthenticated SQL Injection via id Parameter in jo… |
| CVE-2026-34103 | 9.3 | 30.4 | guardian | language-system | CWE-89 | Guardian Language-System Unauthenticated SQL Injection via id Parameter in su… |
| CVE-2026-34104 | 9.3 | 30.4 | guardian | language-system | CWE-89 | Guardian Language-System Unauthenticated SQL Injection via name Parameter in … |
| CVE-2026-34105 | 9.3 | 30.4 | guardian | language-system | CWE-89 | Guardian Language-System Unauthenticated SQL Injection via id Parameter in tr… |
| CVE-2026-56149 | 4.9 | 29.9 | Elastic | Elasticsearch | CWE-770 | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading… |
| CVE-2026-13468 | 7.5 | 29.8 | themeisle | Visualizer – Tables & Charts Manager with Built-in AI Generator | CWE-862 | Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Info… |
| CVE-2026-11883 | 7.2 | 29.6 | Unknown | WebAuthn Provider for Two Factor | — | WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass |
| CVE-2026-56016 | 5.9 | 29.3 | MARKSTOS | CGI::Session::ID::md5 | CWE-338 | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable sess… |
| CVE-2026-8387 | 2.4 | 28.8 | allegroai | allegroai/clearml | CWE-23 | Relative Path Traversal in allegroai/clearml |
| CVE-2026-56150 | 7.5 | 28.1 | Elastic | Fleet Server | CWE-770 | Allocation of Resources Without Limits or Throttling in Fleet Server Leading … |
| CVE-2026-14383 | 8.8 | 27.9 | Google | Chrome | CWE-94 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al… |
| CVE-2026-53492 | 8.4 | 27.8 | containerd | containerd | CWE-20 | containerd CRI checkpoint restore CDI annotation smuggling |
| CVE-2026-56148 | 6.5 | 27.8 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-36912 | 7.5 | 27.3 | n/a | n/a | CWE-476 | A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function o… |
| CVE-2026-38891 | 7.5 | 27.3 | n/a | n/a | CWE-20 | An improper input validation in the gazebo_ros_diff_drive.cpp component of ga… |
| CVE-2026-12127 | 5.3 | 27.3 | smub | WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More | CWE-93 | WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthentica… |
| CVE-2026-53906 | 5.1 | 27.0 | MyComplianceOffice | MCO | CWE-22 | Path Disclosure and Path Traversal in MCO |
| CVE-2026-51946 | 6.5 | 26.6 | n/a | n/a | CWE-89 | SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) al… |
| CVE-2026-50195 | 5.6 | 26.1 | containerd | containerd | CWE-345 | containerd: CRI checkpoint import allows local image tag poisoning |
| CVE-2026-55791 | 6.9 | 25.9 | craftcms | cms | CWE-79 | Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Pois… |
| CVE-2026-13706 | 0.0 | 25.7 | Wikimedia Foundation | UrlShortener | CWE-20 | UrlShortener extension url validation can be bypassed due to difference betwe… |
| CVE-2026-14385 | 8.8 | 25.6 | Google | Chrome | CWE-122 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 … |
| CVE-2026-55153 | 7.1 | 25.6 | swaldman | mchange-commons-java | CWE-470 | mchange-commons-java contains elements susceptible to abuse via JNDI injectio… |
| CVE-2026-5136 | 8.8 | 25.5 | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | CWE-266 | Foreman: foreman: privilege escalation to administrator-level access via user… |
| CVE-2026-58025 | 5.9 | 25.3 | Wikimedia Foundation | MediaWiki | CWE-94 | Remote Code Execution via Unsafe Deserialization in LogItem Import |
| CVE-2026-54908 | 6.3 | 24.8 | pion | dtls | CWE-125 | Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK Serv… |
| CVE-2026-14407 | 8.8 | 24.6 | Google | Chrome | CWE-94 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al… |
| CVE-2026-12110 | 6.5 | 24.6 | taskbuilder | Taskbuilder – Project Management & Task Management Tool With Kanban Board | CWE-89 | Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_se… |
| CVE-2026-24260 | 8.5 | 24.4 | NVIDIA | Container Toolkit | CWE-367 | NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker… |
| CVE-2026-44041 | 6.5 | 24.4 | uvnc | UltraVNC | CWE-125 | UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NU… |
| CVE-2026-55886 | 6.3 | 24.3 | xdan | jodit | CWE-1321 | Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set() |
| CVE-2026-58592 | 8.9 | 23.8 | LadybirdBrowser | Ladybird | CWE-787 | Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference i… |
| CVE-2026-55790 | 7.4 | 23.7 | craftcms | cms | CWE-79 | Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget |
| CVE-2026-12923 | 7.5 | 23.6 | emarket-design | Video Gallery – YouTube Gallery, Playlist & Video Grid | CWE-98 | Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call … |
| CVE-2026-12090 | 6.5 | 23.7 | taskbuilder | Taskbuilder – Project Management & Task Management Tool With Kanban Board | CWE-89 | Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_pr… |
| CVE-2026-14405 | 9.6 | 23.3 | Google | Chrome | CWE-457 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a rem… |
| CVE-2026-12142 | 7.2 | 23.0 | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | CWE-79 | NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]… |
| CVE-2026-13228 | 8.8 | 22.5 | latepoint | LatePoint – Calendar Booking Plugin for Appointments and Events | CWE-269 | LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administ… |
| CVE-2026-14198 | 9.1 | 22.4 | @fastify/middie | @fastify/middie | CWE-436 | @fastify/middie vulnerable to authorization bypass via encoded slash in path … |
| CVE-2026-1239 | 7.5 | 22.4 | kstover | Ninja Forms – The Contact Form Builder That Grows With You | CWE-862 | Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive In… |
| CVE-2026-14363 | 6.9 | 21.9 | The Wikimedia Foundation | Mediawiki - Cargo Extension | CWE-89 | Cargo Extension: SQLi in Special:Drilldown |
| CVE-2026-55794 | 8.7 | 21.8 | craftcms | cms | CWE-94 | Craft CMS: Potential authenticated Remote Code Execution via referrer redirect |
| CVE-2026-12904 | 4.3 | 21.8 | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | CWE-639 | Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (… |
| CVE-2026-14430 | 8.8 | 21.6 | Google | Chrome | CWE-190 | Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remo… |
| CVE-2026-14181 | 7.5 | 21.6 | @fastify/middie | @fastify/middie | CWE-248 | @fastify/middie standalone engine vulnerable to Denial of Service via malform… |
| CVE-2026-13603 | 9.0 | 21.3 | pretix | pretix-oppwa | CWE-20 | SSRF with API key leak in pretix-oppwa |
| CVE-2026-11823 | 7.5 | 21.0 | Repute Infosystems | BookingPress Appointment Booking Pro | CWE-89 | BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection… |
| CVE-2026-11568 | 7.5 | 20.9 | Unknown | Product Configurator for WooCommerce | — | Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft … |
| CVE-2026-57692 | 9.8 | 20.8 | LCweb | PrivateContent | CWE-266 | WordPress PrivateContent plugin <= 9.9.2 - Privilege Escalation vulnerability |
| CVE-2026-58521 | 6.9 | 20.8 | The Wikimedia Foundation | Mediawiki - Cargo Extension | CWE-89 | SQLi in Cargo extension via year range filter |
| CVE-2026-44040 | 6.5 | 20.8 | uvnc | UltraVNC | CWE-338 | UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authenticatio… |
| CVE-2026-49087 | 6.5 | 20.6 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-56151 | 6.5 | 20.6 | Elastic | Kibana | CWE-20 | Improper Input Validation in Kibana Leading to Denial of Service |
| CVE-2026-14393 | 8.8 | 20.6 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote… |
| CVE-2026-58024 | 5.1 | 20.6 | Wikimedia Foundation | MediaWiki | CWE-200 | API identification of users on private wikis |
| CVE-2026-12575 | 7.5 | 20.2 | deltaww | DVP80ES3 | CWE-404 | DVP80ES3 Improper Resource Shutdown or Release Vulnerability |
| CVE-2026-5142 | 6.5 | 20.2 | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | CWE-639 | Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scopin… |
| CVE-2026-5051 | 4.4 | 20.3 | HashiCorp | Vault | CWE-22 | Audit Log Plugin Directory Guard Bypass via Legacy path Option |
| CVE-2026-14387 | 9.6 | 20.0 | Google | Chrome | CWE-472 | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a re… |
| CVE-2026-14392 | 9.6 | 20.0 | Google | Chrome | CWE-787 | Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a… |
| CVE-2026-12579 | 7.4 | 19.7 | deltaww | AS228T | CWE-288 | AS228T - Authentication Bypass Vulnerability |
| CVE-2026-54756 | 6.3 | 19.7 | xdan | jodit | CWE-1321 | Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge |
| CVE-2026-50280 | 6.0 | 19.6 | craftcms | cms | CWE-284 | Craft CMS: Authorization bypass in `entries/move-to-section` via missing targ… |
| CVE-2026-14422 | 8.8 | 19.5 | Google | Chrome | CWE-125 | Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 … |
| CVE-2026-12902 | 4.3 | 19.6 | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | CWE-862 | Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor… |
| CVE-2026-13602 | 7.7 | 19.5 | pretix | pretix | CWE-20 | Session takeover vulnerability |
| CVE-2025-23350 | 9.0 | 19.1 | NVIDIA | BlueField GA | CWE-787 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interfac… |
| CVE-2025-23351 | 9.0 | 19.1 | NVIDIA | BlueField GA | CWE-787 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interfac… |
| CVE-2026-10539 | 9.5 | 19.0 | BMC | Control-M/Server | CWE-305 | Unauthenticated command injection in Control-M/Server communication command |
| CVE-2026-55792 | 6.0 | 19.0 | craftcms | cms | CWE-200 | Craft CMS: Sensitive File Disclosure / Server-Side File Read |
| CVE-2026-10750 | 8.1 | 18.9 | Unknown | Royal MCP | — | Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools |
| CVE-2026-11988 | 6.5 | 18.9 | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | CWE-639 | LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Su… |
| CVE-2026-5135 | 6.5 | 18.5 | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | CWE-639 | Foreman: foreman: unauthorized modification of host configurations via broken… |
| CVE-2026-14258 | 6.5 | 18.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-835 | Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd o… |
| CVE-2026-14382 | 9.6 | 18.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-14409 | 7.5 | 18.5 | Google | Chrome | CWE-693 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al… |
| CVE-2026-47262 | 5.3 | 18.5 | containerd | containerd | CWE-400 | containerd image-triggered runtime DoS via unbounded group parsing |
| CVE-2026-50283 | 5.3 | 18.5 | craftcms | cms | CWE-639 | Craft CMS: Unauthorized Deletion of Source Assets During File Replacement |
| CVE-2026-14395 | 8.8 | 18.4 | Google | Chrome | CWE-787 | Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a r… |
| CVE-2026-14431 | 8.8 | 18.4 | Google | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote… |
| CVE-2026-14193 | 7.5 | 18.2 | deltaww | DVP80ES300T | CWE-129 | DVP80ES300T - Improper Validation of Array Index Vulnerability |
| CVE-2026-54712 | 7.5 | 18.2 | open-telemetry | opentelemetry-java-instrumentation | CWE-400 | OpenTelemetry Javaagent RMI context propagation allows resource exhaustion |
| CVE-2026-14384 | 6.5 | 18.2 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.4… |
| CVE-2026-14386 | 6.5 | 18.2 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a… |
| CVE-2026-14388 | 6.5 | 18.2 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a… |
| CVE-2026-13454 | 6.5 | 18.0 | jetmonsters | MotoPress Appointment Booking | CWE-89 | MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection… |
| CVE-2026-14340 | 5.3 | 17.8 | GitHub | Enterprise Server | CWE-863 | An incorrect authorization vulnerability in GitHub Enterprise Server allows i… |
| CVE-2026-14403 | 8.8 | 17.6 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote… |
| CVE-2026-55793 | 5.9 | 17.5 | craftcms | cms | CWE-79 | Craft CMS: Stored XSS via Structure entry title in table view |
| CVE-2026-12408 | 4.3 | 17.5 | rilwis | Slim SEO – A Fast & Automated SEO Plugin For WordPress | CWE-200 | Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization t… |
| CVE-2026-58033 | 5.3 | 17.2 | Wikimedia Foundation | MediaWiki | CWE-200 | "Total number of distinct authors" statistic at action=info does not exclude … |
| CVE-2026-14411 | 9.6 | 17.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-14420 | 9.6 | 17.0 | Google | Chrome | CWE-125 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 … |
| CVE-2026-14415 | 8.8 | 17.0 | Google | Chrome | CWE-122 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al… |
| CVE-2026-12577 | 8.7 | 16.9 | deltaww | DVP80ES3 | CWE-358 | DVP80ES3 Improperly Implemented Security Check for Standard vulnerability |
| CVE-2026-2891 | 8.2 | 16.9 | HP Inc | CCX | CWE-400 | Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service |
| CVE-2026-49090 | 6.5 | 16.7 | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-12133 | 4.3 | 16.6 | beardev | JoomSport – for Sports: Team & League, Football, Hockey & more | CWE-862 | JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arb… |
| CVE-2026-14428 | 8.3 | 16.5 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Androi… |
| CVE-2026-50284 | 7.1 | 16.5 | craftcms | cms | CWE-862 | Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFo… |
| CVE-2026-5138 | 4.3 | 16.5 | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | CWE-639 | Foreman: foreman: information disclosure via improper validation of nested re… |
| CVE-2026-14432 | 8.8 | 16.3 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote… |
| CVE-2026-7517 | 7.2 | 16.2 | dhruvin | Custom Payment Gateways for WooCommerce | CWE-79 | Custom Payment Gateways for WooCommerce <= 2.1.0 - Unauthenticated Stored Cro… |
| CVE-2026-13246 | 6.4 | 16.3 | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-79 | GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'b… |
| CVE-2026-10538 | 8.9 | 16.1 | BMC | Control-M/Enterprise Manager | CWE-502 | Improper deserialization handling in Control-M Components |
| CVE-2026-14427 | 8.3 | 16.0 | Google | Chrome | CWE-122 | Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed … |
| CVE-2026-50279 | 7.6 | 16.0 | craftcms | cms | CWE-285 | Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mut… |
| CVE-2026-53903 | 5.3 | 15.8 | MyComplianceOffice | MCO | CWE-639 | Insecure Direct Object Reference in MCO |
| CVE-2026-58036 | 2.1 | 15.8 | Wikimedia Foundation | MediaWiki | CWE-200 | Users API leaks whether privileged users have their user groups disabled for … |
| CVE-2026-14397 | 9.6 | 15.7 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 a… |
| CVE-2026-14416 | 9.6 | 15.7 | Google | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a … |
| CVE-2026-55594 | 5.3 | 15.5 | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Stack Overflow in MVG decoder due to missing depth check. |
| CVE-2026-13707 | 0.0 | 15.3 | Wikimedia Foundation | OAuth | CWE-384 | Session fixation attacks on improperly configured OAuth 1.0a tools |
| CVE-2026-12224 | 8.8 | 15.2 | wedevs | Dokan Pro | CWE-269 | Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_… |
| CVE-2026-55661 | 4.8 | 15.2 | tinacms | tinacms | CWE-79 | TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, al… |
| CVE-2026-14396 | 6.5 | 15.0 | Google | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a… |
| CVE-2026-14401 | 8.3 | 15.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome on Andro… |
| CVE-2026-14412 | 8.3 | 15.0 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… |
| CVE-2026-11794 | 8.1 | 14.9 | Unknown | Advanced Form Integration — Connect Forms to 200+ Apps | — | Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via … |
| CVE-2026-14390 | 9.6 | 14.6 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a rem… |
| CVE-2026-14394 | 8.8 | 14.6 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote… |
| CVE-2026-14414 | 5.3 | 14.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Skia in Google Chrome prior to … |
| CVE-2026-9107 | 6.4 | 14.5 | wpchill | Kali Forms — Contact Form & Drag-and-Drop Builder | CWE-79 | Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripti… |
| CVE-2026-10095 | 6.4 | 14.6 | opajaap | WP Photo Album Plus | CWE-79 | WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-14391 | 5.3 | 14.5 | Google | Chrome | CWE-190 | Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 … |
| CVE-2026-58027 | 5.3 | 14.5 | Wikimedia Foundation | AbuseFilter | CWE-200 | QueryAbuseFilter API can be used to see the hit count of private filters, whi… |
| CVE-2026-14389 | 8.3 | 14.4 | Google | Chrome | CWE-472 | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a re… |
| CVE-2026-12435 | 4.3 | 14.3 | stylemix | Motors – Car Dealership & Classified Listings Plugin | CWE-862 | Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbi… |
| CVE-2026-58026 | 0.0 | 14.3 | Wikimedia Foundation | MediaWiki | CWE-200 | $wgNonincludableNamespaces can be bypassed by embedding redirect in other nam… |
| CVE-2026-14429 | 8.3 | 13.8 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Skia in Google Chrome prior to … |
| CVE-2026-12113 | 4.3 | 13.7 | codepeople | Appointment Booking Calendar | CWE-862 | Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticat… |
| CVE-2026-53909 | 5.3 | 13.7 | MyComplianceOffice | MCO | CWE-434 | Arbitrary File Upload in MCO |
| CVE-2026-55577 | 5.9 | 13.5 | ImageMagick | ImageMagick | CWE-754 | ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder |
| CVE-2026-14399 | 6.5 | 13.3 | Google | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a r… |
| CVE-2026-14402 | 6.5 | 13.3 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46… |
| CVE-2026-14408 | 6.5 | 13.3 | Google | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a r… |
| CVE-2026-54704 | 6.5 | 13.2 | open-telemetry | opentelemetry-java-instrumentation | CWE-532 | OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-T… |
| CVE-2026-14400 | 8.3 | 13.1 | Google | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed … |
| CVE-2026-14423 | 9.6 | 12.8 | Google | Chrome | CWE-843 | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remo… |
| CVE-2026-46680 | 7.3 | 12.9 | containerd | containerd | CWE-269 | containerd user ID handling bypass allows runAsNonRoot evasion |
| CVE-2026-58029 | 5.3 | 12.9 | Wikimedia Foundation | MediaWiki | CWE-287 | Full Account Takeover from BotPasswords and OAuth via action=changeauthentica… |
| CVE-2026-7830 | 7.4 | 12.7 | uvnc | UltraVNC | CWE-326 | UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabli… |
| CVE-2026-53466 | 6.5 | 12.8 | ImageMagick | ImageMagick | CWE-190 | ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion o… |
| CVE-2026-57962 | 5.3 | 12.7 | Mozilla | Thunderbird | CWE-400 | Denial-of-service via malicious LDAP address-book server |
| CVE-2026-55688 | 4.0 | 12.7 | AsyncHttpClient | async-http-client | CWE-1275 | AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via T… |
| CVE-2026-54260 | 2.7 | 12.8 | wagtail | wagtail | CWE-400 | Wagtail: Denial of service via unbounded filter specs in the image preview |
| CVE-2026-14425 | 9.6 | 12.6 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a rem… |
| CVE-2026-14426 | 7.5 | 12.4 | Google | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote… |
| CVE-2026-54786 | 2.3 | 12.4 | bytecodealliance | wasmtime | CWE-400 | Wasmtime: Leak in WASIp1 `fd_renumber` implementation |
| CVE-2026-14398 | 9.6 | 12.2 | Google | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a rem… |
| CVE-2026-14419 | 9.6 | 12.2 | Google | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remo… |
| CVE-2026-14424 | 9.6 | 12.2 | Google | Chrome | CWE-416 | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed… |
| CVE-2026-14421 | 6.5 | 12.2 | Google | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46… |
| CVE-2026-12754 | 6.1 | 12.2 | e4jvikwp | VikBooking Hotel Booking Engine & PMS | CWE-79 | VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Script… |
| CVE-2026-13323 | 8.7 | 11.7 | Eclipse Foundation | Eclipse Open VSX | CWE-79 | In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-su… |
| CVE-2026-14381 | 6.5 | 11.7 | Google | Chrome | CWE-290 | Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.… |
| CVE-2026-58593 | 8.7 | 11.6 | NodeBB | NodeBB | CWE-290 | NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to L… |
| CVE-2026-53908 | 6.9 | 11.6 | MyComplianceOffice | MCO | CWE-204 | User Enumeration in MCO |
| CVE-2026-13015 | 6.1 | 11.6 | jgwhite33 | WP Google Review Slider | CWE-79 | WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' … |
| CVE-2026-49088 | 4.4 | 11.7 | Elastic | Kibana | CWE-532 | Insertion of Sensitive Information into Log File in Kibana Leading to Informa… |
| CVE-2026-5120 | 8.1 | 11.4 | Dassault Systèmes | BIOVIA Workbook | CWE-362 | Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 thro… |
| CVE-2026-53902 | 7.1 | 11.3 | MyComplianceOffice | MCO | CWE-266 | Privilege Escalation in MCO |
| CVE-2026-49858 | 5.9 | 11.3 | api-platform | core | CWE-524 | API Platform Core: Cross-user attribute leak in JSON:API and HAL item normali… |
| CVE-2026-14417 | 9.6 | 11.0 | Google | Chrome | CWE-416 | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remo… |
| CVE-2026-12158 | 8.8 | 10.8 | metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | CWE-352 | RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escala… |
| CVE-2026-20458 | 7.5 | 10.7 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In Modem, there is a possible memory corruption due to a missing bounds check… |
| CVE-2026-53904 | 6.3 | 10.6 | MyComplianceOffice | MCO | CWE-307 | Account Denial of Service in MCO |
| CVE-2026-54263 | 7.3 | 10.6 | wagtail | wagtail | CWE-79 | Wagtail: Reflected XSS in dynamic image URL generator view |
| CVE-2026-57720 | 4.3 | 10.6 | Codexpert Inc | ThumbPress | CWE-862 | WordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerability |
| CVE-2026-14413 | 8.3 | 10.5 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a … |
| CVE-2026-14404 | 6.5 | 10.4 | Google | Chrome | CWE-451 | Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.4… |
| CVE-2026-49091 | 8.0 | 10.3 | Elastic | Kibana | CWE-116 | Improper Output Neutralization for Logs in Kibana Leading to Log Injection |
| CVE-2026-54261 | 6.5 | 10.3 | wagtail | wagtail | CWE-280 | Wagtail: Improper permission handling in image preview |
| CVE-2026-13443 | 6.4 | 10.1 | themeum | Tutor LMS – eLearning and online course solution | CWE-79 | Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via… |
| CVE-2026-13733 | 6.4 | 10.1 | codename065 | Download Manager | CWE-79 | Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-12135 | 6.4 | 10.1 | foliovision | FV Flowplayer Video Player | CWE-79 | FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stor… |
| CVE-2026-56152 | 5.3 | 10.1 | Elastic | Elastic Defend | CWE-863 | Incorrect Authorization in Elastic Defend Leading to Information Disclosure |
| CVE-2026-53467 | 5.3 | 9.9 | ImageMagick | ImageMagick | CWE-200 | ImageMagick: Information Disclosure in MNG decoder because allocated memory i… |
| CVE-2026-55660 | 7.6 | 9.6 | tinacms | tinacms | CWE-79 | TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization byp… |
| CVE-2026-10096 | 4.3 | 9.6 | qodeinteractive | Qi Blocks | CWE-639 | Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Autho… |
| CVE-2026-14440 | 7.6 | 9.6 | Cloudflare | Universal SSL | CWE-693 | Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-… |
| CVE-2026-54164 | 6.5 | 9.6 | api-platform | core | CWE-843 | API Platform Core: Missing IRI type check enables resource type confusion |
| CVE-2026-58517 | 6.9 | 9.5 | The Wikimedia Foundation | Mediawiki - WikiLambda Extension | CWE-288 | Blocked users can create and edit WikiLambda objects |
| CVE-2026-27409 | 5.3 | 9.4 | Webba Plugins | Webba Booking | CWE-862 | WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability |
| CVE-2026-53905 | 5.3 | 9.3 | MyComplianceOffice | MCO | CWE-863 | Unauthorized Access to Administrator ACL View in MCO |
| CVE-2026-57963 | 6.5 | 9.1 | Mozilla | Thunderbird | CWE-79 | Chat UI manipulation by injection |
| CVE-2026-58032 | 5.3 | 9.1 | Wikimedia Foundation | MediaWiki | CWE-79 | mw.Api.getErrorMessage() may return injected HTML if used without errorformat… |
| CVE-2026-14410 | 4.3 | 9.0 | Google | Chrome | CWE-451 | Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 … |
| CVE-2026-14406 | 5.9 | 8.9 | Google | Chrome | CWE-125 | Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an a… |
| CVE-2026-12732 | 6.4 | 8.7 | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | CWE-79 | LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-53489 | 8.2 | 8.6 | containerd | containerd | CWE-61 | containerd: Arbitrary host CRI log file read via symlink following in CRI che… |
| CVE-2026-14418 | 4.3 | 8.4 | Google | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a … |
| CVE-2026-41579 | 3.3 | 8.5 | opencontainers | runc | CWE-61 | runc: Malicious image with /dev symlink can trigger limited host filesystem i… |
| CVE-2026-20457 | 5.3 | 8.1 | MediaTek, Inc. | MediaTek chipset | CWE-476 | In Modem, there is a possible system crash due to improper input validation. … |
| CVE-2026-20461 | 5.3 | 7.9 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In Modem, there is a possible out of bounds write due to a missing bounds che… |
| CVE-2026-58263 | 7.2 | 7.8 | xdan | jodit | CWE-79 | Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext car… |
| CVE-2026-57721 | 5.3 | 7.7 | WP Reloaded | ApplyOnline | CWE-862 | WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability |
| CVE-2026-11887 | 4.3 | 7.6 | Unknown | Salon Booking System | — | Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass |
| CVE-2026-53488 | 9.4 | 7.4 | containerd | containerd | CWE-20 | containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binar… |
| CVE-2026-58520 | 6.9 | 7.5 | The Wikimedia Foundation | Mediawiki - UrlShortener Extension | CWE-601 | UrlShortener defaults to ineffective validation open to third-party redirects |
| CVE-2026-24243 | 7.8 | 7.3 | NVIDIA | Megatron-Bridge | CWE-502 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-24248 | 7.8 | 7.3 | NVIDIA | Megatron-Bridge | CWE-94 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-57736 | 7.4 | 7.3 | HubSpot | HubSpot | CWE-201 | WordPress HubSpot plugin <= 11.3.51 - Sensitive Data Exposure vulnerability |
| CVE-2026-14358 | 6.9 | 7.3 | The Wikimedia Foundation | Mediawiki - Charts Extension | CWE-79 | Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title |
| CVE-2026-14324 | 6.5 | 7.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | Pipewire: raop rtsp null deref |
| CVE-2026-20460 | 5.3 | 7.2 | MediaTek, Inc. | MediaTek chipset | CWE-288 | In Modem, there is a possible information disclosure due to improper input va… |
| CVE-2026-58030 | 5.3 | 7.0 | Wikimedia Foundation | SyntaxHighlight_GeSHi | CWE-79 | SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute |
| CVE-2026-27435 | 5.3 | 6.8 | WofficeIO | Woffice | CWE-862 | WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability |
| CVE-2026-58028 | 0.0 | 6.8 | Wikimedia Foundation | MediaWiki | CWE-79 | Pretty-printed API output combined with centralauthtoken allows XSS with cert… |
| CVE-2026-54074 | 7.8 | 6.8 | tinacms | tinacms | CWE-94 | @tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TI… |
| CVE-2026-24246 | 7.8 | 6.6 | NVIDIA | Megatron-Bridge | CWE-470 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-24247 | 7.8 | 6.6 | NVIDIA | Megatron-Bridge | CWE-502 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-20459 | 5.3 | 6.6 | MediaTek, Inc. | MediaTek chipset | CWE-288 | In Modem, there is a possible system crash due to improper input validation. … |
| CVE-2026-58034 | 0.0 | 6.6 | Wikimedia Foundation | CheckUser | CWE-79 | Stored XSS through a system message when blocking a temporary account that's … |
| CVE-2026-58035 | 0.0 | 6.6 | Wikimedia Foundation | MediaWiki | CWE-79 | Stored XSS through a system message in the codex version of Special:Block |
| CVE-2026-58037 | 0.0 | 6.6 | Wikimedia Foundation | MediaWiki | CWE-79 | Core log entries for exceptions and XSS issues in log entry formatting code t… |
| CVE-2026-58038 | 0.0 | 6.6 | Wikimedia Foundation | timeline | CWE-79 | Stored XSS through javascript URLs in SVGs generated by EasyTimeline |
| CVE-2026-24240 | 7.8 | 6.2 | NVIDIA | Megatron-Bridge | CWE-502 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-24249 | 7.8 | 6.1 | NVIDIA | Megatron-Bridge | CWE-94 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-11562 | 4.3 | 5.9 | Unknown | WS Form LITE | — | WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update |
| CVE-2026-54259 | 4.3 | 5.8 | wagtail | wagtail | CWE-280 | Wagtail: Improper restriction handling on Documents and Images chosen endpoints |
| CVE-2026-54262 | 4.3 | 5.8 | wagtail | wagtail | CWE-280 | Wagtail: Pages translations can be created without page permissions when usin… |
| CVE-2026-58031 | 0.0 | 5.4 | Wikimedia Foundation | MediaWiki | CWE-79 | Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected |
| CVE-2026-24250 | 7.8 | 5.2 | NVIDIA | Megatron-Bridge | CWE-502 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-24251 | 7.8 | 5.2 | NVIDIA | Megatron-Bridge | CWE-502 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-54720 | 5.4 | 5.1 | silverstripe | silverstripe-framework | CWE-79 | Silverstripe Framework: Possible XSS attack through media embed |
| CVE-2026-24244 | 7.8 | 5.1 | NVIDIA | Megatron-Bridge | CWE-502 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-24245 | 7.8 | 5.1 | NVIDIA | Megatron-Bridge | CWE-502 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-11981 | 4.3 | 5.1 | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-352 | GiveWP <= 4.15.3 - Cross-Site Request Forgery |
| CVE-2026-12576 | 7.5 | 5.0 | deltaww | DVP80ES3 | CWE-924 | DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a C… |
| CVE-2026-2387 | 6.4 | 4.8 | stephenharris | Event Organiser | CWE-79 | Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Sc… |
| CVE-2026-11380 | 6.4 | 4.8 | jetmonsters | JetWidgets For Elementor | CWE-79 | JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Sit… |
| CVE-2026-24242 | 7.8 | 4.6 | NVIDIA | Megatron-Bridge | CWE-918 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c… |
| CVE-2026-5220 | 6.4 | 4.5 | DivvyDrive Information Technologies Inc. | DivvyDrive | CWE-79 | Stored XSS in DivvyDrive Information Technologies' DivvyDrive |
| CVE-2026-57722 | 5.9 | 4.6 | ShortPixel | Enable Media Replace | CWE-79 | WordPress Enable Media Replace plugin <= 4.2.1 - Cross Site Scripting (XSS) v… |
| CVE-2026-34096 | 4.8 | 4.4 | guardian | language-system | CWE-79 | Guardian Language-System XSS via name Parameter in designer.php |
| CVE-2026-34097 | 4.8 | 4.4 | guardian | language-system | CWE-79 | Guardian Language-System XSS via id Parameter in text_file.php |
| CVE-2026-34098 | 4.8 | 4.4 | guardian | language-system | CWE-79 | Guardian Language-System XSS via id Parameter in media.php |
| CVE-2026-53907 | 4.8 | 3.9 | MyComplianceOffice | MCO | CWE-79 | Stored Cross‑Site Scripting in MCO |
| CVE-2026-13211 | 4.3 | 3.8 | genua | genucenter | CWE-201 | Genucenter Disclosure of SNMP Credentials |
| CVE-2026-11880 | 3.1 | 3.8 | Unknown | Fluent Forms | — | Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR |
| CVE-2026-11570 | 4.2 | 3.6 | Unknown | User Submitted Posts | — | User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name |
| CVE-2026-57737 | 6.5 | 3.4 | Averta LTD | Shortcodes and extra features for Phlox theme | CWE-79 | WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.16 - C… |
| CVE-2026-53329 | 7.0 | 3.4 | Linux | Linux | CWE-674 | drm/amd/display: Use krealloc_array() in dal_vector_reserve() |
| CVE-2026-58519 | 6.9 | 3.3 | The Wikimedia Foundation | Mediawiki - Cargo Extension | CWE-79 | Stored XSS through Cargo's map format |
| CVE-2026-6283 | 5.4 | 3.3 | DivvyDrive Information Technologies Inc. | DivvyDrive | CWE-79 | Stored XSS in DivvyDrive Information Technologies' DivvyDrive |
| CVE-2026-53354 | 8.8 | 3.0 | Linux | Linux | — | arm64: errata: Mitigate TLBI errata on various Arm CPUs |
| CVE-2026-53327 | 5.5 | 3.0 | Linux | Linux | — | debugobjects: Do not fill_pool() if pi_blocked_on |
| CVE-2026-12480 | 5.5 | 2.8 | keras-team | keras-team/keras | CWE-73 | Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras |
| CVE-2026-53341 | 7.8 | 2.7 | Linux | Linux | CWE-416 | fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() |
| CVE-2026-57723 | 7.4 | 2.5 | e4jvikwp | VikBooking Hotel Booking Engine & PMS | CWE-352 | WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Ar… |
| CVE-2026-53330 | 7.1 | 2.5 | Linux | Linux | CWE-125 | drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval() |
| CVE-2026-41121 | 7.8 | 2.5 | Dell | Device Management Agent | CWE-59 | Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improp… |
| CVE-2026-53331 | 5.5 | 2.4 | Linux | Linux | — | slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock |
| CVE-2026-53332 | 5.5 | 2.4 | Linux | Linux | — | slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd |
| CVE-2025-15666 | 1.9 | 2.5 | Open Asset Import Library | Assimp | CWE-119 | Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based… |
| CVE-2026-53328 | 5.5 | 2.4 | Linux | Linux | — | sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() |
| CVE-2026-53356 | 7.8 | 2.2 | Linux | Linux | — | drm/i915/gem: Fix phys BO pread/pwrite with offset |
| CVE-2026-36909 | 6.2 | 2.2 | n/a | n/a | CWE-476 | A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Alek… |
| CVE-2026-53334 | 5.5 | 2.1 | Linux | Linux | CWE-476 | mm/damon/reclaim: handle ctx allocation failure |
| CVE-2026-53335 | 5.5 | 2.1 | Linux | Linux | CWE-476 | mm/damon/lru_sort: handle ctx allocation failure |
| CVE-2026-13769 | 6.8 | 2.0 | AWS | AWS CLI | CWE-732 | Overly permissive File Permissions in AWS CLI |
| CVE-2026-53346 | 7.1 | 1.9 | Linux | Linux | CWE-125 | rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES |
| CVE-2026-53336 | 5.5 | 1.7 | Linux | Linux | — | nvmem: layouts: onie-tlv: fix hang on unknown types |
| CVE-2026-53337 | 5.5 | 1.8 | Linux | Linux | CWE-476 | net: bonding: fix NULL pointer dereference in bond_do_ioctl() |
| CVE-2026-53339 | 5.5 | 1.7 | Linux | Linux | CWE-476 | i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() |
| CVE-2026-53343 | 5.5 | 1.7 | Linux | Linux | — | ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow |
| CVE-2026-53345 | 5.5 | 1.7 | Linux | Linux | CWE-401 | KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying |
| CVE-2026-53347 | 5.5 | 1.7 | Linux | Linux | CWE-908 | drm/virtio: Fix driver removal with disabled KMS |
| CVE-2026-53349 | 5.5 | 1.7 | Linux | Linux | — | netfilter: nf_conntrack: destroy stale expectfn expectations on unregister |
| CVE-2026-53350 | 5.5 | 1.7 | Linux | Linux | CWE-476 | ASoC: wm_adsp: Fix NULL dereference when removing firmware controls |
| CVE-2026-53353 | 5.5 | 1.7 | Linux | Linux | — | hsr: Remove WARN_ONCE() in hsr_addr_is_self(). |
| CVE-2026-36910 | 5.5 | 1.7 | n/a | n/a | CWE-119 | An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MP… |
| CVE-2026-53333 | 5.5 | 1.6 | Linux | Linux | — | mm/mincore: handle non-swap entries before !CONFIG_SWAP guard |
| CVE-2026-53338 | 5.5 | 1.6 | Linux | Linux | CWE-476 | net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_… |
| CVE-2026-53340 | 5.5 | 1.6 | Linux | Linux | — | i2c: imx: fix clock and pinctrl state inconsistency in runtime PM |
| CVE-2026-53342 | 5.5 | 1.6 | Linux | Linux | — | arm64: mm: call pagetable dtor when freeing hot-removed page tables |
| CVE-2026-20462 | 6.7 | 1.5 | MediaTek, Inc. | MediaTek chipset | CWE-122 | In Telephony, there is a possible memory corruption due to a heap buffer over… |
| CVE-2026-36911 | 5.5 | 1.5 | n/a | n/a | CWE-369 | A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBuffe… |
| CVE-2026-20463 | 6.7 | 1.5 | MediaTek, Inc. | MediaTek chipset | CWE-280 | In Modem, there is a possible escalation of privilege due to a permissions by… |
| CVE-2026-55510 | 5.5 | 1.1 | ImageMagick | ImageMagick | CWE-416 | ImageMagick: Use-After-Free in crafted 8BIM when identifying an image |
| CVE-2026-55597 | 5.5 | 1.1 | ImageMagick | ImageMagick | CWE-682 | ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect hand… |
| CVE-2026-14330 | 5.5 | 1.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Pipewire: pulse server alloca stack overflow |
| CVE-2026-53344 | 5.5 | 1.0 | Linux | Linux | CWE-908 | pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init |
| CVE-2026-53348 | 5.5 | 1.0 | Linux | Linux | CWE-476 | ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions |
| CVE-2026-53351 | 5.5 | 1.0 | Linux | Linux | — | riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI |
| CVE-2026-55628 | 5.5 | 0.9 | ImageMagick | ImageMagick | CWE-73 | ImageMagick: Policy Bypass in concatenate operation due to missing checks |
| CVE-2026-53326 | 5.5 | 0.7 | Linux | Linux | CWE-667 | debugobjects: Don't call fill_pool() in early boot hardirq context |
| CVE-2026-55595 | 4.7 | 0.5 | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Infinite Loop in connected-components when providing invalid arg… |
| CVE-2026-58518 | 6.9 | 0.5 | The Wikimedia Foundation | Mediawiki - RedirectManager Extension | CWE-352 | Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation M… |
| CVE-2026-8480 | 4.3 | 0.4 | Stormshield | Stormshield Network Security | CWE-295 | Connection possible to the Administration portal with a revoked certificate |
| CVE-2026-53352 | 4.7 | 0.4 | Linux | Linux | CWE-362 | signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() |
| CVE-2026-10540 | 5.6 | 0.1 | BMC | Control-M/Enterprise Manager | CWE-328 | Weak password hash protection in Control-M/Entreprise Manager |
| CVE-2026-12374 | 6.4 | 0.0 | Cato Networks | SDP Client | CWE-295 | Improper XPC caller certificate validation and TOCTOU race condition in macOS… |