| CVE-2026-44190 | 7.8 | 36.0 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-78 | Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrar… |
| CVE-2026-11331 | 7.5 | 34.7 | ISC | BIND 9 | CWE-790 | Potential wildcard CNAME RPZ policy bypass |
| CVE-2026-65600 | 7.8 | 34.2 | traefik | traefik | CWE-22 | Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex |
| CVE-2026-65650 | 4.3 | 32.2 | Elgg | Elgg | CWE-770 | Elgg before 7.0.0 does not check image dimensions to prevent denial of servic… |
| CVE-2025-50327 | 8.8 | 31.7 | n/a | n/a | CWE-693 | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attac… |
| CVE-2026-11721 | 7.5 | 31.6 | ISC | BIND 9 | CWE-1284 | Cache poisoning possible with label count discrepancy, RRSIG, and wildcards |
| CVE-2026-10822 | 6.5 | 30.2 | ISC | BIND 9 | CWE-617 | Key Record using PRIVATEDNS algorithm may lead to unexpected exit |
| CVE-2026-65589 | 5.1 | 30.3 | n8n-io | n8n | CWE-532 | n8n before 1.123.64 Credential Exposure via LLM Node Execution Data |
| CVE-2025-50324 | 8.8 | 29.4 | n/a | n/a | CWE-693 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker … |
| CVE-2025-50330 | 8.8 | 29.4 | n/a | n/a | CWE-693 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote … |
| CVE-2026-13189 | 7.5 | 29.1 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-36 | SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI fo… |
| CVE-2026-3821 | 8.8 | 28.6 | SMCI | X14DBG-DAP,X14DBI | CWE-78 | Supermicro SMASH service contain an Arbitrary code execution issue |
| CVE-2026-2395 | 9.8 | 28.5 | Xpoda Türkiye Informatics Technology Inc. | No Code Platform | CWE-89 | SQLi in Xpoda Türkiye Informatics Technology's No Code Platform |
| CVE-2026-40712 | 7.2 | 28.0 | Dell | PowerProtect Data Manager | CWE-20 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp… |
| CVE-2026-46738 | 7.2 | 28.0 | Dell | PowerProtect Data Manager | CWE-20 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp… |
| CVE-2026-46737 | 7.2 | 27.9 | Dell | PowerProtect Data Manager | CWE-20 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp… |
| CVE-2026-16544 | 6.5 | 27.7 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-862 | Awx: websocket eventconsumer missing authorization for inventory_update_event… |
| CVE-2026-64830 | 8.7 | 27.3 | FFmpeg | FFmpeg | CWE-122 | FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer |
| CVE-2026-13187 | 8.1 | 27.1 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-470 | DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET… |
| CVE-2026-64832 | 8.7 | 26.4 | FFmpeg | FFmpeg | CWE-415 | FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c |
| CVE-2026-65014 | 6.3 | 26.3 | n8n-io | n8n | CWE-306 | n8n before 2.28.0 Authentication Bypass via test-webhook |
| CVE-2026-64835 | 8.7 | 25.6 | FFmpeg | FFmpeg | CWE-787 | FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder |
| CVE-2026-65015 | 7.2 | 25.2 | n8n-io | n8n | CWE-863 | n8n before 2.30.1 Privilege Escalation via run_node_tool |
| CVE-2026-64829 | 9.1 | 25.0 | q2a | question2answer | CWE-613 | Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow |
| CVE-2026-65590 | 5.5 | 24.9 | n8n-io | n8n | CWE-78 | n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows |
| CVE-2026-13182 | 7.5 | 24.8 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-209 | RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik … |
| CVE-2026-13183 | 7.5 | 24.8 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-208 | RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for … |
| CVE-2026-4773 | 8.1 | 24.7 | Magarsus Consulting Ltd. Co. | IDM-MFA | CWE-1287 | OTP Bypass in Magarsus' IDM-MFA |
| CVE-2026-60367 | 9.8 | 24.4 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-13072 | 9.2 | 24.2 | MongoDB | MongoDB Server | CWE-122 | MongoDB Improper Input Validation in Compute Mode External Data Processing Le… |
| CVE-2026-60366 | 10.0 | 23.7 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-60372 | 9.8 | 23.7 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-60368 | 8.8 | 23.6 | Oracle Corporation | Oracle Platform Security for Java | CWE-1104 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-16632 | 5.5 | 23.7 | boazsegev | facil.io | CWE-20 | boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_e… |
| CVE-2026-65016 | 7.7 | 23.4 | n8n-io | n8n | CWE-639 | n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance… |
| CVE-2026-61391 | 7.2 | 23.0 | Hikvision | DS-2CD Series | CWE-121 | There is a stack-based buffer overflow vulnerability in some Hikvision camera… |
| CVE-2026-48029 | 7.1 | 23.0 | strukturag | libheif | CWE-125 | libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced t… |
| CVE-2026-65603 | 8.7 | 22.9 | getgrav | grav | CWE-269 | Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update |
| CVE-2026-65013 | 8.7 | 22.5 | onlook | repo | CWE-639 | Onlook tRPC Insecure Direct Object Reference via multiple procedures |
| CVE-2026-13065 | 7.1 | 22.2 | MongoDB | MongoDB Server | CWE-476 | MongoDB $linearFill Window Function Improper Input Validation Leading to Proc… |
| CVE-2025-44090 | 8.8 | 21.8 | n/a | n/a | CWE-693 | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary c… |
| CVE-2026-40691 | 7.5 | 21.8 | NLnet Labs | Unbound | CWE-122 | Packet of death for DNSCrypt over TCP |
| CVE-2026-12968 | 8.8 | 21.7 | Unknown | Product Addons and Product Options With Custom Fields | CWE-79 | Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrar… |
| CVE-2026-55973 | 7.5 | 21.6 | NLnet Labs | Unbound | CWE-20 | 'dns-error-reporting: yes' leads to stack buffer overflow |
| CVE-2026-2406 | 6.5 | 21.6 | Universe Software Computer Marketing Trade and Industry Inc. | Online Registration and Workflow Management System | CWE-639 | IDOR in Universe Software's Online Registration and Workflow Management System |
| CVE-2025-44089 | 8.8 | 21.3 | n/a | n/a | CWE-693 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitr… |
| CVE-2026-49499 | 8.8 | 21.1 | Dell | PowerProtect Data Manager | CWE-1270 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Gene… |
| CVE-2026-22049 | 8.7 | 21.1 | NETAPP | ONTAP 9 | CWE-288 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (M… |
| CVE-2025-50325 | 5.4 | 21.1 | n/a | n/a | CWE-693 | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vu… |
| CVE-2026-64796 | 9.8 | 21.0 | regularlabs.com | Sourcerer extension for Joomla | CWE-284 | Joomla Extension - regularlabs.com - various code injection vectors in Source… |
| CVE-2026-32665 | 7.5 | 21.0 | NLnet Labs | Unbound | CWE-1284 | Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass |
| CVE-2026-13055 | 7.1 | 20.8 | MongoDB | MongoDB Server | CWE-617 | Server crash via aggregation pipeline expression with compound wildcard index… |
| CVE-2026-13056 | 7.1 | 20.8 | MongoDB | MongoDB Server | CWE-1325 | A user with read access can cause a DoS by executing a specifically crafted q… |
| CVE-2026-16624 | 9.6 | 20.6 | Cal.com | Cal.diy | CWE-639 | CVE-2026-16624 |
| CVE-2026-60369 | 9.9 | 20.4 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-60373 | 8.8 | 20.4 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-40714 | 7.2 | 20.2 | Dell | PowerProtect Data Manager | CWE-20 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp… |
| CVE-2026-16270 | 6.9 | 20.2 | Open Mercato | Open Mercato | CWE-1333 | ReDoS in Open Mercato |
| CVE-2026-50045 | 5.3 | 20.2 | NLnet Labs | Unbound | CWE-406 | 'max-global-quota' reset by DNSSEC validation restarts |
| CVE-2025-13146 | 6.5 | 19.9 | sevenspark | Contact Form 7 – Dynamic Text Extension | CWE-94 | Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary … |
| CVE-2026-14899 | 7.5 | 19.8 | Mozilla | Thunderbird | CWE-193 | Off-by-one out of bounds read in MIME header parser for forwarding |
| CVE-2026-65601 | 5.3 | 19.8 | traefik | traefik | CWE-863 | Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef |
| CVE-2026-13059 | 8.6 | 19.6 | MongoDB | MongoDB Server | CWE-807 | Improper Validation of Client-Supplied Command Parameters Allowing Role-Based… |
| CVE-2026-60439 | 8.8 | 19.2 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-14586 | 5.9 | 19.0 | NLnet Labs | Unbound | CWE-617 | Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC … |
| CVE-2026-65594 | 5.1 | 19.0 | n8n-io | n8n | CWE-863 | n8n before 2.30.1 Missing OAuth Authorization Check |
| CVE-2026-12987 | 7.5 | 18.9 | Unknown | Events Manager | CWE-89 | Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injecti… |
| CVE-2026-10723 | 6.8 | 18.5 | ISC | BIND 9 | CWE-347 | Incorrect acceptance of NSEC3 records |
| CVE-2026-41637 | 3.7 | 18.5 | NLnet Labs | Unbound | CWE-772 | Degradation of resolution service from improperly accounted client-terminated… |
| CVE-2026-61246 | 8.8 | 18.4 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-13074 | 6.9 | 17.8 | MongoDB | MongoDB Server | CWE-770 | Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to … |
| CVE-2026-3482 | 5.3 | 17.8 | IBM | Sterling B2B Integrator | CWE-639 | IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass |
| CVE-2026-63264 | 5.3 | 17.6 | joomshopping.com | JoomShopping extension for Joomla | CWE-79 | Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 |
| CVE-2026-65012 | 6.3 | 17.4 | invoke-ai | InvokeAI | CWE-306 | InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder |
| CVE-2026-55990 | 5.9 | 17.5 | NLnet Labs | Unbound | CWE-457 | Packet of death for a DNSCrypt misconfigured Unbound |
| CVE-2026-45820 | 6.6 | 17.2 | 101arrowz | fflate | CWE-400 | fflate through 0.8.2 is vulnerable to denial of service via an infinite loop … |
| CVE-2026-14865 | 5.3 | 17.3 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-776 | XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP… |
| CVE-2026-16615 | 6.8 | 17.1 | GNOME | librest | CWE-338 | Librest: weak random number generation in pkce implementation |
| CVE-2026-50251 | 5.3 | 17.1 | NLnet Labs | Unbound | CWE-184 | Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush |
| CVE-2026-16551 | 6.9 | 16.9 | Thinkst Applied Research | OpenCanary | CWE-20 | Denial-of-Service in OpenCanary's MongoDB module |
| CVE-2026-13057 | 6.0 | 16.9 | MongoDB | MongoDB Server | CWE-20 | Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauth… |
| CVE-2026-64792 | 7.5 | 16.5 | regularlabs.com | Articles Anywhere extension for Joomla | CWE-524 | Joomla Extension - regularlabs.com - disclosure of restricted content via sea… |
| CVE-2026-57600 | 7.5 | 16.4 | Hikvision | DS-2CD Series | CWE-20 | Insufficient validation of input parameters in the firmware of some Hikvision… |
| CVE-2026-44621 | 5.9 | 16.3 | NLnet Labs | Unbound | CWE-754 | Libunbound applications configured with 'unwanted-reply-threshold' could even… |
| CVE-2026-64793 | 9.1 | 16.2 | regularlabs.com | Articles Anywhere extension for Joomla | CWE-284 | Joomla Extension - regularlabs.com - Content access and publication bypass in… |
| CVE-2026-64798 | 9.1 | 16.0 | regularlabs.com | IP Login extension for Joomla | CWE-338 | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login exte… |
| CVE-2026-13071 | 7.1 | 16.0 | MongoDB | MongoDB Server | CWE-416 | Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to … |
| CVE-2026-16473 | 4.3 | 15.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame |
| CVE-2026-8152 | 9.3 | 15.9 | Unblu inc. | Unblu Spark | CWE-79 | Unblu Spark Open Redirect leading to DOM-Based XSS |
| CVE-2026-60455 | 8.8 | 15.9 | Oracle Corporation | Oracle Platform Security for Java | CWE-269 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-13192 | 6.5 | 15.8 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-918 | RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX |
| CVE-2026-64794 | 6.5 | 15.8 | regularlabs.com | Articles Anywhere extension for Joomla | CWE-284 | Joomla Extension - regularlabs.com - restricted user-data exposure in Users A… |
| CVE-2026-16560 | 5.3 | 15.9 | Red Hat | Red Hat Directory Server 11 | CWE-1220 | 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multi… |
| CVE-2026-65598 | 8.9 | 15.5 | n8n-io | n8n | CWE-367 | n8n before 1.123.64 Remote Code Execution via Git Clone |
| CVE-2026-13077 | 7.1 | 15.5 | MongoDB | MongoDB Server | CWE-125 | Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSON… |
| CVE-2026-15787 | 6.4 | 15.5 | brainstormforce | Ultimate Addons for Elementor | CWE-79 | Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored … |
| CVE-2026-13089 | 7.5 | 15.4 | RITOU | OIDC::Lite | CWE-347 | OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verifica… |
| CVE-2026-50046 | 5.9 | 15.0 | NLnet Labs | Unbound | CWE-416 | Possible heap use-after-free in an error path when a DoT forwarded query is j… |
| CVE-2026-52863 | 5.9 | 15.0 | NLnet Labs | Unbound | CWE-416 | Memory corruption could lead to crash and denial of service |
| CVE-2026-55717 | 5.9 | 15.0 | NLnet Labs | Unbound | CWE-476 | 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to… |
| CVE-2026-55991 | 5.9 | 15.0 | NLnet Labs | Unbound | CWE-195 | Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 |
| CVE-2026-56444 | 5.9 | 15.0 | NLnet Labs | Unbound | CWE-772 | Degradation of resolution service when 'discard-timeout' and 'serve-expired-c… |
| CVE-2026-13060 | 7.1 | 14.8 | MongoDB | MongoDB Server | CWE-863 | $graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Una… |
| CVE-2026-9737 | 7.1 | 14.6 | MongoDB | MongoDB Server | CWE-617 | Find command with $meta sort can lead to crash |
| CVE-2026-13075 | 7.1 | 14.7 | MongoDB | MongoDB Server | CWE-770 | $rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggest… |
| CVE-2026-13076 | 7.1 | 14.6 | MongoDB | MongoDB Server | CWE-770 | Aggregation Framework Memory Exhaustion Leading to Process Termination |
| CVE-2026-63047 | 7.5 | 14.3 | joomdonation.com | Events Booking extension for Joomla | CWE-284 | Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect… |
| CVE-2026-13058 | 7.1 | 14.0 | MongoDB | MongoDB Server | CWE-617 | Transaction Command Insufficient Input Validation Leading to Process Termination |
| CVE-2026-13064 | 7.1 | 14.0 | MongoDB | MongoDB Server | CWE-407 | MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denia… |
| CVE-2026-13063 | 5.3 | 14.0 | MongoDB | MongoDB Server | CWE-190 | libmongocrypt Improper Input Validation Leading to Process Termination |
| CVE-2026-63685 | 8.8 | 13.9 | regularlabs.com | DB Replacer extension for Joomla | CWE-284 | Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer exte… |
| CVE-2026-61390 | 7.7 | 13.7 | Hikvision | DS-2CD Series | CWE-122 | There is a heap buffer overflow vulnerability in some Hikvision cameras, whic… |
| CVE-2026-13066 | 7.1 | 13.7 | MongoDB | MongoDB Server | CWE-843 | Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure |
| CVE-2026-63048 | 9.4 | 13.5 | joomlack.fr | Page Builder CK extension for Joomla | CWE-434 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK <… |
| CVE-2026-63683 | 7.5 | 13.5 | regularlabs.com | Advanced Module Manager extension for Joomla | CWE-290 | Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regu… |
| CVE-2026-65011 | 5.3 | 12.5 | Graylog2 | graylog2-server | CWE-862 | Graylog2 Server Missing Permission Check on Event Definition Duplicate |
| CVE-2026-44687 | 3.7 | 12.5 | NLnet Labs | Unbound | CWE-193 | Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward z… |
| CVE-2026-13321 | 8.6 | 12.4 | ISC | BIND 9 | CWE-346 | DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field |
| CVE-2026-65597 | 8.2 | 12.0 | n8n-io | n8n | CWE-79 | n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe |
| CVE-2026-64833 | 7.1 | 12.0 | FFmpeg | FFmpeg | CWE-125 | FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c |
| CVE-2026-13073 | 5.3 | 11.8 | MongoDB | MongoDB Server | CWE-617 | MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Te… |
| CVE-2026-57599 | 6.6 | 11.6 | Hikvision | DS-2CD Series | CWE-269 | There is a privilege escalation vulnerability in some Hikvision cameras. Due … |
| CVE-2026-64828 | 5.3 | 11.6 | Froiden | TableTrack | CWE-79 | Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field |
| CVE-2026-13078 | 6.3 | 11.4 | MongoDB | MongoDB Server | CWE-862 | Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader |
| CVE-2026-14932 | 6.5 | 11.3 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-321 | Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart |
| CVE-2026-65596 | 5.1 | 11.3 | n8n-io | n8n | CWE-863 | n8n before 1.123.64 Credential Exfiltration via GraphQL Node |
| CVE-2026-61392 | 5.3 | 11.0 | Hikvision | DS-2CD Series | CWE-200 | There is a information disclosure vulnerability in some Hikvision cameras, al… |
| CVE-2026-42955 | 3.7 | 10.6 | NLnet Labs | Unbound | CWE-672 | Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallow… |
| CVE-2026-13184 | 7.5 | 10.4 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-321 | RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.… |
| CVE-2026-64797 | 7.5 | 10.4 | regularlabs.com | IP Login extension for Joomla | CWE-290 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login ex… |
| CVE-2026-60370 | 7.5 | 10.3 | Oracle Corporation | Oracle Platform Security for Java | CWE-1021 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-16490 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System prescription.php sql injection |
| CVE-2026-65602 | 5.3 | 8.4 | traefik | traefik | CWE-863 | Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass |
| CVE-2026-14322 | 5.3 | 8.0 | Unknown | Timetics | CWE-284 | Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payme… |
| CVE-2026-46582 | 3.7 | 8.0 | NLnet Labs | Unbound | CWE-358 | A wildcard replay, as another piece of data, triggers poisoning in the serve … |
| CVE-2026-54478 | 3.7 | 7.6 | NLnet Labs | Unbound | CWE-290 | DNS Cookie bypass when combined with proxy-protocol use |
| CVE-2026-38763 | 5.5 | 7.4 | n/a | n/a | CWE-400 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at… |
| CVE-2026-14985 | 7.8 | 7.1 | Analog Way | Picturall Quad Compact Mark II | CWE-22 | CVE-2026-14985 |
| CVE-2026-13069 | 7.1 | 7.0 | MongoDB | MongoDB Server | CWE-770 | Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Re… |
| CVE-2026-65592 | 8.4 | 6.9 | n8n-io | n8n | CWE-79 | n8n before 1.123.64 Stored DOM XSS via cachedResultUrl |
| CVE-2026-38765 | 7.8 | 6.9 | n/a | n/a | CWE-269 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at… |
| CVE-2026-38766 | 7.8 | 6.9 | n/a | n/a | CWE-269 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at… |
| CVE-2026-60371 | 8.0 | 6.8 | Oracle Corporation | Oracle Platform Security for Java | CWE-200 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi… |
| CVE-2026-13061 | 5.3 | 6.3 | MongoDB | MongoDB Server | CWE-863 | Improper Access Control Allowing Cross-User Session Metadata Disclosure in $l… |
| CVE-2026-65599 | 5.1 | 5.0 | n8n-io | n8n | CWE-312 | n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header |
| CVE-2026-14881 | 8.4 | 4.9 | MongoDB | MongoDB Compass | CWE-78 | Compass connection import allows to override OIDC browser open command (usual… |
| CVE-2026-55708 | 3.1 | 4.7 | NLnet Labs | Unbound | CWE-1188 | Privacy/configuration issue when adding local data in views through 'unbound-… |
| CVE-2026-44192 | 6.6 | 4.6 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-22 | Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and … |
| CVE-2025-60835 | 7.8 | 4.5 | n/a | n/a | CWE-35 | An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute… |
| CVE-2026-13068 | 2.3 | 4.6 | MongoDB | MongoDB Server | CWE-863 | MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cr… |
| CVE-2026-44690 | 7.5 | 4.3 | NLnet Labs | Unbound | CWE-345 | Cross-zone wildcard cache poisoning via RRSIG.labels manipulation |
| CVE-2026-65593 | 6.3 | 4.1 | n8n-io | n8n | CWE-918 | n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters |
| CVE-2026-63281 | 4.8 | 4.0 | regularlabs.com | Advanced Module Manager extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs condit… |
| CVE-2026-50252 | 5.7 | 3.9 | NLnet Labs | Unbound | CWE-349 | Possible cache poisoning attack by mapping source port population per thread |
| CVE-2026-64795 | 5.4 | 3.3 | regularlabs.com | Modals extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in va… |
| CVE-2026-14551 | 8.8 | 3.2 | servereye GmbH | servereye Windows Agent (Sensorhub) | CWE-73 | Local Privilege Escalation in servereye client (sensorhub) |
| CVE-2026-56844 | 8.4 | 3.0 | Veeam | Backup and Replication | CWE-22 | A vulnerability in the Veeam Updater component of the Veeam Software Applianc… |
| CVE-2026-50248 | 6.5 | 2.9 | NLnet Labs | Unbound | CWE-345 | BOGUS configured primary hostname accepted for XFR in auth/rpz zones |
| CVE-2026-63280 | 8.8 | 2.8 | regularlabs.com | Advanced Module Manager extension for Joomla | CWE-352 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile… |
| CVE-2026-63684 | 8.8 | 2.8 | regularlabs.com | Content Templater extension for Joomla | CWE-352 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile… |
| CVE-2026-64791 | 8.8 | 2.8 | regularlabs.com | Regular Labs Extension Manager extension for Joomla | CWE-352 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile… |
| CVE-2026-16157 | 7.8 | 2.0 | Duplicati | Duplicati | CWE-732 | Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission a… |
| CVE-2026-56416 | 4.8 | 2.0 | NLnet Labs | Unbound | CWE-354 | Possible heap buffer overflow when validator canonicalizes RDATA that contain… |
| CVE-2026-63265 | 8.0 | 1.8 | regularlabs.com | Advanced Module Manager extension for Joomla | CWE-352 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile… |
| CVE-2026-13062 | 7.1 | 1.7 | MongoDB | MongoDB Server | CWE-441 | MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption … |
| CVE-2026-13188 | 5.9 | 1.5 | Progress Software | Telerik UI for ASP.NET AJAX | CWE-345 | DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX |
| CVE-2026-44276 | 4.4 | 1.4 | Dell | PowerProtect Data Manager | CWE-200 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exp… |
| CVE-2026-50243 | 6.3 | 1.3 | NLnet Labs | Unbound | CWE-348 | 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL |
| CVE-2026-16607 | 8.5 | 1.0 | Fujitsu | Linux openFT | CWE-269 | Authenticated local root privilege escalation vulnerability in openFT for Lin… |
| CVE-2026-7328 | 6.8 | 0.6 | Caliptra | Core Runtime Firmware | CWE-862 | Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service |
| CVE-2026-13070 | 6.0 | 0.5 | MongoDB | MongoDB Server | CWE-476 | Improper Validation of OCSP Response During Outbound TLS Handshake Leading to… |
| CVE-2026-44187 | 3.3 | 0.5 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-256 | Ansible-lightspeed: ansible lightspeed extension for visual studio code: info… |
| CVE-2026-13067 | 7.2 | 0.0 | MongoDB | MongoDB Server | CWE-863 | tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domai… |