| CVE-2026-58158 | 8.2 | 43.9 | Apache Software Foundation | Apache Traffic Server | CWE-121 | Apache Traffic Server: PROXY protocol parsing has port truncation and a stack… |
| CVE-2026-65883 | 10.0 | 43.8 | aimy-extensions.com | Aimy Captcha-Less Form Guard plugin for Joomla | CWE-502 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy… |
| CVE-2026-58179 | 9.2 | 43.7 | Apache Software Foundation | Apache Traffic Server | CWE-121 | Apache Traffic Server: regex_remap plugin overflows the stack from attacker i… |
| CVE-2026-58160 | 6.3 | 43.5 | Apache Software Foundation | Apache Traffic Server | CWE-125 | Apache Traffic Server: Out-of-bounds reads while parsing DNS responses |
| CVE-2026-14270 | 8.8 | 43.3 | ThemeComplete | Extra Checkout Options - addon for Extra Product Options plugin | CWE-434 | Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooComm… |
| CVE-2026-58177 | 8.3 | 43.3 | Apache Software Foundation | Apache Traffic Server | CWE-787 | Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts … |
| CVE-2026-58186 | 8.2 | 43.2 | Apache Software Foundation | Apache Traffic Server | CWE-20 | Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels d… |
| CVE-2026-58182 | 8.2 | 43.0 | Apache Software Foundation | Apache Traffic Server | CWE-400 | Apache Traffic Server: ts_lua plugin has initialization and resource-handling… |
| CVE-2026-13423 | 9.8 | 42.7 | Unknown | Streamit | CWE-94 | Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Funct… |
| CVE-2026-58159 | 7.0 | 42.1 | Apache Software Foundation | Apache Traffic Server | CWE-863 | Apache Traffic Server: Listener and ACL handling allow access-control bypass |
| CVE-2026-58183 | 8.2 | 41.3 | Apache Software Foundation | Apache Traffic Server | CWE-20 | Apache Traffic Server: prefetch plugin can crash on attacker-influenced input |
| CVE-2026-67429 | 10.0 | 40.2 | flytohub | flyto-core | CWE-22 | Flyto2 Core: Arbitrary file write via image.download (and other file-writing … |
| CVE-2026-66723 | 7.0 | 40.2 | CERT.PL | MWDB Core | CWE-862 | Missing authentication requirement in Remote Instances proxy API in MWDB Core |
| CVE-2025-10656 | 9.8 | 40.1 | holest | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | CWE-863 | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37… |
| CVE-2026-58181 | 8.2 | 40.1 | Apache Software Foundation | Apache Traffic Server | CWE-121 | Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack … |
| CVE-2026-11974 | 8.6 | 39.9 | Unknown | wp-media-folder-addon | CWE-22 | Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download |
| CVE-2026-58189 | 8.2 | 39.8 | Apache Software Foundation | Apache Traffic Server | CWE-918 | Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amp… |
| CVE-2026-5057 | 7.5 | 39.6 | ATEN | Unizon | CWE-306 | ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability |
| CVE-2026-5490 | 8.8 | 39.4 | DriveLock | DriveLock | CWE-89 | DriveLock SQL Injection Privilege Escalation Vulnerability |
| CVE-2026-58151 | 8.7 | 39.0 | Apache Software Foundation | Apache Traffic Server | CWE-400 | Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash… |
| CVE-2026-65324 | 8.2 | 39.0 | Apache Software Foundation | Apache Traffic Server | CWE-400 | Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer… |
| CVE-2026-58153 | 6.3 | 38.8 | Apache Software Foundation | Apache Traffic Server | CWE-444 | Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers t… |
| CVE-2026-58184 | 8.3 | 37.9 | Apache Software Foundation | Apache Traffic Server | CWE-787 | Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory |
| CVE-2026-58187 | 6.3 | 37.6 | Apache Software Foundation | Apache Traffic Server | CWE-787 | Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of s… |
| CVE-2026-58157 | 6.9 | 37.5 | Apache Software Foundation | Apache Traffic Server | CWE-200 | Apache Traffic Server: Improper server-session reuse can expose data across c… |
| CVE-2026-65100 | 6.3 | 37.3 | Apache Software Foundation | Apache Traffic Server | CWE-696 | Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a … |
| CVE-2026-58185 | 8.2 | 37.1 | Apache Software Foundation | Apache Traffic Server | CWE-416 | Apache Traffic Server: Use-after-free in the intercept plugin |
| CVE-2026-67432 | 7.5 | 36.3 | modelcontextprotocol | ruby-sdk | CWE-770 | MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allo… |
| CVE-2026-50622 | 8.8 | 36.1 | Apache Software Foundation | Apache Atlas | CWE-862 | Apache Atlas: Missing Authorization on Admin Endpoints |
| CVE-2026-54680 | 9.9 | 35.5 | kube-logging | logging-operator | CWE-74 | Logging operator has Fluentd configuration injection that allows remote code … |
| CVE-2026-5056 | 7.8 | 35.5 | GStreamer | GStreamer | CWE-121 | GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabi… |
| CVE-2026-67595 | 9.2 | 35.2 | webreinvent | vaahcms | CWE-506 | VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blad… |
| CVE-2026-46678 | 5.9 | 34.9 | pydantic | pydantic-ai | CWE-918 | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incom… |
| CVE-2026-60112 | 9.3 | 34.0 | NASA-AMMOS | AIT-GUI | CWE-306 | AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() |
| CVE-2026-60113 | 9.3 | 34.0 | NASA-AMMOS | AIT-DSN | CWE-306 | AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes |
| CVE-2026-15975 | 7.5 | 32.6 | GitLab | GitLab | CWE-770 | Allocation of Resources Without Limits or Throttling in GitLab |
| CVE-2026-67201 | 7.7 | 32.2 | vlang | v | CWE-436 | V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http |
| CVE-2026-58155 | 9.2 | 31.8 | Apache Software Foundation | Apache Traffic Server | CWE-444 | Apache Traffic Server: Header-name length truncation enables header aliasing … |
| CVE-2026-18191 | 9.3 | 31.5 | Vacron | VIN-DS783E-E6 | CWE-912 | Vacron|IP Camera - Hidden Functionality |
| CVE-2026-67215 | 8.7 | 31.1 | DaveGamble | cJSON | CWE-674 | cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion |
| CVE-2026-18192 | 7.1 | 31.2 | Vacron | VIN-DS783E-E6 | CWE-23 | Vacron|IP Camera - Arbitrary File Read |
| CVE-2026-58154 | 9.2 | 30.4 | Apache Software Foundation | Apache Traffic Server | CWE-787 | Apache Traffic Server: Memory-safety errors in MIME and header parsing |
| CVE-2026-0667 | 9.3 | 29.9 | Schneider Electric | SCADAPack 47x | CWE-754 | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability t… |
| CVE-2026-12144 | 8.8 | 29.9 | saadiqbal | Wholesale for WooCommerce | CWE-269 | Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escala… |
| CVE-2026-65886 | 9.2 | 29.5 | balbooa.com | Gridbox extension for Joomla | CWE-22 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridb… |
| CVE-2026-14529 | 9.8 | 29.1 | IBM | WebSphere Application Server | CWE-306 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-15344 | 4.9 | 28.6 | opajaap | WP Photo Album Plus | CWE-89 | WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Inject… |
| CVE-2026-67437 | 7.5 | 28.5 | OliveTin | OliveTin | CWE-400 | OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded M… |
| CVE-2026-54735 | 10.0 | 28.2 | prebid | prebid-server | CWE-918 | prebid-server's request forgery vulnerability allows for possible host enviro… |
| CVE-2026-67216 | 8.2 | 28.1 | DaveGamble | cJSON | CWE-407 | cJSON cJSON_Compare Exponential Complexity Denial of Service |
| CVE-2026-50782 | 7.5 | 28.0 | n/a | n/a | CWE-611 | Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in… |
| CVE-2026-22068 | 6.9 | 27.8 | Apache Software Foundation | Apache Traffic Server | CWE-777 | Apache Traffic Server: Regex mappings match with malicious domain names |
| CVE-2026-13346 | 5.6 | 27.8 | Python Packaging Authority | pip | CWE-36 | pip absolute path traversal during download from malicious package indexes |
| CVE-2026-13307 | 6.8 | 27.4 | Autel | MaxiCharger AC Elite Home | CWE-122 | Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code… |
| CVE-2026-18022 | 8.8 | 27.3 | n/a | pgvector | CWE-190 | pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-… |
| CVE-2026-54693 | 8.2 | 27.3 | zitadel | zitadel | CWE-863 | ZITADEL Users Can Self-Verify Email/Phone via API |
| CVE-2026-67427 | 8.6 | 26.9 | flytohub | flyto-core | CWE-522 | Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get be… |
| CVE-2026-57834 | 7.0 | 26.8 | Apache Software Foundation | Apache Traffic Server | CWE-444 | Apache Traffic Server: Malformed chunked message body allows request smuggling |
| CVE-2026-67428 | 8.5 | 26.6 | flytohub | flyto-core | CWE-918 | Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs withou… |
| CVE-2026-33267 | 7.7 | 26.5 | Apache Software Foundation | Apache Traffic Server | CWE-20 | Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata |
| CVE-2026-59899 | 6.9 | 26.4 | netty | netty | CWE-770 | Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 … |
| CVE-2026-6267 | 5.3 | 26.2 | GitLab | GitLab | CWE-201 | Insertion of Sensitive Information Into Sent Data in GitLab |
| CVE-2026-58162 | 8.4 | 26.1 | Apache Software Foundation | Apache Traffic Server | CWE-295 | Apache Traffic Server: Certifier plugin trusts client SNI when generating cer… |
| CVE-2026-44943 | 6.9 | 25.9 | open-iscsi | open-iscsi | CWE-22 | remote limited file-write as root via discovery in open-iscsi |
| CVE-2026-63227 | 9.9 | 25.7 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. | Koollab LMS | CWE-434 | Unrestricted SCORM file upload vulnerability |
| CVE-2026-24033 | 6.9 | 25.6 | Apache Software Foundation | Apache Traffic Server | CWE-444 | Apache Traffic Server: Request smuggling via chunked extension quoted-string … |
| CVE-2026-13723 | 6.5 | 25.6 | Develar | app-builder | CWE-22 | Develar's electron-builder allows arbitrary file overwrite |
| CVE-2026-14341 | 4.9 | 25.5 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-13697 | 9.1 | 25.4 | undici | undici | CWE-200 | undici vulnerable to cross-user information disclosure and parse-time crash v… |
| CVE-2026-33930 | 8.2 | 25.1 | Apache Software Foundation | Apache Traffic Server | CWE-121 | Apache Traffic Server: Buffer overflow via Host field that has a long string … |
| CVE-2026-58152 | 6.9 | 25.1 | Apache Software Foundation | Apache Traffic Server | CWE-190 | Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrup… |
| CVE-2026-54078 | 8.7 | 24.7 | veraPDF | veraPDF-validation | CWE-611 | veraPDF Validation XXE via Rich Text |
| CVE-2026-54079 | 8.7 | 24.7 | veraPDF | veraPDF-validation | CWE-611 | veraPDF Validation XXE via XFA |
| CVE-2026-67425 | 8.6 | 24.7 | flytohub | flyto-core | CWE-201 | Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url |
| CVE-2026-67213 | 8.2 | 24.7 | nanoid_project | nanoid | CWE-835 | nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customR… |
| CVE-2026-67214 | 8.2 | 24.7 | nanoid_project | nanoid | CWE-835 | nanoid before 5.1.16 Infinite Loop via Negative Size in non-secure module |
| CVE-2026-58150 | 7.8 | 24.3 | Apache Software Foundation | Apache Traffic Server | CWE-444 | Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejecte… |
| CVE-2026-12436 | 8.4 | 23.6 | GitLab | GitLab | CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attribute… |
| CVE-2026-14488 | 9.1 | 23.3 | Meta Box | Meta Box AIO | CWE-862 | Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Po… |
| CVE-2026-67194 | 7.1 | 23.1 | svarshavchik | Courier IMAP | CWE-674 | Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH… |
| CVE-2026-16655 | 7.2 | 23.0 | wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | CWE-79 | Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name … |
| CVE-2026-54080 | 6.9 | 22.7 | veraPDF | veraPDF-parser | CWE-1325 | veraPDF Parser DoS via PostScript CMap Streams |
| CVE-2026-54081 | 6.9 | 22.7 | veraPDF | veraPDF-parser | CWE-1325 | veraPDF Parser DoS via PostScript Type 1 Font Programs |
| CVE-2026-11973 | 4.9 | 22.7 | wp-lab | WP-Lister Lite for eBay | CWE-89 | WP-Lister Lite for eBay <= 3.8.8 - Authenticated (Shop Manager+) SQL Injectio… |
| CVE-2026-8338 | 9.2 | 22.5 | Black Duck | Coverity Connect | CWE-288 | Authentication and Authorization Bypass in Coverity Connect |
| CVE-2026-50642 | 4.8 | 22.5 | so-fancy | diff-so-fancy | CWE-116 | Terminal Escape Injection in diff‑so‑fancy |
| CVE-2026-16326 | 10.0 | 22.5 | HashiCorp | Tooling | CWE-488 | consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-H… |
| CVE-2026-63229 | 9.1 | 22.1 | Three Learning | Koollab LMS | CWE-89 | Pre-authentication blind SQL injection vulnerability |
| CVE-2026-63230 | 9.1 | 22.1 | Three Learning | Koollab LMS | CWE-89 | Pre-authentication error-based SQL injection vulnerability |
| CVE-2026-41920 | 7.0 | 22.2 | Apache Software Foundation | Apache Traffic Server | CWE-284 | Apache Traffic Server: SNI to Host header matching policy is not properly enf… |
| CVE-2026-16751 | 6.5 | 22.0 | Ente | Museum Server | — | Ente Museum Server Authorization Bypass Vulnerability |
| CVE-2026-63232 | 9.9 | 22.0 | Three Learning | Koollab LMS | CWE-89 | SQL injection and unsafe deserialisation vulnerability |
| CVE-2026-63233 | 9.9 | 22.0 | Three Learning | Koollab LMS | CWE-89 | SQL injection and unsafe deserialisation vulnerability |
| CVE-2026-63234 | 9.9 | 22.0 | Three Learning | Koollab LMS | CWE-89 | SQL injection and unsafe deserialisation vulnerability |
| CVE-2026-14351 | 4.3 | 22.0 | GitLab | GitLab | CWE-1230 | Exposure of Sensitive Information Through Metadata in GitLab |
| CVE-2026-18207 | 6.5 | 21.8 | Red Hat | Red Hat Build of Keycloak | CWE-285 | Keycloak-services: keycloak-services: client policy source-group condition by… |
| CVE-2026-67426 | 9.3 | 21.6 | flytohub | flyto-core | CWE-306 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and i… |
| CVE-2026-67430 | 5.3 | 21.6 | modelcontextprotocol | ruby-sdk | CWE-401 | MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows m… |
| CVE-2026-9177 | 9.4 | 21.3 | Axway | SecureTransport | CWE-1336 | Server-Side Template Injection in SecureTransport's Apache Velocity mail temp… |
| CVE-2026-65885 | 9.4 | 21.1 | balbooa.com | Gridbox extension for Joomla | CWE-434 | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridb… |
| CVE-2026-54666 | 8.3 | 21.1 | acacode | swagger-typescript-api | CWE-74 | swagger-typescript-api vulnerable to code injection via unescaped OpenAPI pat… |
| CVE-2026-67435 | 6.0 | 21.1 | Linuxfabrik | monitoring-plugins | CWE-200 | linuxfabrik-lib: fetch() forwards credential headers across a cross-origin re… |
| CVE-2026-18201 | 5.5 | 21.0 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: generic identity-provider creation can … |
| CVE-2026-4672 | 4.3 | 21.0 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-65884 | 10.0 | 20.9 | balbooa.com | Gridbox extension for Joomla | CWE-284 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 |
| CVE-2026-65887 | 10.0 | 20.9 | balbooa.com | Gridbox extension for Joomla | CWE-284 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in … |
| CVE-2026-65888 | 10.0 | 20.9 | balbooa.com | Gridbox extension for Joomla | CWE-284 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < … |
| CVE-2026-65889 | 9.2 | 20.9 | balbooa.com | Gridbox extension for Joomla | CWE-284 | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion… |
| CVE-2026-6089 | 4.9 | 20.2 | blendmedia | WP CTA – Call Now Button, Sticky Button & Call to Action Builder | CWE-918 | WP CTA <= 2.1.2 - Authenticated (Administrator+) Server-Side Request Forgery |
| CVE-2025-69943 | 9.8 | 20.0 | n/a | n/a | CWE-89 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in ge… |
| CVE-2026-65890 | 9.2 | 20.0 | balbooa.com | Gridbox extension for Joomla | CWE-89 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2… |
| CVE-2026-67431 | 8.3 | 20.1 | modelcontextprotocol | ruby-sdk | CWE-284 | MCP Ruby SDK: Ruby SSE Session Poisoning |
| CVE-2026-18255 | 7.2 | 19.6 | Red Hat | Red Hat Quay 3 | CWE-863 | Quay: quay: global read-only superuser can view robot account tokens |
| CVE-2026-54661 | 8.3 | 19.2 | acacode | swagger-typescript-api | CWE-74 | swagger-typescript-api vulnerable to code injection via unescaped `servers[0]… |
| CVE-2026-54662 | 8.3 | 19.2 | acacode | swagger-typescript-api | CWE-74 | swagger-typescript-api vulnerable to code injection via unescaped `servers[0]… |
| CVE-2026-54664 | 8.3 | 19.2 | acacode | swagger-typescript-api | CWE-74 | swagger-typescript-api vulnerable to code injection via unescaped enum string… |
| CVE-2026-18197 | 6.4 | 19.0 | — | Link Library | CWE-79 | Improper neutralization of input during web page generation ('cross-site scri… |
| CVE-2026-66724 | 5.3 | 19.0 | CERT.PL | MWDB Core | CWE-862 | Permission Bypass Via Undocumented HTTP Methods In MWDB Core |
| CVE-2026-67193 | 6.9 | 18.4 | Xlight | Xlight FTP Server | CWE-203 | Xlight FTP Server < 3.9.5 Information Disclosure via USER Command |
| CVE-2026-59901 | 8.7 | 18.2 | netty | netty | CWE-835 | Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Th… |
| CVE-2025-65340 | 9.8 | 17.9 | n/a | n/a | CWE-89 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /… |
| CVE-2025-67403 | 9.8 | 17.9 | n/a | n/a | CWE-89 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj… |
| CVE-2025-67404 | 9.8 | 17.9 | n/a | n/a | CWE-89 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj… |
| CVE-2025-69942 | 9.8 | 17.9 | n/a | n/a | CWE-89 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /… |
| CVE-2026-6336 | 5.3 | 17.2 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-13690 | 7.4 | 17.1 | Unknown | UsersWP | CWE-287 | UsersWP < 1.2.67 - Two-Factor Authentication Bypass |
| CVE-2026-16553 | 5.4 | 17.1 | GitLab | GitLab | CWE-522 | Insufficiently Protected Credentials in GitLab |
| CVE-2026-55995 | 8.7 | 16.8 | open-iscsi | open-iscsi | CWE-415 | Double-free in the iSNS attribute decoder in open-iscsi |
| CVE-2026-63231 | 8.1 | 16.9 | Three Learning | Koollab LMS | CWE-89 | Post-authentication SQL injection vulnerability |
| CVE-2026-67439 | 4.3 | 16.9 | OliveTin | OliveTin | CWE-863 | OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Ac… |
| CVE-2026-67217 | 6.9 | 16.6 | DaveGamble | cJSON | CWE-696 | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation |
| CVE-2026-50558 | 5.9 | 16.6 | brightio | penelope | CWE-22 | Penelope unsafe tar extraction allows arbitrary local file write via crafted … |
| CVE-2026-15077 | 4.3 | 16.7 | GitLab | GitLab | CWE-74 | Improper Neutralization of Input Used for LLM Prompting in GitLab |
| CVE-2026-67436 | 8.3 | 16.5 | Linuxfabrik | monitoring-plugins | CWE-20 | Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidate… |
| CVE-2026-59898 | 6.3 | 16.5 | netty | netty | CWE-444 | Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation |
| CVE-2026-13425 | 7.2 | 16.4 | code4life | Database for CF7 | CWE-79 | Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via A… |
| CVE-2026-15144 | 5.3 | 16.2 | @fastify/rate-limit | @fastify/rate-limit | CWE-307 | @fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation |
| CVE-2026-54660 | 7.4 | 15.8 | acacode | swagger-typescript-api | CWE-200 | swagger-typescript-api vulnerable to authorization-token exfiltration via spe… |
| CVE-2026-18266 | 5.4 | 15.7 | LangGenius | Dify | CWE-601 | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability |
| CVE-2026-16597 | 7.2 | 15.5 | duracelltomi | GTM4WP – A Google Tag Manager (GTM) plugin for WordPress | CWE-79 | GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerc… |
| CVE-2026-8791 | 6.4 | 15.5 | ameliabooking | Booking System Trafft | CWE-79 | Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Si… |
| CVE-2026-33385 | 5.1 | 15.4 | OpenSolution | Quick.CMS | CWE-89 | Blind SQL Injection in Quick.CMS |
| CVE-2026-14300 | 8.1 | 15.2 | Unknown | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) | CWE-287 | miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover |
| CVE-2026-59920 | 6.5 | 15.2 | netty | netty | CWE-93 | Netty: STOMP CONNECT Frame Header Injection |
| CVE-2026-3093 | 4.7 | 15.1 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-64557 | 8.8 | 14.8 | Linux | Linux | — | Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() |
| CVE-2026-67424 | 8.5 | 14.9 | flytohub | flyto-core | CWE-918 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space withou… |
| CVE-2026-13605 | 6.8 | 14.7 | Unknown | PhotoSwipe | CWE-79 | Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute |
| CVE-2026-4604 | 5.3 | 14.6 | klubraum | Klubraum Membership Request | CWE-862 | Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticat… |
| CVE-2026-12703 | 8.0 | 14.6 | TeamViewer | Remote | CWE-288 | Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS |
| CVE-2026-16328 | 8.6 | 14.3 | HashiCorp | Tooling | CWE-918 | consul-mcp-server vulnerable to server side request forgery leading to token … |
| CVE-2025-60931 | 7.5 | 14.3 | n/a | n/a | CWE-639 | An Insecure Direct Object Reference (IDOR) in the Employee Compensation View … |
| CVE-2026-65943 | 7.5 | 14.3 | rolandd.com | RO CSVI extension for Joomla | CWE-284 | Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI <… |
| CVE-2026-59900 | 6.9 | 14.3 | netty | netty | CWE-444 | Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Trans… |
| CVE-2026-17166 | 4.3 | 14.3 | magepeopleteam | Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar | CWE-862 | Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Aut… |
| CVE-2026-14643 | 7.5 | 14.1 | undici | undici | CWE-436 | undici vulnerable to cross-user information disclosure via whitespace around … |
| CVE-2026-54082 | 6.5 | 14.1 | veraPDF | veraPDF-validation | CWE-611 | veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When … |
| CVE-2026-13309 | 6.8 | 13.7 | Autel | MaxiCharger AC Elite Home | CWE-121 | Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Cod… |
| CVE-2025-14562 | 3.1 | 13.3 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-58156 | 6.3 | 13.0 | Apache Software Foundation | Apache Traffic Server | CWE-863 | Apache Traffic Server: URL and port parsing errors allow access-control bypass |
| CVE-2026-15831 | 4.3 | 12.9 | GitLab | GitLab | CWE-1270 | Generation of Incorrect Security Tokens in GitLab |
| CVE-2026-5060 | 6.5 | 12.8 | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | CWE-639 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14… |
| CVE-2026-12895 | 7.1 | 12.3 | Frappe | ERPNext | CWE-89 | SQL Injection in Frappe's ERPNext |
| CVE-2026-63238 | 6.5 | 12.3 | Three Learning | Koollab LMS | CWE-287 | Authentication bypass vulnerability |
| CVE-2026-12938 | 6.4 | 11.8 | contrid | Newsletters | CWE-79 | Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-12939 | 6.4 | 11.8 | contrid | Newsletters | CWE-79 | Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-54705 | 6.3 | 11.3 | arnog | mathlive | CWE-116 | mathlive's Lack of Escaping of HTML allows for XSS |
| CVE-2026-11351 | 5.3 | 11.0 | Unknown | ShinyStat Analytics | CWE-200 | ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Informat… |
| CVE-2026-66489 | 5.3 | 10.8 | balbooa.com | Gridbox extension for Joomla | CWE-200 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosu… |
| CVE-2026-66488 | 5.3 | 10.7 | balbooa.com | Gridbox extension for Joomla | CWE-285 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 |
| CVE-2026-8339 | 8.7 | 10.6 | Black Duck | Coverity Connect | CWE-89 | SQL Injection in Coverity Connect SOAP API |
| CVE-2025-67406 | 7.3 | 10.5 | n/a | n/a | CWE-89 | https://www.sourcecodester.com Advocate office management system 1.0 is affec… |
| CVE-2026-18236 | 9.3 | 10.3 | Google | Google-ADK | CWE-863 | Google-ADK Continuation Forgery |
| CVE-2026-12927 | 8.4 | 10.3 | Schneider Electric | IGSS Definition (Def.exe) | CWE-787 | CWE-787 Out-of-bounds write vulnerability exists that could cause loss of dat… |
| CVE-2026-13113 | 5.3 | 10.2 | GitLab | GitLab | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab |
| CVE-2026-5626 | 4.3 | 10.1 | bplugins | Survey Form Block – collect answers and insights from your audience | CWE-862 | Survey Form Block <= 1.0.1 - Missing Authorization to Authenticated (Subscrib… |
| CVE-2026-63118 | 6.9 | 9.9 | modelcontextprotocol | ruby-sdk | CWE-346 | MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) pro… |
| CVE-2026-54249 | 6.8 | 9.8 | pydantic | pydantic-ai | CWE-918 | VercelAIAdapter trusts client-controlled `providerMetadata` to construct `Upl… |
| CVE-2026-65975 | 6.5 | 9.8 | pydantic | pydantic-ai | CWE-863 | Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute … |
| CVE-2026-64685 | 5.3 | 9.8 | ImageMagick | ImageMagick | CWE-125 | ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file c… |
| CVE-2026-63235 | 3.7 | 9.6 | Three Learning | Koollab LMS | CWE-284 | Improper access control vulnerability |
| CVE-2026-65891 | 6.5 | 9.6 | joomlacontenteditor.net | Joomla Content Editor (JCE) extension for Joomla | CWE-20 | Joomla Extension - joomlacontenteditor.net - Creation of hidden files and uni… |
| CVE-2026-7436 | 6.4 | 9.3 | wpclever | WPC Badge Management for WooCommerce | CWE-79 | WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) … |
| CVE-2026-15735 | 6.4 | 9.3 | itpathsolutions | Contact Form to Any API | CWE-79 | Contact Form to Any API <= 3.0.6 - Authenticated (Contributor+) Stored Cross-… |
| CVE-2026-17161 | 6.4 | 9.3 | wpxpo | WowStore – Store Builder & Product Blocks for WooCommerce | CWE-79 | WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-17162 | 6.4 | 9.3 | wpxpo | WowStore – Store Builder & Product Blocks for WooCommerce | CWE-79 | WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-18174 | 5.3 | 9.3 | @fastify/forwarded | @fastify/forwarded | CWE-20 | @fastify/forwarded vulnerable to improper input validation via unstripped tab… |
| CVE-2026-16463 | 7.8 | 9.2 | Autodesk | AutoCAD | CWE-122 | DXF File Parsing Heap-Based Overflow in Autodesk AutoCAD |
| CVE-2026-18220 | 7.8 | 8.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation pro… |
| CVE-2026-13306 | 4.3 | 8.1 | Autel | MaxiCharger AC Elite Home | CWE-306 | Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability |
| CVE-2026-13692 | 5.3 | 8.0 | Unknown | PayU CommercePro Plugin | CWE-862 | PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering |
| CVE-2026-16465 | 7.1 | 8.0 | Autodesk | AutoCAD | CWE-125 | DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD |
| CVE-2026-54663 | 6.1 | 8.0 | acacode | swagger-typescript-api | CWE-20 | swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` |
| CVE-2026-17550 | 5.5 | 7.7 | Autodesk | AutoCAD | CWE-125 | DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD |
| CVE-2025-69949 | 7.3 | 7.4 | n/a | n/a | CWE-89 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in c… |
| CVE-2026-16728 | 6.5 | 7.4 | undici | undici | CWE-444 | undici vulnerable to downstream response desynchronization via retry interceptor |
| CVE-2026-63240 | 4.3 | 7.4 | Three Learning | Koollab LMS | CWE-200 | Information disclosure vulnerability |
| CVE-2026-35226 | 7.1 | 6.9 | CODESYS | CODESYS PROFINET | CWE-787 | Out-of-bounds Write in CODESYS PROFINET Controller |
| CVE-2025-67405 | 7.3 | 6.6 | n/a | n/a | CWE-89 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj… |
| CVE-2025-67407 | 7.3 | 6.6 | n/a | n/a | CWE-89 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj… |
| CVE-2025-67408 | 7.3 | 6.6 | n/a | n/a | CWE-89 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj… |
| CVE-2025-69944 | 7.3 | 6.6 | n/a | n/a | CWE-89 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in t… |
| CVE-2025-69945 | 7.3 | 6.6 | n/a | n/a | CWE-89 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /… |
| CVE-2026-16729 | 6.5 | 6.4 | undici | undici | CWE-74 | undici vulnerable to cookie attribute injection via unsanitized domain and un… |
| CVE-2026-63236 | 3.7 | 6.4 | Three Learning | Koollab LMS | CWE-284 | Improper access control vulnerability |
| CVE-2026-65325 | 6.3 | 6.2 | Apache Software Foundation | Apache Traffic Server | CWE-295 | Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without … |
| CVE-2026-50641 | 7.1 | 5.7 | Streamsoft | Business Intelligence | CWE-256 | Plaintext password storage in Streamsoft Business Intelligence |
| CVE-2025-65337 | 6.1 | 5.1 | n/a | n/a | CWE-79 | Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (… |
| CVE-2026-66490 | 6.1 | 5.1 | balbooa.com | Gridbox extension for Joomla | CWE-79 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment av… |
| CVE-2026-56389 | 6.8 | 5.1 | GNU | Bison | CWE-78 | Arbitrary Command Execution in GNU Bison |
| CVE-2026-15157 | 5.4 | 5.1 | undici | undici | CWE-93 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| CVE-2026-66400 | 6.3 | 4.9 | getgrav | grav | CWE-613 | Grav Login Plugin before 3.8.13 Insufficient Session Expiration |
| CVE-2026-63242 | 4.3 | 4.9 | Three Learning | Koollab LMS | CWE-639 | Business logic vulnerability |
| CVE-2026-13268 | 7.8 | 4.8 | G DATA | Total Security | CWE-59 | G DATA Total Security Backup Service Link Following Local Privilege Escalatio… |
| CVE-2026-65946 | 6.1 | 4.6 | rolandd.com | RO CSVI extension for Joomla | CWE-79 | Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSV… |
| CVE-2026-14224 | 5.4 | 4.4 | Unknown | Easy Appointments | CWE-639 | Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modific… |
| CVE-2026-54574 | 8.2 | 4.3 | termux | proot-distro | CWE-61 | `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via M… |
| CVE-2026-15228 | 7.1 | 3.9 | — | Kong/kubernetes-ingress-controller | CWE-400 | Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via… |
| CVE-2026-16543 | 7.1 | 3.9 | — | Kong/kong-operator | CWE-400 | Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-cert… |
| CVE-2026-63241 | 3.1 | 3.9 | Three Learning | Koollab LMS | CWE-639 | Insecure direct object reference vulnerability |
| CVE-2026-56390 | 4.6 | 3.3 | GNU | Bison | CWE-73 | Arbitrary Output Location Change in GNU Bison |
| CVE-2026-65944 | 8.8 | 3.1 | rolandd.com | RO CSVI extension for Joomla | CWE-352 | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CS… |
| CVE-2026-59247 | 7.6 | 3.0 | gleam-lang | gleam | CWE-345 | Insufficient verification of Hex package metadata in Gleam |
| CVE-2026-63119 | 6.2 | 3.0 | modelcontextprotocol | ruby-sdk | CWE-400 | MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhau… |
| CVE-2026-9720 | 4.3 | 2.9 | facturadorvirtual | Facturación Electrónica Costa Rica | CWE-352 | Facturación Electrónica Costa Rica <= 2.0.2 - Cross-Site Request Forgery to P… |
| CVE-2026-63228 | 2.6 | 2.9 | Three Learning | Koollab LMS | CWE-434 | Unrestricted image upload vulnerability |
| CVE-2026-65947 | 7.3 | 2.7 | balbooa.com | Gridbox extension for Joomla | CWE-352 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface … |
| CVE-2026-62343 | 4.7 | 2.5 | ImageMagick | ImageMagick | CWE-190 | ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid k… |
| CVE-2026-63239 | 5.4 | 2.3 | Three Learning | Koollab LMS | CWE-798 | Hard-coded AWS IAM credentials vulnerability |
| CVE-2026-54727 | 8.2 | 2.3 | termux | proot-distro | CWE-668 | proot-distro has a Container Isolation Bypass via Crafted Restore Archive |
| CVE-2026-13305 | 6.4 | 2.3 | Autel | MaxiCharger AC Elite Home | CWE-347 | Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryp… |
| CVE-2026-64556 | 7.8 | 2.2 | Linux | Linux | — | perf/core: Detach event groups during remove_on_exec |
| CVE-2026-64558 | 7.8 | 2.1 | Linux | Linux | — | s390/pkey: Check length in pkey_pckmo handler implementation |
| CVE-2026-64559 | 7.8 | 2.1 | Linux | Linux | — | s390/pkey: Check length in PKEY_VERIFYPROTK ioctl |
| CVE-2026-64560 | 7.8 | 2.2 | Linux | Linux | — | posix-cpu-timers: Prevent UAF caused by non-leader exec() race |
| CVE-2026-14354 | 8.7 | 1.9 | Schneider Electric | EcoStruxure™ Cybersecurity Admin Expert | CWE-522 | CWE-522 Insufficiently Protected Credentials vulnerability exists that could … |
| CVE-2026-63237 | 4.8 | 1.9 | Three Learning | Koollab LMS | CWE-347 | TOTP two-factor authentication bypass vulnerability |
| CVE-2026-40272 | 7.0 | 1.6 | BlackBerry Ltd | QNX Software Development Platform | CWE-1284 | Vulnerability in the QNX libtraceparser Impacts QNX Software Development Plat… |
| CVE-2026-59919 | 5.5 | 1.6 | netty | netty | CWE-93 | Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address |
| CVE-2026-62995 | 2.3 | 1.3 | authlib | joserfc | CWE-345 | joserfc accepts JWT with padding, leading to JWT malleability |
| CVE-2026-52791 | 2.0 | 1.1 | containers | fuse-overlayfs | CWE-266 | fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC) |
| CVE-2026-18257 | 5.6 | 1.0 | Systerel | S2OPC | CWE-295 | Improper Certificate Validation in S2OPC |
| CVE-2026-10684 | 3.0 | 1.0 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in coredump shell when printing stored-dump target code |
| CVE-2026-14234 | 7.1 | 1.0 | Unknown | WOLF | CWE-79 | WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF |
| CVE-2026-2482 | 8.8 | 0.9 | IBM | WebSphere Application Server - Liberty | CWE-352 | IBM WebSphere Application Server Liberty is affected by a cross-site request … |
| CVE-2026-44944 | 8.5 | 0.6 | open-iscsi | open-iscsi | CWE-863 | iscsiuio control-socket authentication bypass in open-iscsi |
| CVE-2026-6102 | 7.8 | 0.4 | MSI | MSI Center | CWE-346 | MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vul… |
| CVE-2026-8497 | 7.4 | 0.3 | Devolutions | Password Manager | CWE-295 | Improper certificate validation in the Devolutions Server connection handling… |
| CVE-2026-67433 | 5.8 | 0.2 | Linuxfabrik | monitoring-plugins | CWE-59 | Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database … |