| CVE-2026-39932 | 9.4 | 52.7 | openemr | openemr | CWE-95 | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection |
| CVE-2026-66326 | 8.8 | 52.6 | Microsoft | Microsoft Edge (Chromium-based) | CWE-862 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-12872 | 9.8 | 49.8 | Unknown | Webinfos | CWE-434 | Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload |
| CVE-2026-8793 | 6.9 | 49.5 | PaperCut | PaperCut NG/MF | CWE-307 | PaperCut NG/MF: Insufficient brute-force protection |
| CVE-2026-48330 | 10.0 | 49.4 | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-8794 | 6.9 | 49.3 | PaperCut | PaperCut NG/MF | CWE-208 | PaperCut NG/MF: User enumeration via timing attack |
| CVE-2026-41452 | 9.3 | 48.6 | krayin | laravel-crm | CWE-306 | Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup |
| CVE-2026-61523 | 8.6 | 47.9 | WebsiteBaker Org e.V. | WebsiteBaker CMS | CWE-94 | WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor |
| CVE-2026-48323 | 10.0 | 47.1 | Adobe | Adobe Campaign Classic | CWE-1336 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Us… |
| CVE-2026-69095 | 8.7 | 46.8 | openwrt | luci | CWE-22 | OpenWrt luci-app-bmx7 Path Traversal via bmx7-info |
| CVE-2026-18588 | 9.3 | 46.3 | Wavlink | WL-NU516U1 | CWE-119 | Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow |
| CVE-2026-18589 | 8.9 | 46.3 | Wavlink | WL-NU516U1 | CWE-119 | Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow |
| CVE-2026-66315 | 7.5 | 46.2 | Microsoft | Microsoft Edge (Chromium-based) | CWE-416 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-66314 | 5.3 | 44.7 | Microsoft | Microsoft Edge (Chromium-based) | CWE-367 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-61372 | 7.5 | 44.4 | Apache Software Foundation | Apache Jena Fuseki | CWE-22 | Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrict… |
| CVE-2026-61524 | 8.6 | 43.7 | WebsiteBaker Org e.V. | WebsiteBaker CMS | CWE-434 | WebsiteBaker CMS < 2.13.10 File Upload RCE via Module Installation |
| CVE-2026-18613 | 8.9 | 43.3 | GL-iNet | GL-MT3000 | CWE-74 | GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection |
| CVE-2026-18646 | 5.5 | 42.9 | danpros | HTMLy | CWE-22 | danpros HTMLy Author Name htmly.php path traversal |
| CVE-2026-33591 | 10.0 | 42.0 | Tranquil IT Systems | WAPT Server | CWE-288 | Authentication bypass on WaptServer |
| CVE-2026-68979 | 5.9 | 41.9 | Apache Software Foundation | Apache NiFi | CWE-862 | Apache NiFi: Missing Authorization for Components Referenced by Parameter Con… |
| CVE-2026-68981 | 8.8 | 41.6 | Apache Software Foundation | Apache NiFi | CWE-409 | Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP … |
| CVE-2026-16250 | 9.8 | 40.9 | Unknown | Personal QR Message | CWE-434 | Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload |
| CVE-2026-20479 | 7.5 | 40.4 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In Modem, there is a possible out of bounds read due to a missing bounds chec… |
| CVE-2026-18582 | 5.5 | 40.4 | mz-automation | libiec61850 | CWE-590 | mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteA… |
| CVE-2026-18583 | 5.5 | 40.4 | mz-automation | libiec61850 | CWE-119 | mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of… |
| CVE-2026-48326 | 9.9 | 39.7 | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-48317 | 9.6 | 39.7 | Adobe | Adobe Campaign Classic | CWE-95 | Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynam… |
| CVE-2026-48331 | 10.0 | 38.9 | Adobe | Adobe Campaign Classic | CWE-918 | Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-48333 | 9.8 | 38.9 | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2025-15672 | 8.1 | 38.6 | Unknown | ChamaWP | CWE-502 | Chama < 1.0.13 - Unauthenticated PHP Object Injection |
| CVE-2026-16060 | 9.8 | 38.6 | Unknown | Insert or Embed Articulate Content into WordPress | CWE-434 | Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ A… |
| CVE-2026-48399 | 7.5 | 38.3 | Adobe | Adobe Campaign Classic | CWE-657 | Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657) |
| CVE-2026-38447 | 9.8 | 37.7 | n/a | n/a | CWE-331 | osTicket 1.18.3 generates API keys using a predictable construction based on … |
| CVE-2026-18607 | 7.4 | 36.5 | Wavlink | WN572 | CWE-119 | Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow |
| CVE-2026-64827 | 9.3 | 36.3 | Telenia Software | TVox | CWE-807 | Telenia TVox 26.5.3 Authentication Bypass via set_env.php |
| CVE-2026-63563 | 6.9 | 35.9 | Sharp Corporation | Sharp MFPs | CWE-1188 | Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have… |
| CVE-2026-18645 | 2.1 | 35.6 | danpros | HTMLy | CWE-22 | danpros HTMLy Admin Content Endpoint admin.php add_content path traversal |
| CVE-2026-65804 | 6.1 | 34.5 | Microsoft | Microsoft Edge (Chromium-based) | CWE-94 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-69152 | 7.5 | 34.2 | juliangruber | brace-expansion | CWE-400 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202… |
| CVE-2026-66311 | 6.2 | 33.7 | Microsoft | Microsoft Edge (Chromium-based) | CWE-862 | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2026-21548 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | T8100/T9100/T8200/T8300 | CWE-20 | In nr modem, there is a possible improper input validation. This could lead t… |
| CVE-2026-21549 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | T8100/T9100/T8200/T8300 | CWE-20 | In modem, there is a possible improper input validation. This could lead to r… |
| CVE-2026-21550 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | T8100/T9100/T8200/T8300 | CWE-20 | In modem, there is a possible improper input validation. This could lead to r… |
| CVE-2026-21551 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | T8100/T9100/T8200/T8300 | CWE-20 | In modem, there is a possible improper input validation. This could lead to r… |
| CVE-2026-21552 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | T8100/T9100/T8200/T8300 | CWE-20 | In modem, there is a possible improper input validation. This could lead to r… |
| CVE-2026-21553 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | T8100/T9100/T8200/T8300 | CWE-20 | In modem, there is a possible improper input validation. This could lead to r… |
| CVE-2026-21554 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | UDX710 | CWE-20 | In modem, there is a possible improper input validation. This could lead to r… |
| CVE-2026-21555 | 7.5 | 33.6 | Unisoc (Shanghai) Technologies Co., Ltd. | UDX710 | CWE-20 | In modem, there is a possible improper input validation. This could lead to r… |
| CVE-2026-18610 | 5.5 | 32.8 | NewType | WebEIP | CWE-287 | NewType WebEIP EIP_Com_FileList.aspx improper authentication |
| CVE-2026-69079 | 8.7 | 32.8 | misp | cti-transmute | CWE-770 | Unauthenticated Denial of Service via Unbounded Activity-Timeline Range in CT… |
| CVE-2026-18667 | 9.3 | 32.4 | Tenable, Inc. | Sensor Proxy | CWE-94 | Sensor Proxy Version 1.4.2 Fixes One Vulnerability |
| CVE-2026-66325 | 6.1 | 32.4 | Microsoft | Microsoft Edge (Chromium-based) | CWE-918 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-18738 | 5.1 | 31.3 | shlinkio | Shlink | CWE-1236 | Shlink CSV Formula Injection via Visit Export CLI |
| CVE-2026-18631 | 2.1 | 31.1 | jeequan | jeepay | CWE-285 | jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authoriza… |
| CVE-2026-18632 | 2.1 | 30.7 | langgenius | dify | CWE-791 | langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements… |
| CVE-2026-69089 | 8.7 | 30.4 | getgrav | grav | CWE-22 | Grav CMS before 2.0.11 Path Traversal via watermark |
| CVE-2026-18644 | 2.1 | 30.3 | danpros | HTMLy | CWE-22 | danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal |
| CVE-2026-58060 | 8.7 | 29.6 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-789 | HSS public-key level count unbounded, enabling huge allocation on verify |
| CVE-2026-66310 | 7.1 | 29.5 | Microsoft | Microsoft Edge for Android | CWE-73 | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2026-66318 | 8.1 | 29.1 | Microsoft | Microsoft Edge (Chromium-based) | CWE-346 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-69091 | 8.7 | 28.7 | Admidio | admidio | CWE-306 | Admidio before 5.0.11 Authentication Bypass via forum.php |
| CVE-2026-62416 | 6.9 | 28.7 | Sharp Corporation | Network Scanner Tool Lite | CWE-1188 | Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporat… |
| CVE-2026-14557 | 9.1 | 28.6 | Unknown | SoftMarket — Digital Marketplace | CWE-287 | SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification… |
| CVE-2026-18647 | 5.5 | 28.5 | jina-ai | reader | CWE-918 | jina-ai reader Crawler/Puppeteer crawler.ts isValidTLD server-side request fo… |
| CVE-2026-20464 | 6.5 | 28.3 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In hevc decoder, there is a possible out of bounds write due to an integer ov… |
| CVE-2025-15673 | 4.9 | 28.2 | Unknown | Import and export users and customers | CWE-22 | Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read |
| CVE-2026-69083 | 9.9 | 28.1 | siyuan-note | siyuan | CWE-89 | SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent |
| CVE-2026-41453 | 8.7 | 28.1 | krayin | laravel-crm | CWE-89 | Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Param… |
| CVE-2026-69086 | 8.3 | 28.1 | siyuan-note | siyuan | CWE-22 | SiYuan before v3.7.3 Path Traversal via unvalidated avID |
| CVE-2025-15627 | 6.9 | 27.9 | TP-Link Systems Inc. | Omada Gateways | CWE-321 | Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication |
| CVE-2026-69185 | 7.5 | 27.6 | socketio | socket.io | CWE-20 | Socket.IO: Zero-attachment Memory Exhaustion |
| CVE-2026-48031 | 9.1 | 27.5 | dhax | go-base | CWE-798 | Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery |
| CVE-2026-59652 | 6.9 | 27.1 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-90 | LDAP filter injection in legacy jdk1.4 LDAPStoreHelper |
| CVE-2026-8763 | 9.3 | 26.0 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-295 | Name Constraints bypass via trailing dot in rfc822Name and URI |
| CVE-2026-58059 | 8.7 | 25.8 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-407 | Quadratic-time escaping when stringifying X.500 distinguished names |
| CVE-2026-67611 | 8.6 | 25.8 | openemr | openemr | CWE-308 | OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configura… |
| CVE-2026-58063 | 5.3 | 25.8 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-770 | BCFKS keystore load honours unbounded KDF cost from untrusted file |
| CVE-2026-39931 | 8.6 | 25.5 | openemr | openemr | CWE-434 | OpenEMR Authenticated SQL Injection via backup.php Import Feature |
| CVE-2026-67610 | 8.6 | 25.4 | openemr | openemr | CWE-306 | OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access |
| CVE-2026-12965 | 9.1 | 25.2 | Unknown | Super Store Finder WordPress | CWE-89 | Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking |
| CVE-2026-18733 | 7.5 | 25.0 | AWS | strands-agents-tools | CWE-1427 | Prompt injection bypasses shell tool consent gate in Strands Agents Tools |
| CVE-2026-69240 | 9.8 | 24.8 | sequelize | sequelize | CWE-89 | Sequelize: SQL Injection (Oracle DB) |
| CVE-2026-68980 | 2.3 | 24.6 | Apache Software Foundation | Apache NiFi | CWE-863 | Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion |
| CVE-2026-69153 | 6.3 | 24.0 | postcss | postcss | CWE-22 | PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMapping… |
| CVE-2026-68584 | 9.2 | 23.8 | siyuan-note | siyuan | CWE-288 | SiYuan before v3.7.3 Authentication Bypass via Content Endpoints |
| CVE-2026-62354 | 7.7 | 23.8 | Apache Software Foundation | Apache NiFi | CWE-863 | Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests |
| CVE-2026-38444 | 6.1 | 23.1 | n/a | n/a | CWE-79 | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the e… |
| CVE-2026-16300 | 9.8 | 22.9 | Unknown | ChamaWP | CWE-862 | Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset |
| CVE-2026-69078 | 8.8 | 22.7 | misp | cti-transmute | CWE-918 | Server-Side Request Forgery and Local File Disclosure in CTI-Transmute Evalua… |
| CVE-2026-67974 | 7.5 | 22.6 | n/a | n/a | CWE-20 | A parser boundary flaw in the Software Bus Network (SBN) application's peer s… |
| CVE-2026-69244 | 7.1 | 22.5 | aio-libs | aiohttp | CWE-125 | AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malfor… |
| CVE-2026-18585 | 5.3 | 22.5 | GL.iNet | MT3000 | CWE-119 | GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow |
| CVE-2026-66065 | 8.4 | 22.2 | Q00 | ouroboros | CWE-15 | Ouroboros: Untrusted project .env can still reach RCE via omitted execution-r… |
| CVE-2026-13586 | 5.3 | 21.9 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-770 | PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) |
| CVE-2026-69192 | 7.7 | 21.7 | beaugunderson | ip-address | CWE-20 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d… |
| CVE-2026-58139 | 6.0 | 21.7 | duckdb | duckdb-aws | CWE-863 | DuckDB AWS Extension Security Policy Bypass via load_aws_credentials Procedure |
| CVE-2026-59646 | 8.7 | 21.6 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-789 | DTLS handshake reassembler allocates buffer from unchecked 24-bit length |
| CVE-2026-69075 | 6.9 | 21.5 | flowintel | flowintel | CWE-79 | Stored Cross-Site Scripting via Vue Template Injection in FlowIntel |
| CVE-2026-69084 | 9.9 | 21.5 | siyuan-note | siyuan | CWE-89 | SiYuan before v3.7.3 SQL Injection via searchEmbedBlock |
| CVE-2026-18654 | 6.9 | 21.5 | AWS | aws-cli | CWE-322 | Disabled SSH host key verification in Amazon AWS CLI EMR helper commands |
| CVE-2026-2346 | 9.8 | 21.0 | Menulux Software Inc. | Mobile App | CWE-639 | IDOR in Menulux Software's Mobile App |
| CVE-2026-9390 | 9.1 | 20.7 | TIMLEGGE | XML::Sig | CWE-643 | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup |
| CVE-2026-16572 | 8.6 | 20.6 | Unknown | LogMyTrip | CWE-89 | LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie |
| CVE-2026-48061 | 5.9 | 20.7 | litestar-org | litestar | CWE-644 | Litestar: AllowedHostsMiddleware bypasses host validation via client-controll… |
| CVE-2026-10849 | 7.5 | 20.5 | zephyrproject | zephyr | CWE-122 | Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server… |
| CVE-2026-67973 | 7.5 | 20.3 | n/a | n/a | CWE-400 | An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to caus… |
| CVE-2026-67976 | 7.5 | 20.3 | n/a | n/a | CWE-400 | The Ref::SignalGen component of fprime framework v4.2.2 does not validate the… |
| CVE-2026-67977 | 7.5 | 20.3 | n/a | n/a | CWE-400 | An integer overflow in the Svc::FileDownlink::SendPartial component of fprime… |
| CVE-2026-59638 | 9.3 | 20.1 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-297 | JSSE hostname verifier CN-fallback enabled by default despite documented opt-in |
| CVE-2026-69198 | 6.9 | 20.1 | beaugunderson | ip-address | CWE-20 | ip-address: a CIDR suffix on the parsed address suppresses special-use classi… |
| CVE-2026-69243 | 6.3 | 19.9 | aio-libs | aiohttp | CWE-444 | AIOHTTP: HTTP request smuggling via WebSocket upgrade |
| CVE-2026-18593 | 2.9 | 18.6 | vxcontrol | PentAGI | CWE-264 | vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox |
| CVE-2026-59650 | 9.3 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-20 | MTI/A0 DH agreement exponentiates unvalidated peer value |
| CVE-2026-12852 | 8.7 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-789 | MLS wire decoder allocates attacker-declared opaque length before bounds check |
| CVE-2026-13506 | 8.7 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-674 | Lazy ASN.1 sequence forcing resets nesting-depth guard |
| CVE-2026-14682 | 8.7 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-789 | Possible OOM from unbounded up-front allocation on a definite-length read |
| CVE-2026-59640 | 8.7 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-203 | OpenPGP CFB quick-check oracle active on symmetric/session-key paths |
| CVE-2026-59644 | 8.7 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-834 | MLS hash-ratchet honours arbitrary 32-bit generation counter from sender |
| CVE-2026-59645 | 8.7 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-674 | OER parser recurses without depth limit on self-referential IEEE 1609.2 schema |
| CVE-2026-59649 | 8.7 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-789 | OpenPGP user-attribute subpacket length bounded only by JVM max memory |
| CVE-2026-67978 | 7.5 | 18.2 | n/a | n/a | CWE-20 | An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to caus… |
| CVE-2026-12185 | 7.1 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-789 | BKS/UBER keystore allocates from untrusted lengths before integrity check |
| CVE-2026-59647 | 6.9 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-770 | CRMF/CMP password-MAC honours unbounded iteration count |
| CVE-2026-59648 | 6.9 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-770 | OpenPGP Argon2 S2K honours attacker-chosen memory and passes |
| CVE-2026-15055 | 5.3 | 18.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-770 | PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input |
| CVE-2026-46714 | 5.1 | 18.2 | misskey-dev | misskey | CWE-674 | Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation |
| CVE-2026-16532 | 9.1 | 18.1 | Unknown | Link Library | CWE-89 | Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link S… |
| CVE-2026-51775 | 9.8 | 17.9 | n/a | n/a | CWE-89 | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker … |
| CVE-2026-67972 | 7.5 | 17.7 | n/a | n/a | CWE-200 | An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attacker… |
| CVE-2026-67616 | 5.3 | 17.0 | owen2345 | camaleon-cms | CWE-862 | Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint |
| CVE-2026-18655 | 7.1 | 16.9 | AWS | amazon-mq-mcp-server | CWE-923 | Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server… |
| CVE-2026-69085 | 9.9 | 16.7 | siyuan-note | siyuan | CWE-89 | SiYuan before v3.7.3 SQL Injection via searchDocs |
| CVE-2026-48115 | 6.3 | 16.5 | misskey-dev | misskey | CWE-285 | Misskey: Improper Authorization in the Announcements API |
| CVE-2026-38446 | 6.1 | 16.3 | n/a | n/a | CWE-79 | A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 d… |
| CVE-2026-18682 | 1.3 | 16.2 | n/a | OpenAkita | CWE-79 | OpenAkita File Upload API upload cross site scripting |
| CVE-2026-68587 | 9.2 | 16.0 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction |
| CVE-2026-18736 | 5.3 | 15.7 | shlinkio | Shlink | CWE-918 | Shlink Server-Side Request Forgery via Short URL Title Auto-Resolution |
| CVE-2026-68586 | 9.2 | 15.5 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc |
| CVE-2026-18737 | 7.1 | 15.4 | shlinkio | Shlink | CWE-89 | Shlink Blind SQL Injection via tags/stats orderBy Parameter |
| CVE-2026-69088 | 8.6 | 14.5 | getgrav | grav | CWE-94 | Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint |
| CVE-2026-66313 | 6.8 | 14.5 | Microsoft | Microsoft Edge (Chromium-based) | CWE-346 | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2026-15930 | 9.4 | 14.4 | Unknown | Simple Membership | CWE-862 | Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover vi… |
| CVE-2026-16534 | 9.1 | 14.3 | Unknown | Import and export users and customers | CWE-269 | Import and export users and customers < 2.4.2 - Custom Role Privilege Escalat… |
| CVE-2026-67970 | 7.5 | 14.3 | n/a | n/a | CWE-284 | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.… |
| CVE-2026-16057 | 6.5 | 14.4 | Unknown | Contest Gallery | CWE-862 | Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtub… |
| CVE-2026-60011 | 6.9 | 14.2 | Sharp Corporation | Sharp MFPs | CWE-425 | Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authoriz… |
| CVE-2026-52521 | 8.1 | 14.0 | n/a | n/a | CWE-89 | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attacke… |
| CVE-2026-18584 | 5.3 | 14.1 | GL.iNet | E5800 | CWE-266 | GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authoriz… |
| CVE-2026-16297 | 4.1 | 14.1 | Unknown | Clearfy Cache | CWE-502 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import |
| CVE-2026-48113 | 8.5 | 13.8 | jpillora | chisel | CWE-863 | Chisel: ACL Bypass via Post-Handshake SSH Channel ExtraData Injection |
| CVE-2026-66322 | 5.4 | 13.5 | Microsoft | Microsoft Edge (Chromium-based) | CWE-346 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-69092 | 6.9 | 13.3 | Admidio | admidio | CWE-79 | Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpoint |
| CVE-2025-15628 | 8.2 | 13.0 | TP-Link Systems Inc. | Omada Gateways | CWE-798 | Hardcoded Certificates in TP-Link Omada Device Communications |
| CVE-2026-16539 | 8.1 | 12.9 | Unknown | sm page duplicator | CWE-89 | SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication |
| CVE-2026-67969 | 7.5 | 12.9 | n/a | n/a | CWE-20 | An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows … |
| CVE-2026-18108 | 9.8 | 12.8 | TIMLEGGE | Net::SAML2 | CWE-347 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because … |
| CVE-2026-18248 | 9.1 | 12.5 | @fastify/aws-lambda | @fastify/aws-lambda | CWE-345 | @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled… |
| CVE-2026-15231 | 2.7 | 12.5 | Unknown | Tag, Category, and Taxonomy Manager | CWE-639 | TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR |
| CVE-2026-46712 | 2.3 | 12.2 | misskey-dev | misskey | CWE-639 | Misskey: Lack of proper permission checks in Direct Messaging feature |
| CVE-2026-69246 | 7.2 | 11.9 | guzzle | guzzle | CWE-180 | Guzzle: Noncanonical host can bypass host-based checks |
| CVE-2026-69087 | 7.1 | 11.9 | getgrav | grav-plugin-form | CWE-601 | Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twig |
| CVE-2026-68930 | 6.5 | 11.9 | Eugeny | russh | CWE-666 | Russh: Channel-scoped server callbacks can be reached without an open channel |
| CVE-2026-69082 | 8.8 | 11.7 | misp | cti-transmute | CWE-352 | Cross-Site Request Forgery in the Administrative User Deletion Endpoint |
| CVE-2026-58061 | 8.7 | 11.8 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-354 | CCM-family modes write plaintext to caller buffer before tag check |
| CVE-2026-66316 | 5.4 | 11.7 | Microsoft | Microsoft Edge (Chromium-based) | CWE-346 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-66317 | 5.4 | 11.7 | Microsoft | Microsoft Edge (Chromium-based) | CWE-346 | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2026-67975 | 7.5 | 11.4 | n/a | n/a | CWE-284 | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily r… |
| CVE-2026-66296 | 5.1 | 11.2 | lud | oaskit | CWE-79 | Reflected XSS in oaskit's default HTML error handler |
| CVE-2026-18718 | 7.1 | 10.9 | National Security Agency | Ghidra | CWE-427 | Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State |
| CVE-2026-58062 | 9.3 | 10.5 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-295 | Stapled OCSP response accepted without binding to the checked certificate |
| CVE-2026-20465 | 8.1 | 10.6 | MediaTek, Inc. | MediaTek chipset | CWE-122 | In wlan AP driver, there is a possible out of bounds write due to a missing b… |
| CVE-2026-18592 | 2.0 | 10.4 | n/a | osCommerce | CWE-74 | osCommerce Email Template Configuration EmailController.php EmailController s… |
| CVE-2025-15544 | 6.9 | 10.3 | TP-Link Systems Inc. | Omada Gateways | CWE-759 | Weak Credential Protection During TP-Link Omada Device Adoption |
| CVE-2026-69090 | 6.9 | 10.3 | Admidio | admidio | CWE-862 | Admidio before 5.0.11 Cross-Organization Role Modification |
| CVE-2026-15254 | 6.5 | 10.3 | Unknown | Simply Schedule Appointments | CWE-863 | Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclo… |
| CVE-2026-16563 | 6.5 | 10.3 | Unknown | Academy LMS | CWE-284 | Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via les… |
| CVE-2026-69151 | 7.6 | 10.0 | angular | angular | CWE-79 | Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes |
| CVE-2025-15630 | 5.8 | 10.1 | TP-Link Systems Inc. | Omada Gateways | CWE-362 | Device Provisioning Race Condition in TP-Link Omada Adoption Workflow |
| CVE-2026-18092 | 8.1 | 9.6 | TIMLEGGE | Net::SAML2 | CWE-347 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via… |
| CVE-2026-69149 | 8.6 | 9.5 | angular | angular | CWE-79 | Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cro… |
| CVE-2026-68585 | 6.9 | 9.5 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo |
| CVE-2026-69249 | 8.7 | 9.2 | pyca | cryptography | CWE-400 | python-cryptography: Duplicate self-signed intermediates can cause exponentia… |
| CVE-2026-18568 | 7.5 | 9.0 | TIMLEGGE | XML::Sig | CWE-347 | XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification… |
| CVE-2026-69097 | 7.3 | 8.6 | gitpython-developers | GitPython | CWE-74 | GitPython before 3.1.53 Config Injection via Submodule Names |
| CVE-2026-69248 | 6.9 | 8.4 | pyca | cryptography | CWE-295 | python-cryptography verifier accepts wildcard DNS names allowing escape from … |
| CVE-2026-47746 | 8.9 | 8.1 | misskey-dev | misskey | CWE-367 | Misskey: JSON-LD signature validation + compaction is vulnerable to timing at… |
| CVE-2026-18243 | 6.9 | 8.1 | HP Inc | HP DesignJet T3500 | CWE-79 | HP DesignJet T3500 - Potential Cross-Site Scripting (XSS) |
| CVE-2026-20482 | 6.5 | 8.0 | MediaTek, Inc. | MediaTek chipset | CWE-770 | In wlan STA FW, there is a possible system becoming unresponsive due to loggi… |
| CVE-2025-15629 | 6.9 | 7.9 | TP-Link Systems Inc. | Omada Gateways | CWE-331 | Weak Session Key Generation in TP-Link Omada Adoption Protocol |
| CVE-2026-13340 | 6.1 | 8.0 | Unknown | SVG Support | CWE-79 | SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass |
| CVE-2026-16274 | 2.7 | 7.7 | Unknown | Classified Listing | CWE-862 | Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure… |
| CVE-2026-16276 | 2.7 | 7.7 | Unknown | Classified Listing | CWE-862 | Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via … |
| CVE-2025-15631 | 5.7 | 7.5 | TP-Link Systems Inc. | Omada Gateways | CWE-759 | Weak Credential Storage in TP-Link Omada Devices |
| CVE-2026-69247 | 8.2 | 7.3 | pyca | cryptography | CWE-208 | cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle… |
| CVE-2026-18089 | 7.5 | 7.3 | TIMLEGGE | Net::SAML2 | CWE-295 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by … |
| CVE-2026-46713 | 9.2 | 7.2 | misskey-dev | misskey | CWE-347 | Misskey: JSON-LD signature validation + compaction may lead to improper activ… |
| CVE-2026-12803 | 8.7 | 7.1 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-354 | KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD … |
| CVE-2026-12860 | 8.7 | 7.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-347 | RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path |
| CVE-2026-59639 | 8.7 | 7.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-347 | CMS verifySignatures returns true for SignedData with zero signers |
| CVE-2026-59641 | 8.7 | 7.1 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-345 | S/MIME validator trusts signer-asserted signingTime for path validation |
| CVE-2026-59643 | 8.7 | 7.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-347 | OpenPGP inline-signature policy failures silently ignored |
| CVE-2026-59651 | 7.1 | 7.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-326 | BKS keystore accepts legacy version with 16-bit integrity MAC key |
| CVE-2026-47211 | 8.4 | 7.1 | Q00 | ouroboros | CWE-426 | Ouroboros: Remote Code Execution via Untrusted Project-Directory .env |
| CVE-2026-12802 | 8.7 | 6.9 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-354 | CMS AuthEnvelopedData fails to enforce tag-length on decryption |
| CVE-2026-28147 | 5.4 | 6.7 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-862 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-18648 | 1.9 | 6.8 | Blix | Email Blue Mail Calendar App | CWE-22 | Blix Email Blue Mail Calendar App react-native-receive-sharing-intent FileDir… |
| CVE-2026-9487 | 9.1 | 6.4 | TIMLEGGE | XML::Sig | CWE-347 | XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID |
| CVE-2026-18651 | 5.4 | 6.4 | Red Hat | Red Hat Directory Server 11 | CWE-287 | 389-ds-base: 389-ds-base: sasl plain bind installs connection credentials bef… |
| CVE-2026-20466 | 6.1 | 6.3 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In sec boot, there is a possible escalation of privilege due to a heap buffer… |
| CVE-2026-52520 | 5.4 | 6.1 | n/a | n/a | CWE-79 | Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerabilit… |
| CVE-2026-49131 | 5.1 | 6.2 | Deciso B.V. | OPNsense | CWE-79 | OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field |
| CVE-2026-20471 | 4.6 | 6.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In DA, there is a possible out of bounds write due to a missing bounds check.… |
| CVE-2026-56608 | 5.3 | 6.0 | HCL Software | HCL iControl | CWE-284 | HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 … |
| CVE-2026-67598 | 9.1 | 5.9 | emlog | emlog | CWE-295 | Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php |
| CVE-2026-15383 | 6.1 | 5.9 | Unknown | Blog Floating Button | CWE-79 | Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent He… |
| CVE-2026-15931 | 6.1 | 5.9 | Unknown | Simple Membership | CWE-79 | Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscriptio… |
| CVE-2026-16289 | 4.3 | 5.8 | Unknown | ProfileGrid | CWE-862 | ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_… |
| CVE-2026-67617 | 4.8 | 5.7 | microweber | microweber | CWE-79 | Microweber CMS 2.0.20 Stored XSS via tag_names Parameter |
| CVE-2026-69094 | 5.3 | 5.5 | Admidio | admidio | CWE-639 | Admidio before 5.0.11 IDOR via save_temporary mylist_function.php |
| CVE-2026-48063 | 9.3 | 5.3 | WhiskeySockets | Baileys | CWE-290 | Baileys has message upsert / hist sync spoofing and app state corruption when… |
| CVE-2026-12816 | 8.7 | 5.3 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-354 | IESEngine stream-mode MAC forgery via length-dependent KDF split |
| CVE-2026-12817 | 8.7 | 5.3 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-354 | OpenPGP AEAD decryption skips final tag on chunk-aligned data |
| CVE-2026-59642 | 8.7 | 5.3 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-354 | CMS AuthenticatedData content not bound to MAC when authAttrs present |
| CVE-2026-6695 | 5.5 | 4.8 | Red Hat | Red Hat Enterprise Linux 6 | CWE-805 | Gimp: gimp: remote code execution via crafted paa file |
| CVE-2026-65875 | 5.1 | 4.9 | baserCMS Users Community | BaserCMS | CWE-1236 | BaserCMS provided by baserCMS Users Community contains a CSV file injection v… |
| CVE-2026-67673 | 4.6 | 4.9 | n/a | n/a | CWE-121 | A stack-based buffer overflow vulnerability exists in the cmd_edl function of… |
| CVE-2026-15260 | 4.3 | 4.9 | Unknown | GEO my WP | CWE-639 | Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification a… |
| CVE-2026-16564 | 4.3 | 4.9 | Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | CWE-639 | Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-a… |
| CVE-2026-16565 | 4.3 | 4.9 | Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | CWE-639 | Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Produ… |
| CVE-2026-63545 | 2.4 | 4.8 | Sharp Corporation | Sharp MFPs | CWE-459 | Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally wh… |
| CVE-2026-6694 | 5.5 | 4.6 | Red Hat | Red Hat Enterprise Linux 6 | CWE-120 | Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk |
| CVE-2026-67612 | 4.8 | 4.5 | openemr | openemr | CWE-79 | OpenEMR 8.2.0 Stored XSS via import_template.php Template Management |
| CVE-2026-67609 | 8.5 | 3.9 | Telenia Software | TVox | CWE-250 | Telenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration |
| CVE-2026-69245 | 6.5 | 3.6 | guzzle | guzzle | CWE-180 | Guzzle: Noncanonical cookie domain keeps subdomain scope |
| CVE-2026-18508 | 4.4 | 3.6 | Red Hat | Red Hat Hardened Images | CWE-59 | Tar: tar: --one-top-level hardlink targets not confined to top-level director… |
| CVE-2026-68742 | 5.5 | 3.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethost… |
| CVE-2026-18642 | 7.8 | 3.4 | TUBITAK BILGEM Software Technologies Research Institute | eta-otp-lock | CWE-502 | Remote Code Execution via Insecure Deserialization in TÜBİTAK BİLGEM's eta-ot… |
| CVE-2026-4793 | 7.3 | 3.3 | Synology | Synology Assistant | CWE-276 | An incorrect default permissions vulnerability in Synology Assistant before 7… |
| CVE-2025-9291 | 7.7 | 3.1 | TP-Link Systems Inc. | Omada Gateways | CWE-295 | Improper Certificate Validation in TP-Link Omada Cloud Communications |
| CVE-2026-20470 | 6.2 | 3.1 | MediaTek, Inc. | MediaTek chipset | CWE-926 | In Telephony, there is a possible information disclosure due to a missing per… |
| CVE-2026-20483 | 7.7 | 2.7 | MediaTek, Inc. | MediaTek chipset | CWE-862 | In Telephony, there is a possible escalation of privilege due to a missing pe… |
| CVE-2026-20488 | 4.4 | 2.5 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In display, there is a possible information disclosure due to a missing bound… |
| CVE-2026-20489 | 4.4 | 2.5 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In display, there is a possible information disclosure due to an integer over… |
| CVE-2026-20467 | 6.0 | 2.3 | MediaTek, Inc. | MediaTek chipset | CWE-749 | In apusys, there is a possible escalation of privilege due to a missing bound… |
| CVE-2026-20473 | 6.0 | 2.3 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In display, there is a possible memory corruption due to use after free. This… |
| CVE-2026-20475 | 6.0 | 2.3 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In display, there is a possible out of bounds write due to a missing bounds c… |
| CVE-2026-20477 | 6.0 | 2.3 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In display, there is a possible out of bounds write due to a missing bounds c… |
| CVE-2026-68945 | 8.8 | 2.1 | angular | angular | CWE-345 | Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Re… |
| CVE-2026-20484 | 4.4 | 2.0 | MediaTek, Inc. | MediaTek chipset | CWE-201 | In TFA, there is a possible information disclosure due to a missing permissio… |
| CVE-2026-18605 | 6.4 | 1.9 | CheckMAL | AppCheck Pro | CWE-426 | CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled se… |
| CVE-2026-9593 | 8.4 | 1.8 | Endress+Hauser | FDI Package library | CWE-427 | iDTM FDI Unauthorized Debug Interface Enablement |
| CVE-2026-40717 | 7.8 | 1.8 | Dell | Monitor driver | CWE-59 | Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Be… |
| CVE-2026-20468 | 6.0 | 1.8 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In apusys, there is a possible escalation of privilege due to a confused depu… |
| CVE-2026-20469 | 6.0 | 1.8 | MediaTek, Inc. | MediaTek chipset | CWE-123 | In trusted_mem, there is a possible escalation of privilege due to improper i… |
| CVE-2026-41447 | 8.5 | 1.7 | Zucchetti S.p.a. | FirmaCheck | CWE-426 | FirmaCheck < 1.3.16 DLL Hijacking via Unvalidated OpenSSL Configuration Path |
| CVE-2026-20486 | 6.7 | 1.7 | MediaTek, Inc. | MediaTek chipset | CWE-754 | In imgsensor, there is a possible application crash due to incorrect error ha… |
| CVE-2026-20481 | 6.0 | 1.6 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In geniezone, there is a possible out of bounds write due to a missing bounds… |
| CVE-2026-20497 | 6.0 | 1.6 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In geniezone, there is a possible out of bounds write due to a missing bounds… |
| CVE-2026-20498 | 6.0 | 1.7 | MediaTek, Inc. | MediaTek chipset | CWE-1287 | In geniezone, there is a possible escalation of privilege due to a missing pe… |
| CVE-2026-59913 | 7.8 | 1.6 | Dell | Display and Peripheral Manager (DDPM Mac) | CWE-306 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005,… |
| CVE-2026-20496 | 4.4 | 1.6 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In geniezone, there is a possible out of bounds read due to a missing bounds … |
| CVE-2026-18581 | 1.9 | 1.6 | ggml-org | llama.cpp | CWE-617 | ggml-org llama.cpp Jinja Minja Template parser.cpp assertion |
| CVE-2026-18606 | 7.1 | 1.5 | Razer | RzUpdateService | CWE-266 | Razer RzUpdateService Named Pipe RzUpdateService.exe privileges management |
| CVE-2026-69093 | 7.1 | 1.5 | Admidio | admidio | CWE-352 | Admidio before 5.0.11 CSRF via category-report preferences |
| CVE-2026-20476 | 5.5 | 1.5 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In ccci, there is a possible out of bounds read due to a missing bounds check… |
| CVE-2026-49132 | 5.1 | 1.5 | Deciso B.V. | OPNsense | CWE-79 | OPNsense < 26.1.9 Stored XSS via Certificate Description Field |
| CVE-2026-20495 | 7.8 | 1.4 | MediaTek, Inc. | MediaTek chipset | CWE-862 | In Bluetooth driver, there is a possible permission bypass due to a missing p… |
| CVE-2026-15430 | 6.2 | 1.3 | Wellbia | XIGNCODE3 | CWE-269 | CVE-2026-15430 |
| CVE-2026-20485 | 6.0 | 1.4 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In HFRP, there is a possible out of bounds write due to a missing bounds chec… |
| CVE-2026-20472 | 4.4 | 1.3 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In TFA, there is a possible out of bounds write due to a missing bounds check… |
| CVE-2026-20478 | 5.5 | 1.2 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In Audio HAL, there is a possible out of bounds write due to a heap buffer ov… |
| CVE-2026-20480 | 5.5 | 1.2 | MediaTek, Inc. | MediaTek chipset | CWE-122 | In Audio HAL, there is a possible out of bounds write due to a heap buffer ov… |
| CVE-2026-18477 | 4.4 | 1.2 | Red Hat | Red Hat Hardened Images | CWE-367 | Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore pa… |
| CVE-2026-18604 | 1.9 | 1.1 | textPlus | Text Message and Call App | CWE-926 | textPlus Text Message and Call App com.gogii.textplus DialerActivity improper… |
| CVE-2026-59912 | 7.8 | 1.1 | Dell | Display and Peripheral Manager (DDPM Mac) | CWE-284 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005,… |
| CVE-2026-20491 | 5.5 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In med, there is a possible out of bounds write due to an incorrect bounds ch… |
| CVE-2026-20494 | 5.5 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In wifi, there is a possible out of bounds read due to a missing bounds check… |
| CVE-2026-12259 | 5.3 | 1.0 | nltk | nltk/nltk | CWE-494 | Improper Input Validation in nltk/nltk |
| CVE-2026-20490 | 4.4 | 1.0 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In ccci, there is a possible out of bounds read due to a missing bounds check… |
| CVE-2026-20493 | 4.4 | 1.0 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In wifi, there is a possible out of bounds write due to a missing bounds chec… |
| CVE-2026-56609 | 6.5 | 0.9 | HCL Software | HCL iControl | CWE-327 | HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 … |
| CVE-2026-20474 | 6.0 | 0.7 | MediaTek, Inc. | MediaTek chipset | CWE-367 | In display, there is a possible escalation of privilege due to a race conditi… |
| CVE-2026-20492 | 5.5 | 0.3 | MediaTek, Inc. | MediaTek chipset | CWE-367 | In Audio HAL, there is a possible system becoming unresponsive due to a race … |
| CVE-2026-18591 | 0.9 | 0.2 | Meesho | Online Shopping App | CWE-310 | Meesho Online Shopping App com.meesho.supply cleartext storage |
| CVE-2026-0392 | 7.3 | 0.0 | Latvijas Valsts radio un televīzijas centrs (LVRTC) | eParakstītājs 3.0 | CWE-295 | eParakstītājs 3.0 for Windows – remote code execution via unauthenticated aut… |