| CVE-2026-54208 | 8.5 | 31.2 | Tobit Laboratories AG | TeamDavid | CWE-20 | TeamDavid: Arbitrary File Write leading to Stored XSS |
| CVE-2026-66914 | 9.2 | 31.0 | seblod.com | SEBLOD extension for Joomla | CWE-22 | Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.… |
| CVE-2026-50540 | 9.6 | 30.9 | kata-containers | kata-containers | CWE-20 | Kata Containers: Config Path Annotation Arbitrary File Loading |
| CVE-2026-66492 | 6.1 | 30.3 | phoca.cz | Phoca Commander extension for Joomla | CWE-22 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander… |
| CVE-2026-65819 | 7.5 | 29.7 | gopacket | gopacket | CWE-125 | gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/und… |
| CVE-2026-62992 | 6.9 | 29.5 | smarty-php | smarty | CWE-22 | Smarty: Symlink path traversal out of trusted directories |
| CVE-2026-46405 | 5.3 | 29.5 | openbao | openbao | CWE-770 | OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens |
| CVE-2026-46409 | 9.6 | 29.4 | openyak | openyak | CWE-94 | OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution |
| CVE-2026-20337 | 7.5 | 29.3 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
| CVE-2026-15215 | 8.8 | 28.4 | Unknown | Subscriptions for WooCommerce | CWE-269 | Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Instal… |
| CVE-2026-71557 | 6.3 | 28.0 | go-git | go-git | CWE-22 | go-git: Malicious reference names may modify files outside the reference storage |
| CVE-2026-62996 | 6.9 | 27.8 | smarty-php | smarty | CWE-22 | Smarty Security stream restriction bypass through stream: resource |
| CVE-2026-49007 | 7.5 | 27.5 | ZTE | F689 | CWE-798 | Information leakage vulnerability in ZTE F689 product |
| CVE-2026-48039 | 9.1 | 27.4 | pipeboard-co | meta-ads-mcp | CWE-287 | Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Acc… |
| CVE-2025-58375 | 8.1 | 27.2 | frappe | frappe | CWE-89 | Frappe has potential SQL Injection due to missing validation |
| CVE-2026-16263 | 8.8 | 26.5 | Unknown | WP Maps | CWE-22 | WP Maps < 4.9.7 - Subscriber+ Local File Inclusion |
| CVE-2026-48047 | 5.9 | 26.4 | xwiki | xwiki-platform | CWE-24 | XWiki Platform vulnerable to potential arbitrary file writing using path trav… |
| CVE-2026-12071 | 5.3 | 26.4 | Tobit Laboratories AG | TeamDavid | CWE-601 | TeamDavid: Header Injection leading to Open Redirect via URL-encoded characters |
| CVE-2026-54214 | 5.3 | 26.4 | Tobit Laboratories AG | TeamDavid | CWE-601 | TeamDavid: Header Injection through the 'cType' URL parameter |
| CVE-2026-19229 | 5.5 | 25.7 | SourceCodester | Online Clothing Store | CWE-200 | SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file i… |
| CVE-2026-19017 | 6.8 | 25.7 | HashiCorp | Consul | CWE-862 | Consul vulnerable to partial arbitrary file read via Vault Connect CA provider |
| CVE-2026-20338 | 7.5 | 25.6 | Cisco | Cisco Secure Endpoint | CWE-415 | ClamAV ZIP File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20339 | 7.5 | 25.6 | Cisco | Cisco Secure Endpoint | CWE-190 | ClamAV PESpin File Format Processing Integer Overflow Vulnerability |
| CVE-2026-20345 | 7.5 | 25.6 | Cisco | Cisco Secure Endpoint | CWE-121 | ClamAV GPT File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20346 | 7.5 | 25.6 | Cisco | Cisco Secure Endpoint | CWE-125 | ClamAV PDF File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20347 | 7.5 | 25.6 | Cisco | Cisco Secure Endpoint | CWE-125 | ClamAV Mach-O File Format Processing Memory Corruption Vulnerability |
| CVE-2026-20348 | 7.5 | 25.6 | Cisco | Cisco Secure Endpoint | CWE-120 | ClamAV XAR File Format Processing Memory Corruption Vulnerability |
| CVE-2026-54204 | 7.7 | 25.3 | Tobit Laboratories AG | TeamDavid | CWE-20 | TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in… |
| CVE-2026-54201 | 6.9 | 25.3 | Tobit Laboratories AG | TeamDavid | CWE-862 | TeamDavid: Missing Authorization |
| CVE-2026-54203 | 9.2 | 24.7 | Tobit Laboratories AG | TeamDavid | CWE-200 | TeamDavid: Memory Leak leaking sensitive information |
| CVE-2025-63235 | 7.5 | 24.5 | n/a | n/a | CWE-400 | In sol commit 373d848 (2024-12-12), the broker does not fully release resourc… |
| CVE-2026-71851 | 9.0 | 24.4 | brix | crypto-js | CWE-331 | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulner… |
| CVE-2026-56793 | 9.8 | 24.0 | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-287 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an… |
| CVE-2026-66491 | 8.2 | 24.0 | phoca.cz | Phoca Commander extension for Joomla | CWE-22 | Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 |
| CVE-2026-66493 | 6.4 | 24.0 | phoca.cz | Phoca Commander extension for Joomla | CWE-22 | Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander… |
| CVE-2026-14365 | 9.8 | 23.9 | themetechmount | TrueBooker – Appointment Booking and Scheduler System | CWE-862 | TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Pass… |
| CVE-2026-47660 | 8.7 | 23.7 | aehrc | pathling | CWE-522 | Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client creden… |
| CVE-2026-17593 | 7.2 | 23.4 | Sonatype | Nexus Repository | CWE-470 | Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration |
| CVE-2026-45808 | 7.1 | 23.5 | openbao | openbao | CWE-863 | OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasse… |
| CVE-2026-48094 | 5.3 | 23.1 | dartiss | shareopenly | CWE-79 | ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared UR… |
| CVE-2026-54202 | 8.5 | 22.9 | Tobit Laboratories AG | TeamDavid | CWE-36 | TeamDavid: Path Traversal in the archive creation functionality |
| CVE-2026-56794 | 6.5 | 22.8 | Dell | Dell OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-23 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a … |
| CVE-2026-52879 | 7.5 | 22.0 | klever-io | klever-go | CWE-400 | Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-d… |
| CVE-2026-52880 | 7.5 | 22.0 | klever-io | klever-go | CWE-400 | Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run |
| CVE-2026-17599 | 6.9 | 21.9 | Sonatype | Nexus Repository 3 | CWE-620 | Nexus Repository 3 - Unverified Onboarding State on change-admin-password End… |
| CVE-2026-17597 | 5.1 | 21.9 | Sonatype | Nexus Repository 3 | CWE-918 | Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Veri… |
| CVE-2026-19015 | 5.3 | 21.8 | HashiCorp | Consul | CWE-770 | Uncontrolled resource consumption in the Consul Connect CA roots endpoint |
| CVE-2026-19113 | 5.3 | 21.8 | HashiCorp | Consul | CWE-400 | Unauthenticated denial of service via unbounded request body processing |
| CVE-2026-19082 | 7.5 | 21.7 | TONYC | Imager | CWE-125 | Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap b… |
| CVE-2026-70561 | 7.1 | 21.7 | TestLinkOpenSourceTRMS | TestLink | CWE-639 | TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php |
| CVE-2026-71556 | 7.1 | 21.8 | go-git | go-git | CWE-59 | go-git: Worktree operations may follow symlinks |
| CVE-2026-69127 | 6.9 | 21.6 | getkirby | kirby | CWE-497 | Kirby: System path exposure from error messages in the REST API |
| CVE-2026-66062 | 5.3 | 21.7 | sveltejs | kit | CWE-1333 | SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via th… |
| CVE-2026-71848 | 5.3 | 21.6 | honojs | hono | CWE-407 | Hono: Algorithmic Complexity DoS in Language Middleware |
| CVE-2026-54209 | 8.9 | 21.2 | Tobit Laboratories AG | TeamDavid | CWE-125 | TeamDavid: Buffer Overflow in 'editini' function |
| CVE-2026-17595 | 5.3 | 21.2 | Sonatype | Nexus Repository 3 | CWE-497 | Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass |
| CVE-2026-14364 | 9.8 | 21.0 | themetechmount | TrueBooker – Appointment Booking and Scheduler System | CWE-640 | TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Pass… |
| CVE-2026-54216 | 5.3 | 20.8 | Tobit Laboratories AG | TeamDavid | CWE-79 | TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter |
| CVE-2026-54338 | 5.3 | 20.7 | jupyterhub | jupyterhub | CWE-400 | JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging … |
| CVE-2026-19210 | 2.1 | 20.7 | SourceCodester | Photo Share Website | CWE-284 | SourceCodester Photo Share Website ajax.php save_upload unrestricted upload |
| CVE-2026-54205 | 6.3 | 20.5 | Tobit Laboratories AG | TeamDavid | CWE-20 | TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in lin… |
| CVE-2026-54206 | 6.3 | 20.5 | Tobit Laboratories AG | TeamDavid | CWE-20 | TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sen… |
| CVE-2026-54207 | 6.3 | 20.5 | Tobit Laboratories AG | TeamDavid | CWE-20 | TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in mov… |
| CVE-2026-47249 | 7.5 | 20.3 | klever-io | klever-go | CWE-400 | Klever-Go KVM: Hash-array amplification in P2P resolver request handling |
| CVE-2026-52878 | 7.5 | 20.3 | klever-io | klever-go | CWE-476 | Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can … |
| CVE-2026-62295 | 7.5 | 20.3 | hapifhir | org.hl7.fhir.core | CWE-20 | HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denia… |
| CVE-2026-62296 | 7.5 | 20.3 | hapifhir | org.hl7.fhir.core | CWE-20 | HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow de… |
| CVE-2026-66059 | 5.3 | 19.9 | frappe | frappe | CWE-863 | Frappe: Field-level permission bypass via Document Follow |
| CVE-2026-48097 | 7.8 | 19.7 | 0x5t4l1n | NexTOR_IP_CHANGER | CWE-78 | NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution |
| CVE-2026-19208 | 2.9 | 19.7 | n/a | WonderTrader | CWE-840 | WonderTrader TraderDD.cpp queryTrades behavioral workflow |
| CVE-2026-19244 | 2.0 | 19.6 | HKUDS | nanobot | CWE-266 | HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control |
| CVE-2026-54218 | 8.8 | 19.3 | Tobit Laboratories AG | TeamDavid | CWE-321 | TeamDavid: Weak Cryptography and Insecure Password Storage |
| CVE-2026-54215 | 5.3 | 19.3 | Tobit Laboratories AG | TeamDavid | CWE-601 | TeamDavid: Open Redirect via the 'replyUrl' parameter |
| CVE-2026-19212 | 2.1 | 19.3 | n/a | WonderTrader | CWE-453 | WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized va… |
| CVE-2026-14205 | 9.8 | 19.0 | Unknown | WP Events Manager | CWE-287 | WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter |
| CVE-2026-49343 | 5.9 | 18.4 | klever-io | klever-go | CWE-400 | Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch boo… |
| CVE-2026-19196 | 5.5 | 18.2 | SourceCodester | Photo Share Website | CWE-74 | SourceCodester Photo Share Website ajax.php login sql injection |
| CVE-2026-19211 | 5.5 | 18.2 | SourceCodester | Photo Share Website | CWE-74 | SourceCodester Photo Share Website ajax.php signup sql injection |
| CVE-2026-19231 | 5.5 | 18.2 | SourceCodester | Simple Doctors Appointment System | CWE-74 | SourceCodester Simple Doctors Appointment System ajax.php delete_appointment … |
| CVE-2026-54199 | 5.3 | 18.2 | Tobit Laboratories AG | TeamDavid | CWE-20 | TeamDavid: Header Injection through request body in link storing functionality |
| CVE-2026-64637 | 9.9 | 18.1 | WebPros | Plesk | CWE-269 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, all… |
| CVE-2026-19014 | 4.3 | 18.0 | HashiCorp | Consul | CWE-770 | Uncontrolled resource consumption in the Consul Connect authorization endpoint |
| CVE-2026-48169 | 8.8 | 17.8 | MervinPraison | praisonai-platform | CWE-639 | PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API |
| CVE-2026-14943 | 7.5 | 17.8 | Unknown | Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content | CWE-200 | Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure v… |
| CVE-2026-15816 | 7.5 | 17.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-78 | Dracut: dracut: root code execution via unescaped error message written to so… |
| CVE-2026-66000 | 2.3 | 17.7 | frappe | frappe | CWE-863 | Frappe: Unrestricted access to Document Follow APIs |
| CVE-2026-54217 | 5.3 | 17.6 | Tobit Laboratories AG | TeamDavid | CWE-20 | TeamDavid: Stored XSS in web application |
| CVE-2026-71847 | 8.7 | 17.0 | ruby | json | CWE-416 | Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buf… |
| CVE-2026-17598 | 5.3 | 17.0 | Sonatype | Nexus Repository 3 | CWE-915 | Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration |
| CVE-2026-47364 | 6.5 | 16.8 | Datadog | Android App | CWE-200 | In versions of the Datadog Android application prior to v545-5.9.2, the app t… |
| CVE-2026-48170 | 9.1 | 16.6 | thomaspoignant | scim-patch | CWE-1321 | scimPatch vulnerable to prototype pollution via unfiltered keys in patch |
| CVE-2026-19012 | 5.3 | 15.9 | HashiCorp | Consul | CWE-476 | Authenticated denial of service in Consul Enterprise-to-Community Edition dow… |
| CVE-2026-47127 | 6.5 | 15.9 | ghostfolio | ghostfolio | CWE-862 | Ghostfolio has a Stripe subscription bypass |
| CVE-2026-54200 | 8.4 | 15.7 | Tobit Laboratories AG | TeamDavid | CWE-73 | TeamDavid: Local File Inclusion via the form field 'scjob' |
| CVE-2026-16038 | 9.1 | 15.3 | Unknown | MStore API | CWE-862 | MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gat… |
| CVE-2026-66838 | 5.9 | 15.3 | elixir-ecto | postgrex | CWE-89 | SQL injection via the :comment option in Postgrex.stream/4 |
| CVE-2026-61477 | 2.3 | 15.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-93 | Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows … |
| CVE-2026-47662 | 8.7 | 15.3 | aehrc | pathling | CWE-20 | Pathling $bulk-submit allows bearer-token exfiltration and persistent warehou… |
| CVE-2026-47663 | 8.7 | 15.3 | aehrc | pathling | CWE-285 | Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfil… |
| CVE-2026-17596 | 6.3 | 15.2 | Sonatype | Nexus Repository 3 | CWE-79 | Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name |
| CVE-2026-17594 | 8.2 | 15.1 | Sonatype | Nexus Repository 3 | CWE-863 | Nexus Repository 3 - Authorization Bypass in Repository Creation |
| CVE-2026-64636 | 7.7 | 15.0 | WebPros | Plesk | CWE-89 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and … |
| CVE-2026-71849 | 3.7 | 14.8 | honojs | hono | CWE-200 | Hono: Proxy Helper does not remove response headers listed in the `Connection… |
| CVE-2026-14644 | 8.6 | 14.6 | Sonatype | Nexus Repository 3 | CWE-843 | Nexus Repository 3 - Privilege Escalation |
| CVE-2026-12070 | 8.4 | 14.6 | Tobit Laboratories AG | TeamDavid | CWE-73 | TeamDavid: Arbitrary File Deletion via form field 'scjob' |
| CVE-2026-16265 | 6.5 | 14.6 | Unknown | WP Maps | CWE-400 | WP Maps < 4.9.7 - Subscriber+ Denial of Service |
| CVE-2026-11907 | 6.5 | 14.5 | xwp | Stream – Activity Log & Audit Trail | CWE-862 | Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensit… |
| CVE-2026-16030 | 8.1 | 13.6 | Unknown | MStore API | CWE-287 | MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Aut… |
| CVE-2026-66058 | 5.3 | 13.4 | frappe | frappe | CWE-639 | Frappe: Unrestricted access to a Document Follow API |
| CVE-2026-15361 | 8.1 | 12.9 | Unknown | Content Views | CWE-89 | Content Views < 4.5 - Subscriber+ SQL Injection via preview_request |
| CVE-2026-19246 | 2.1 | 12.9 | HKUDS | nanobot | CWE-918 | HKUDS nanobot Provider-returned Image URL image_generation.py _download_image… |
| CVE-2026-48026 | 8.7 | 12.6 | treeverse | lakeFS | CWE-79 | lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML |
| CVE-2026-59717 | 4.3 | 12.4 | home-assistant | core | CWE-601 | Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing |
| CVE-2026-19213 | 2.1 | 12.3 | n/a | WonderTrader | CWE-840 | WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow |
| CVE-2026-17601 | 8.9 | 12.2 | Sonatype | Nexus Repository 3 | CWE-862 | Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator |
| CVE-2026-17600 | 8.7 | 12.2 | Sonatype | Nexus Repository 3 | CWE-613 | Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deac… |
| CVE-2026-19016 | 4.2 | 11.8 | HashiCorp | Consul | CWE-22 | Authorization bypass for session deletion in the transaction API |
| CVE-2026-19207 | 1.9 | 11.5 | PHPGurukul | Company Visitor Management System | CWE-79 | PHPGurukul Company Visitor Management System manage-newvisitors.php cross sit… |
| CVE-2026-16041 | 7.5 | 11.2 | Unknown | MStore API | CWE-862 | MStore API < 4.21.0 - Unauthenticated Product Review Creation |
| CVE-2026-15570 | 7.1 | 11.1 | Vestel | Telefunken TE24553B45V2DZ Smart TV | CWE-918 | Improper URL Scheme and Destination Validation in SmartCenter browserseturl C… |
| CVE-2026-15359 | 6.5 | 10.5 | Unknown | Templately | CWE-862 | Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connectio… |
| CVE-2026-16039 | 6.5 | 10.3 | Unknown | MStore API | CWE-639 | MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR |
| CVE-2025-71409 | 7.1 | 10.2 | ATN-B1 | CPDLC | CWE-306 | No Authentication for Very High Frequency Data Link messages used in CPDLC |
| CVE-2026-19209 | 2.0 | 10.0 | SourceCodester | Photo Share Website | CWE-79 | SourceCodester Photo Share Website index.php home cross site scripting |
| CVE-2026-19230 | 2.0 | 10.0 | SourceCodester | Photo Share Website | CWE-79 | SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cro… |
| CVE-2025-71410 | 6.0 | 10.0 | ATN-B1 | CPDLC | CWE-770 | Malicious Link Control Frames Can Cause Loss of CPDLC Functions |
| CVE-2025-71411 | 6.0 | 10.0 | ATN-B1 | CPDLC | CWE-770 | In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultane… |
| CVE-2025-71413 | 6.0 | 10.0 | ATN-B1 | CPDLC | CWE-754 | In CPDLC, Malformed or Out of Sequence Frames Can Cause Resets |
| CVE-2026-12261 | 5.3 | 9.2 | nltk | nltk/nltk | CWE-284 | Improper Access Control in nltk/nltk |
| CVE-2026-44964 | 6.5 | 9.0 | Datadog | Android App | CWE-441 | In versions of the Datadog Android application prior to v545-5.9.2, OnCallNot… |
| CVE-2025-71412 | 7.1 | 8.3 | ATN-B1 | CPDLC | CWE-754 | In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate |
| CVE-2026-16027 | 5.4 | 8.2 | Revenue Administration | E-Signature | CWE-918 | Unauthenticated WebSocket-to-XAdES SSRF in Revenue Administration's E-Signature |
| CVE-2026-47243 | 9.2 | 7.9 | kata-containers | kata-containers | CWE-22 | Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs |
| CVE-2026-49008 | 6.5 | 7.2 | ZTE | F689 | CWE-321 | Integrity‑check credential leakage vulnerability in an application function o… |
| CVE-2026-47361 | 6.4 | 7.1 | Datadog | Android App | CWE-926 | In versions of the Datadog Android application prior to v541-5.9.2, BubbleCha… |
| CVE-2026-47362 | 4.6 | 6.9 | Datadog | Android App | CWE-922 | In versions of the Datadog Android application prior to v554-5.9.4, two Room-… |
| CVE-2026-48007 | 8.6 | 6.2 | element-hq | element-call | CWE-200 | Element Call reports full URLs of visited pages to analytics server |
| CVE-2026-71850 | 4.8 | 6.1 | honojs | hono | CWE-488 | Hono: `memo()` retains SSR output across requests, leading to cross-user data… |
| CVE-2026-19206 | 1.9 | 6.1 | MZ Automation | libiec61850 | CWE-119 | MZ Automation libiec61850 ASDU Element sv_subscriber.c SVReceiver_stopThreadl… |
| CVE-2026-9031 | 6.8 | 6.0 | TP-Link Systems Inc. | Archer A6 v4 | CWE-20 | Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 |
| CVE-2026-48093 | 6.5 | 5.9 | dartiss | code-embed | CWE-79 | Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embed |
| CVE-2026-15032 | 6.1 | 5.9 | Unknown | Comments | CWE-79 | wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion |
| CVE-2026-15214 | 4.3 | 5.9 | Unknown | Subscriptions for WooCommerce | CWE-639 | Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Discl… |
| CVE-2026-37171 | 5.9 | 5.7 | n/a | n/a | CWE-863 | A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v1… |
| CVE-2026-15970 | 4.2 | 5.6 | HashiCorp | Consul | CWE-647 | L7 intention authorization bypass via custom public listener |
| CVE-2026-16262 | 7.5 | 5.5 | Unknown | Estatik Real Estate Plugin | CWE-352 | Estatik < 4.3.3 - Login CSRF |
| CVE-2026-71381 | 4.0 | 5.5 | Adobe | Adobe Genuine Software Integrity Service | CWE-863 | Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization |
| CVE-2026-12801 | 6.4 | 5.3 | themefic | Ultra Addons for Contact Form 7 | CWE-79 | Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stor… |
| CVE-2026-11425 | 2.0 | 5.3 | Domoticz | Domoticz | CWE-79 | Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert … |
| CVE-2026-14331 | 6.1 | 4.6 | Unknown | Subscribe2 | CWE-79 | Subscribe2 < 10.46 - Reflected XSS via email Parameter |
| CVE-2026-49006 | 5.3 | 4.5 | ZTE | F689 | CWE-321 | TLS credential leakage vulnerability in ZTE F689 product |
| CVE-2026-46358 | 5.4 | 4.4 | openbao | openbao | CWE-532 | OpenBao's Inline Auth Incorrectly Redacted Headers |
| CVE-2026-47664 | 8.6 | 4.2 | aehrc | pathling | CWE-20 | Pathling: $import-pnp operation enables authenticated SSRF, credential leakag… |
| CVE-2026-9169 | 8.8 | 4.2 | LUCID Vision Labs | Arena SDK | CWE-427 | LUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on Windows |
| CVE-2026-47363 | 6.3 | 4.0 | Datadog | Android App | CWE-926 | In versions of the Datadog Android application prior to v541-5.9.2, the expor… |
| CVE-2026-19190 | 7.1 | 3.6 | StableBit | Scanner | CWE-266 | StableBit Scanner ScannerService Scanner.Service.exe permission |
| CVE-2026-48120 | 8.6 | 3.6 | mawww | kakoune | CWE-74 | Kakoune has a Critical RCE via Autorestore Backup Filename Injection |
| CVE-2026-15245 | 5.4 | 3.3 | Unknown | BNE Testimonials | CWE-79 | BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode |
| CVE-2026-15386 | 5.4 | 3.3 | Unknown | Meow Gallery | CWE-79 | Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text |
| CVE-2026-48098 | 7.3 | 3.1 | 0x5t4l1n | NexTOR_IP_CHANGER | CWE-78 | NexTOR IP Changer Unsafely Uses sudo and shell=True |
| CVE-2026-9030 | 6.8 | 3.1 | TP-Link Systems Inc. | Archer A6 v4 | CWE-362 | Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 |
| CVE-2026-71870 | 4.8 | 2.9 | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage for large /ToUnicode streams |
| CVE-2026-71852 | 4.8 | 2.8 | py-pdf | pypdf | CWE-834 | pypdf: Possible long runtimes/large memory usage for large CID font width ranges |
| CVE-2026-48122 | 5.4 | 2.6 | Shopify | ruby-lsp | CWE-78 | Workspace settings can override executable and Gemfile paths used by the Ruby… |
| CVE-2026-18497 | 7.1 | 2.6 | Sean Barrett (nothings) | nothings stb | CWE-122 | The nothings stb TrueType library contains a heap buffer overflow vulnerability |
| CVE-2026-64676 | 5.7 | 2.4 | kata-containers | kata-containers | CWE-862 | Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host t… |
| CVE-2026-19245 | 1.9 | 2.3 | HKUDS | nanobot | CWE-200 | HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command info… |
| CVE-2026-45198 | 7.8 | 2.1 | Imagination Technologies | Graphics DDK | CWE-822 | GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted |
| CVE-2026-58262 | 7.1 | 2.0 | klever-io | klever-go | CWE-345 | Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum |
| CVE-2026-17435 | 2.5 | 2.0 | RRWO | File::Rotate::Simple | CWE-59 | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dang… |
| CVE-2026-62293 | 5.0 | 1.9 | hapifhir | org.hl7.fhir.core | CWE-20 | HAPI FHIR: Stored XSS in scan report via unescaped IG and profile titles |
| CVE-2026-49005 | 2.4 | 1.8 | ZTE | F689 | CWE-916 | Root password hash exposure vulnerability in ZTE F689 product |
| CVE-2026-15148 | 5.3 | 1.8 | Unknown | WP Events Manager | CWE-345 | WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status… |
| CVE-2026-66060 | 7.1 | 1.7 | home-assistant | core | CWE-862 | Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation executio… |
| CVE-2026-66061 | 7.1 | 1.7 | home-assistant | core | CWE-862 | Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmat… |
| CVE-2026-44965 | 5.5 | 1.7 | Datadog | Android App | CWE-926 | In versions of the Datadog Android application prior to v545-5.9.2, six App W… |
| CVE-2026-19189 | 7.1 | 1.5 | Power Sofware | PowerISO | CWE-266 | Power Sofware PowerISO Kernel Driver scdemu.sys privileges management |
| CVE-2026-19193 | 7.1 | 1.5 | Jiangmin | Antivirus | CWE-266 | Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access co… |
| CVE-2026-19195 | 7.1 | 1.5 | V-Secure | Jingyun Antivirus | CWE-266 | V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control |
| CVE-2026-15211 | 5.9 | 1.5 | Unknown | Subscriptions for WooCommerce | CWE-345 | Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied … |
| CVE-2026-15239 | 5.3 | 1.5 | Unknown | Simple CAPTCHA with Cloudflare Turnstile | CWE-345 | Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile… |
| CVE-2026-66151 | 5.5 | 1.5 | SonicWall | Global VPN Client | CWE-125 | SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to … |
| CVE-2026-19191 | 7.1 | 1.4 | StableBit | DrivePool | CWE-266 | StableBit DrivePool DrivePoolService DrivePool.Service.exe permission |
| CVE-2026-19192 | 7.1 | 1.4 | DeepCool | DisplayService | CWE-266 | DeepCool DisplayService DeepCoolDisplayService.exe access control |
| CVE-2026-49746 | 7.1 | 1.3 | Imagination Technologies | Graphics DDK | CWE-823 | GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem |
| CVE-2026-18938 | 6.2 | 1.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | P11-kit: integer overflow in rpc attribute-array length calculation can under… |
| CVE-2026-45204 | 5.5 | 1.3 | Imagination Technologies | Graphics DDK | CWE-476 | GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in … |
| CVE-2026-11743 | 6.6 | 1.2 | zephyrproject | zephyr | CWE-125 | Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver al… |
| CVE-2026-11742 | 3.6 | 0.7 | zephyrproject | zephyr | CWE-416 | Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock |
| CVE-2026-19079 | 4.4 | 0.3 | Red Hat | Red Hat Hardened Images | CWE-367 | Policycoreutils: policycoreutils: toctou race condition in fixfiles allows ar… |