Critical vulnerabilities, curated daily for security professionals
🎯 SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
📊
Today's Security Brief
Friday's vulnerability disclosures include a CVSS 10.0 flaw in Copeland XWEB Pro (CVE-2026-21718) and a CVSS 9.9 Google Cloud service vulnerability (CVE-2026-27941), alongside critical issues in Xerox FreeFlow Core, Langflow, and EverShop. Critical CVEs jumped to 18, a 125% increase from the prior day's 8, while 100 high-priority vulnerabilities held steady. Remote code execution and authentication bypass patterns dominate the critical findings, affecting enterprise infrastructure from Totolink routers to OpenStack Vitrage deployments. Cisco Catalyst SD-WAN and multiple Microsoft Windows components are confirmed under active exploitation across 18 KEV entries. Patch availability remains at 0%, requiring organizations to prioritize compensating controls and network segmentation for affected systems.
CVSS 10.0 vulnerability in Copeland XWEB Pro (CVE-2026-21718) and CVSS 9.9 Google Cloud service flaw (CVE-2026-27941) require immediate risk assessment
18 critical CVEs disclosed, up 125% from 8 the prior day, spanning Microsoft, Xerox, HP, and Langflow products
100 high-priority CVEs remained consistent with the prior day's volume across the disclosure pipeline
Remote code execution and authentication bypass flaws affect Totolink N300RH routers, EverShop e-commerce, and OpenStack Vitrage
0% patch availability across all disclosed vulnerabilities — compensating controls and network isolation are essential
18 actively exploited vulnerabilities include Cisco Catalyst SD-WAN (CVSS 10.0), multiple Microsoft Windows components, and Roundcube Webmail
Immediate action: Prioritize network segmentation and access restrictions for Copeland XWEB Pro, Google Cloud services, Cisco Catalyst SD-WAN, and Microsoft Windows systems confirmed under active exploitation. With 0% patch availability, implement compensating controls including WAF rules, privilege reduction, and enhanced monitoring for all affected products until vendor patches are released.
💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove
Section Navigation
⚠️
CISA Known Exploited Vulnerabilities
⚠️ CISA KEV
CVE-2026-20127
10
CiscoCatalyst SD
⏰ Federal Deadline:February 26, 2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
CVSS Base10
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-21513
9.5📝
MicrosoftWindows
⏰ Federal Deadline:March 2, 2026(4 days remaining)
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-21525
9.5
MicrosoftWindows
⏰ Federal Deadline:March 2, 2026(4 days remaining)
Microsoft Windows NULL Pointer Dereference Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-21510
9.5📝
MicrosoftWindows
⏰ Federal Deadline:March 2, 2026(4 days remaining)
A protection mechanism failure in the Windows Shell allows an unauthenticated attacker to bypass security features over a network connection.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-21533
9.5📝
MicrosoftWindows
⏰ Federal Deadline:March 2, 2026(4 days remaining)
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate their privileges locally on the affected system.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-21519
9.5📝
MicrosoftWindows
⏰ Federal Deadline:March 2, 2026(4 days remaining)
A type confusion vulnerability in the Desktop Window Manager (DWM) allows an authorized local attacker to elevate their privileges to a higher level.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-21514
9.5📝
MicrosoftOffice
⏰ Federal Deadline:March 2, 2026(4 days remaining)
A security feature bypass vulnerability in Microsoft Office Word exists due to reliance on untrusted inputs, allowing an unauthorized local attacker to circumvent security protections.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-20700
9.5📝
AppleApple OS
⏰ Federal Deadline:March 4, 2026(6 days remaining)
A memory corruption vulnerability in Apple software was addressed through improved state management to prevent potential exploitation.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2024-43468
9.5📜 Late Disclosure
MicrosoftConfiguration Manager
⏰ Federal Deadline:March 4, 2026(6 days remaining)
Microsoft Configuration Manager SQL Injection Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2025-15556
9.5
Notepad++Notepad++
⏰ Federal Deadline:March 4, 2026(6 days remaining)
Notepad++ Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2020-7796
9.5📜 Late Disclosure
SynacorZimbra Collaboration Suite
⏰ Federal Deadline:March 9, 2026(11 days remaining)
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2024-7694
9.5📜 Late Disclosure
TeamT5ThreatSonar Anti-Ransomware
⏰ Federal Deadline:March 9, 2026(11 days remaining)
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2008-0015
9.5📜 Late Disclosure
MicrosoftWindows
⏰ Federal Deadline:March 9, 2026(11 days remaining)
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2026-2441
9.5📝
GoogleChromium
⏰ Federal Deadline:March 9, 2026(11 days remaining)
Google Chrome is vulnerable to a "Use After Free" condition in its CSS engine, which could allow a remote attacker to execute arbitrary code via a crafted webpage.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2021-22175
9.5📜 Late Disclosure
GitLabGitLab
⏰ Federal Deadline:March 10, 2026(12 days remaining)
GitLab Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2025-49113
9.5
RoundcubeWebmail
⏰ Federal Deadline:March 12, 2026(14 days remaining)
RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2025-68461
9.5
RoundcubeWebmail
⏰ Federal Deadline:March 12, 2026(14 days remaining)
RoundCube Webmail Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEV
CVE-2026-25108
9.5📝
Soliton Systems K.KFileZen
⏰ Federal Deadline:March 16, 2026(18 days remaining)
FileZen is affected by a high-severity OS command injection vulnerability that allows a threat actor to execute arbitrary commands on the underlying operating system.
CVSS Base9.5
→
CRSSelect profile
🚨
Critical Vulnerabilities
CVE-2026-28215
9.1📝
MicrosoftOAuth application
A critical flaw in Hoppscotch allows unauthenticated attackers to overwrite infrastructure configurations via the onboarding endpoint, leading to SSO hijacking and full credential exposure.
CVSS Base9.1
→
CRSSelect profile
CVE-2026-2251
9.8
XeroxFreeFlow Core
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE.
This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.
Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads
https://www.support.xerox.com/en-us/product/core/downloads
CVSS Base9.8
→
CRSSelect profile
CVE-2026-27941
9.9📝
GoogleCloud service
OpenLIT GitHub Actions workflows are vulnerable to unauthorized code execution via forked pull requests, leading to the potential theft of sensitive secrets and cloud service keys.
CVSS Base9.9
→
CRSSelect profile
CVE-2025-12981
9.8📝
WordPressis vulnerable
The Listee theme for WordPress allows unauthenticated registration as an Administrator due to a broken validation check in the listee-core plugin's registration function.
CVSS Base9.8
→
CRSSelect profile
CVE-2025-50857
9.8📝
HPZenTaoPMS
ZenTaoPMS is vulnerable to a directory traversal flaw in its AI module, enabling unauthenticated attackers to achieve remote code execution via malicious file uploads.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-27966
9.8📝
LangflowLangflow
Langflow's CSV Agent node improperly enables dangerous code execution by default, allowing unauthenticated attackers to achieve remote code execution via prompt injection.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-28213
9.8📝
theEverShop
The EverShop eCommerce platform leaks password reset tokens in API responses, enabling unauthenticated attackers to bypass authentication and take over any user account.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-3301
9.8📝
TotolinkN300RH
A remote OS command injection vulnerability exists in the Totolink N300RH Web Management Interface due to improper handling of the webWlanIdx parameter.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-28370
9.1📝
OpenStackVitrage
OpenStack Vitrage contains a code execution vulnerability in its query parser, allowing authenticated API users to execute arbitrary code on the service host.
CVSS Base9.1
→
CRSSelect profile
CVE-2026-21718
10📝
CopelandXWEB Pro
Copeland XWEB Pro suffers from an authentication bypass vulnerability that allows unauthenticated attackers to achieve remote code execution.
CVSS Base10
→
CRSSelect profile
CVE-2026-24663
9📝
CopelandXWEB Pro
An unauthenticated OS command injection vulnerability in Copeland XWEB Pro allows remote code execution via a crafted request to the libraries installation route.
CVSS Base9
→
CRSSelect profile
CVE-2026-28363
9.9
ABBMultiple Products
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.
CVSS Base9.9
→
CRSSelect profile
CVE-2026-20781
9.4📝
OCPP ImplementationsOCPP WebSocket Endpoint
A lack of authentication in OCPP WebSocket endpoints allows unauthenticated attackers to impersonate charging stations and manipulate charging network data.
CVSS Base9.4
→
CRSSelect profile
CVE-2026-24731
9.4📝
OCPP ImplementationsOCPP WebSocket Endpoint
Unauthenticated attackers can impersonate EV charging stations due to missing authentication mechanisms in OCPP WebSocket endpoints, enabling data manipulation.
CVSS Base9.4
→
CRSSelect profile
CVE-2026-25851
9.4📝
OCPP ImplementationsOCPP WebSocket Endpoint
OCPP WebSocket endpoints lack authentication, allowing unauthenticated attackers to impersonate legitimate charging stations and issue unauthorized commands.
CVSS Base9.4
→
CRSSelect profile
CVE-2026-27767
9.4📝
OCPP ImplementationsOCPP WebSocket Endpoint
Unauthenticated attackers can perform station impersonation and manipulate backend data due to a lack of authentication on OCPP WebSocket endpoints.
WebSocket endpoints lack authentication, allowing unauthenticated attackers to impersonate charging stations and manipulate backend data via the Open Charge Point Protocol.
Unauthenticated attackers can perform station impersonation and manipulate backend data due to a lack of proper authentication on OCPP WebSocket endpoints.
CVSS Base9.4
→
CRSSelect profile
⚠️
High Priority Updates
CVE-2026-27700
8.2📝
AWSLambda adapter
The Hono web application framework is affected by a high-severity vulnerability that could impact any JavaScript runtime environment it supports.
CVSS Base8.2
→
CRSSelect profile
CVE-2026-27938
7.7
WordPresssites
WPGraphQL provides a GraphQL API for WordPress sites
CVSS Base7.7
→
CRSSelect profile
CVE-2026-2252
7.5
performFreeFlow Core
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references
CVSS Base7.5
→
CRSSelect profile
CVE-2026-1779
8.1
WordPressis vulnerable
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5
CVSS Base8.1
→
CRSSelect profile
CVE-2026-20048
7.7📝
CiscoNexus
A vulnerability in the SNMP subsystem of Cisco Nexus 9000 Series switches could allow an authenticated attacker to cause a denial of service condition.
CVSS Base7.7
→
CRSSelect profile
CVE-2026-20051
7.4📝
CiscoNexus
A vulnerability in the EVPN Layer 2 ingress packet processing of Cisco Nexus switches allows an adjacent attacker to trigger a disruptive Layer 2 traffic loop.
CVSS Base7.4
→
CRSSelect profile
CVE-2026-1311
8.8
WordPressis vulnerable
The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0
CVSS Base8.8
→
CRSSelect profile
CVE-2026-1565
8.8
WordPressis vulnerable
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4
CVSS Base8.8
→
CRSSelect profile
CVE-2026-20126
8.8📝
CiscoCatalyst SD
A privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated, local attacker with low-level privileges to gain root access to the underlying operating system.
CVSS Base8.8
→
CRSSelect profile
CVE-2026-27899
8.8
Dockerimages for
WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management
CVSS Base8.8
→
CRSSelect profile
CVE-2026-1557
7.5
WordPressis vulnerable
The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1
CVSS Base7.5
→
CRSSelect profile
CVE-2026-27903
7.5📝
Isaacsminimatch
The minimatch library, a JavaScript utility for glob matching, is vulnerable to a flaw that could result in application instability or unauthorized processing of malicious expressions.
CVSS Base7.5
→
CRSSelect profile
CVE-2026-27904
7.5📝
Isaacsminimatch
A second high-severity vulnerability in the minimatch JavaScript library could lead to system resource exhaustion or security bypasses when processing glob expressions.
CVSS Base7.5
→
CRSSelect profile
CVE-2026-2428
7.5
WordPressis vulnerable
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6
CVSS Base7.5
→
CRSSelect profile
CVE-2026-22719
8.1📝
VMwareAria Operations
VMware Aria Operations contains a command injection vulnerability that could allow an attacker to execute arbitrary commands on the affected system.
CVSS Base8.1
→
CRSSelect profile
CVE-2026-22720
8
VMwareAria Operations
VMware Aria Operations contains a stored cross-site scripting vulnerability
CVSS Base8
→
CRSSelect profile
CVE-2026-20128
7.5
CiscoCatalyst SD
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system
CVSS Base7.5
→
CRSSelect profile
CVE-2026-20010
7.4
CiscoNX
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly
CVSS Base7.4
→
CRSSelect profile
CVE-2026-20033
7.4
CiscoNexus
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device
CVSS Base7.4
→
CRSSelect profile
CVE-2026-3261
7.3
HPof the
A flaw has been found in itsourcecode School Management System 1
CVSS Base7.3
→
CRSSelect profile
CVE-2026-0980
8.3
RedSatellite
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite
CVSS Base8.3
→
CRSSelect profile
CVE-2026-26984
8.7
Archand Imaging
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research
CVSS Base8.7
→
CRSSelect profile
CVE-2026-25164
8.1
HPMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVSS Base8.1
→
CRSSelect profile
CVE-2025-71057
8.2
D-LinkWireless
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1
CVSS Base8.2
→
CRSSelect profile
CVE-2026-26985
8.1
Archand Imaging
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research
CVSS Base8.1
→
CRSSelect profile
CVE-2026-25476
7.5
HPMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVSS Base7.5
→
CRSSelect profile
CVE-2026-3271
8.8
TendaF453
A vulnerability was found in Tenda F453 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-3272
8.8
TendaF453
A vulnerability was determined in Tenda F453 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-3273
8.8
TendaF453
A vulnerability was identified in Tenda F453 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-3274
8.8
TendaF453
A security flaw has been discovered in Tenda F453 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-3275
8.8
TendaF453
A weakness has been identified in Tenda F453 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-27831
7.5
DNSMultiple Products
rldns is an open source DNS server
CVSS Base7.5
→
CRSSelect profile
CVE-2026-26955
8.8
UnknownMultiple Products
FreeRDP is a free implementation of the Remote Desktop Protocol
CVSS Base8.8
→
CRSSelect profile
CVE-2026-26965
8.8
UnknownMultiple Products
FreeRDP is a free implementation of the Remote Desktop Protocol
CVSS Base8.8
→
CRSSelect profile
CVE-2026-0752
8
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16
CVSS Base8
→
CRSSelect profile
CVE-2026-28216
8.3
UnknownMultiple Products
hoppscotch is an open source API development ecosystem
CVSS Base8.3
→
CRSSelect profile
CVE-2026-25191
7.8
FinalCodepath
The installer of FinalCode Client provided by Digital Arts Inc
CVSS Base7.8
→
CRSSelect profile
CVE-2025-14511
7.5
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12
CVSS Base7.5
→
CRSSelect profile
CVE-2026-1388
7.5
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9
CVSS Base7.5
→
CRSSelect profile
CVE-2026-1662
7.5
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14
CVSS Base7.5
→
CRSSelect profile
CVE-2026-28372
7.4
inetutilsin release
telnetd in GNU inetutils through 2
CVSS Base7.4
→
CRSSelect profile
CVE-2026-27850
7.5
sourceMultiple Products
Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network
CVSS Base7.5
→
CRSSelect profile
CVE-2026-27635
7.5
collectionMultiple Products
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing
CVSS Base7.5
→
CRSSelect profile
CVE-2026-3071
8.4
fromMultiple Products
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0
CVSS Base8.4
→
CRSSelect profile
CVE-2026-3172
8.1
BufferMultiple Products
Buffer overflow in parallel HNSW index build in pgvector 0
CVSS Base8.1
→
CRSSelect profile
CVE-2026-28136
7.6
VeronaLabs WP SMSMultiple Products
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection
CVSS Base7.6
→
CRSSelect profile
CVE-2026-28193
8.8
YouTrackMultiple Products
In JetBrains YouTrack before 2025
CVSS Base8.8
→
CRSSelect profile
CVE-2026-25746
8.8
prescriptionMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVSS Base8.8
→
CRSSelect profile
CVE-2026-27976
8.8
ArchMultiple Products
Zed, a code editor, has an extension installer allows tar/gzip downloads
CVSS Base8.8
→
CRSSelect profile
CVE-2026-27952
8.8
UnknownMultiple Products
Agenta is an open-source LLMOps platform
CVSS Base8.8
→
CRSSelect profile
CVE-2026-27961
8.8
UnknownMultiple Products
Agenta is an open-source LLMOps platform
CVSS Base8.8
→
CRSSelect profile
CVE-2026-28274
8.7
UnknownMultiple Products
Initiative is a self-hosted project management platform
CVSS Base8.7
→
CRSSelect profile
CVE-2026-27730
8.6
UnknownMultiple Products
esm
CVSS Base8.6
→
CRSSelect profile
CVE-2026-26938
8.6
TemplateMultiple Products
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242)
CVSS Base8.6
→
CRSSelect profile
CVE-2026-25085
8.6
ProMultiple Products
A vulnerability exists in Copeland XWEB Pro version 1
CVSS Base8.6
→
CRSSelect profile
CVE-2025-67601
8.3
RancherMultiple Products
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts
CVSS Base8.3
→
CRSSelect profile
CVE-2026-24890
8.1
patientMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVSS Base8.1
→
CRSSelect profile
CVE-2026-25136
8.1
UnknownMultiple Products
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies
CVSS Base8.1
→
CRSSelect profile
CVE-2026-23750
8.1
PouchMultiple Products
Golioth Pouch version 0
CVSS Base8.1
→
CRSSelect profile
CVE-2026-28275
8.1
UnknownMultiple Products
Initiative is a self-hosted project management platform
CVSS Base8.1
→
CRSSelect profile
CVE-2026-20742
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-20902
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-20910
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-21389
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-24517
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-24689
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-24695
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-25109
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-25111
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-25195
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-20764
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-23702
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-24452
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-25037
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-25105
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-25196
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-25721
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-3037
8
ProMultiple Products
An OS command injection vulnerability exists in XWEB Pro version 1
CVSS Base8
→
CRSSelect profile
CVE-2026-28364
7.9
OCamlMultiple Products
In OCaml before 4
CVSS Base7.9
→
CRSSelect profile
CVE-2026-23703
7.8
FinalCodeMultiple Products
The installer of FinalCode Client provided by Digital Arts Inc
CVSS Base7.8
→
CRSSelect profile
CVE-2026-26682
7.8
UnknownMultiple Products
An issue in fastCMS before v
CVSS Base7.8
→
CRSSelect profile
CVE-2026-28211
7.8
UnknownMultiple Products
The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing
CVSS Base7.8
→
CRSSelect profile
CVE-2026-1442
7.8
LGMultiple Products
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models
CVSS Base7.8
→
CRSSelect profile
CVE-2026-27706
7.7
UnknownMultiple Products
Plane is an an open-source project management tool
CVSS Base7.7
→
CRSSelect profile
CVE-2025-14343
7.6
Dokuzsoft TechnologyMultiple Products
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd
CVSS Base7.6
→
CRSSelect profile
CVE-2026-27959
7.5
UnknownMultiple Products
Koa is middleware for Node
CVSS Base7.5
→
CRSSelect profile
CVE-2026-26078
7.5
UnknownMultiple Products
Discourse is an open source discussion platform
CVSS Base7.5
→
CRSSelect profile
CVE-2026-26265
7.5
directoryMultiple Products
Discourse is an open source discussion platform
CVSS Base7.5
→
CRSSelect profile
CVE-2026-27449
7.5
IntelMultiple Products
Umbraco Engage is a business intelligence platform
CVSS Base7.5
→
CRSSelect profile
CVE-2026-28276
7.5
UnknownMultiple Products
Initiative is a self-hosted project management platform
CVSS Base7.5
→
CRSSelect profile
CVE-2026-20792
7.5
UnknownMultiple Products
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests
CVSS Base7.5
→
CRSSelect profile
CVE-2026-25113
7.5
UnknownMultiple Products
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests
CVSS Base7.5
→
CRSSelect profile
CVE-2026-25114
7.5
UnknownMultiple Products
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests
CVSS Base7.5
→
CRSSelect profile
CVE-2026-25945
7.5
UnknownMultiple Products
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests
CVSS Base7.5
→
CRSSelect profile
CVE-2026-24445
7.5
UnknownMultiple Products
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests
CVSS Base7.5
→
CRSSelect profile
CVE-2026-26305
7.5
UnknownMultiple Products
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests
CVSS Base7.5
→
CRSSelect profile
CVE-2026-27800
7.4
ArchMultiple Products
Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0
CVSS Base7.4
→
CRSSelect profile
CVE-2026-25733
7.3
CustomMultiple Products
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies
CVSS Base7.3
→
CRSSelect profile
CVE-2026-3200
7.3
UnknownMultiple Products
A vulnerability was identified in z-9527 admin 1
CVSS Base7.3
→
CRSSelect profile
CVE-2026-27616
7.3
UnknownMultiple Products
Vikunja is an open-source self-hosted task management platform