CVE-2026-105284 — CVSS 10.0 (critical): A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file…
CVE-2025-41115 — CVSS 10.0 (critical): SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in…
CVE-2026-42368 — CVSS 9.9 (critical): A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP…
CVE-2026-32922 — CVSS 9.9 (critical): OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing…
CVE-2026-22907 — CVSS 9.9 (critical): An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.
CVE-2025-62645 — CVSS 9.9 (critical): The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token…
CVE-2025-10725 — CVSS 9.9 (critical): A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data…
CVE-2025-54049 — CVSS 9.9 (critical): Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue…
CVE-2025-26512 — CVSS 9.9 (critical): SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user…
CVE-2026-72839 — CVSS 9.8 (critical): filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir…