| CVE-2026-11645exploited | 8.8 | high | google / chrome | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a | 89d ago |
| CVE-2026-45659exploited | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 106d ago |
| CVE-2026-33634exploited | 8.8 | high | aquasec / setup-trivy | Trivy is a security scanner. | 166d ago |
| CVE-2026-3910exploited | 8.8 | high | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arb | 176d ago |
| CVE-2026-3909exploited | 8.8 | high | google / chrome | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bou | 176d ago |
| CVE-2026-20230exploited | 8.6 | high | cisco / unified communications manager | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Sess | 94d ago |
| CVE-2026-54420exploited | 8.5 | high | litespeedtech / litespeed cpanel plugin | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks p | 84d ago |
| CVE-2026-55255exploited | 8.4 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2025-48595exploited | 8.4 | high | google / android | In multiple locations, there is a possible way to achieve code execution due to an integer overflow. | 96d ago |
| CVE-2026-42897exploited | 8.1 | high | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 114d ago |
| CVE-2026-53362exploited | 7.8 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocat | 63d ago |
| CVE-2026-20245exploited | 7.8 | high | cisco / catalyst sd-wan manager | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Mana | 93d ago |
| CVE-2026-41091exploited | 7.8 | high | microsoft / malware protection engine | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker | 108d ago |
| CVE-2026-28318exploited | 7.5 | high | solarwinds / serv-u | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authenti | 93d ago |