| CVE-2026-15429 | 8.8 | — | — | — | tp-link / archer vx1800v firmware | A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. | 88d ago |
| CVE-2026-15428 | 8.8 | — | — | — | tp-link / archer vx1800v firmware | An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the dom | 88d ago |
| CVE-2026-15696 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. | 88d ago |
| CVE-2026-15695 | 8.8 | — | — | — | — | A flaw has been found in Tenda BE12 Pro 16.03.66.23. | 88d ago |
| CVE-2026-15694 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. | 88d ago |
| CVE-2026-15693 | 8.8 | — | — | — | — | A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. | 88d ago |
| CVE-2026-15692 | 8.8 | — | — | — | — | A weakness has been identified in Tenda BE12 Pro 16.03.66.23. | 88d ago |
| CVE-2026-15691 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. | 88d ago |
| CVE-2026-57856 | 8.8 | — | — | — | — | Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). | 88d ago |
| CVE-2026-57855 | 8.8 | — | — | — | — | Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). | 88d ago |
| CVE-2026-62200 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext trans | 89d ago |
| CVE-2026-62199 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter star | 89d ago |
| CVE-2026-62194 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install command | 89d ago |
| CVE-2026-62190 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows l | 89d ago |
| CVE-2026-55773 | 8.8 | — | — | — | — | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization | 89d ago |
| CVE-2026-55771 | 8.8 | — | — | — | — | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization | 89d ago |
| CVE-2026-55772 | 8.8 | — | — | — | — | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization | 89d ago |
| CVE-2026-49972 | 8.8 | — | — | — | — | Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achiev | 89d ago |
| CVE-2026-49970 | 8.8 | — | — | — | — | Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that al | 89d ago |
| CVE-2026-61463 | 8.8 | — | — | — | — | Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated user | 89d ago |
| CVE-2026-57786 | 8.8 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication | 89d ago |
| CVE-2026-57713 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Objec | 89d ago |
| CVE-2026-57410 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalati | 89d ago |
| CVE-2026-57386 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue | 89d ago |
| CVE-2026-57371 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This i | 89d ago |
| CVE-2026-15548 | 8.8 | — | — | — | — | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. | 89d ago |
| CVE-2026-15545 | 8.8 | — | — | — | — | A vulnerability was identified in Shibby Tomato up to 1.28.0000. | 89d ago |
| CVE-2026-15544 | 8.8 | — | — | — | — | A vulnerability was determined in Shibby Tomato up to 1.28.0000. | 89d ago |
| CVE-2026-15543 | 8.8 | — | — | — | — | A vulnerability was found in Tenda CH22 1.0.0.1. | 89d ago |
| CVE-2026-61876 | 8.8 | — | — | — | — | LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent | 90d ago |
| CVE-2026-61875 | 8.8 | — | — | — | — | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inje | 90d ago |
| CVE-2026-59260 | 8.8 | — | — | — | — | OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated u | 90d ago |
| CVE-2026-15484 | 8.8 | — | — | — | — | A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. | 90d ago |
| CVE-2026-15483 | 8.8 | — | — | — | — | A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. | 90d ago |
| CVE-2026-15481 | 8.8 | — | — | — | — | A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. | 90d ago |
| CVE-2026-15480 | 8.8 | — | — | — | — | A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. | 90d ago |
| CVE-2026-57828 | 8.8 | — | — | — | phoca / download | Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extensio | 91d ago |
| CVE-2026-1359 | 8.8 | — | — | — | — | The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data | 91d ago |
| CVE-2026-15155 | 8.8 | — | — | — | — | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to A | 91d ago |
| CVE-2025-6784 | 8.8 | — | — | — | — | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0 | 91d ago |
| CVE-2026-2354 | 8.8 | — | — | — | — | The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type vali | 91d ago |
| CVE-2026-14262 | 8.8 | — | — | — | — | The Simple JWT Login – Allows you to use JWT on REST endpoints. | 91d ago |
| CVE-2026-13353 | 8.8 | — | — | — | — | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable t | 91d ago |
| CVE-2026-13756 | 8.8 | — | — | — | — | The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin | 91d ago |
| CVE-2026-44795 | 8.8 | — | — | — | linuxfoundation / spinnaker | Spinnaker is an open source, multi-cloud continuous delivery platform. | 92d ago |
| CVE-2026-57215 | 8.8 | — | — | — | broadcom / rabbitmq server | RabbitMQ is a messaging and streaming broker. | 92d ago |
| CVE-2026-6212 | 8.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. | 92d ago |
| CVE-2026-61461 | 8.8 | — | — | — | dify / dify | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows atta | 92d ago |
| CVE-2026-61460 | 8.8 | — | — | — | — | Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonContr | 92d ago |
| CVE-2025-30007 | 8.8 | — | — | — | hestiacp / control panel | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authe | 92d ago |
| CVE-2026-2398 | 8.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. | 92d ago |
| CVE-2026-54149 | 8.8 | — | — | — | — | MaxKB is an open-source AI assistant for enterprise. | 92d ago |
| CVE-2026-61434 | 8.8 | — | — | — | — | PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows | 92d ago |
| CVE-2026-59793 | 8.8 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | 92d ago |
| CVE-2026-54469 | 8.8 | — | — | — | dell / unisphere for powermax | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnera | 92d ago |
| CVE-2026-15070 | 8.8 | — | — | — | — | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve | 92d ago |
| CVE-2026-58143 | 8.8 | — | — | — | — | Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated a | 93d ago |
| CVE-2026-55207 | 8.8 | — | — | — | — | Pimcore is an Open Source Data & Experience Management Platform. | 93d ago |
| CVE-2026-59148 | 8.8 | — | — | — | — | Mockoon provides way to design and run mock APIs. | 93d ago |
| CVE-2026-13492 | 8.8 | — | — | — | — | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65 | 93d ago |