| CVE-2026-59734 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 93d ago |
| CVE-2026-58378 | 8.8 | — | — | — | — | Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. | 93d ago |
| CVE-2026-4275 | 8.8 | — | — | — | — | The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Requ | 93d ago |
| CVE-2026-47830 | 8.8 | — | — | — | — | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-priv | 93d ago |
| CVE-2026-47828 | 8.8 | — | — | — | cloudfoundry / bosh cli | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to th | 93d ago |
| CVE-2026-5523 | 8.8 | — | — | — | — | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, | 93d ago |
| CVE-2026-59723 | 8.8 | — | — | — | cline / cline | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. | 93d ago |
| CVE-2026-15133 | 8.8 | — | — | — | google / chrome | Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arb | 93d ago |
| CVE-2026-15132 | 8.8 | — | — | — | google / chrome | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-15129 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit | 93d ago |
| CVE-2026-15126 | 8.8 | — | — | — | google / chrome | Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-15125 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execut | 93d ago |
| CVE-2026-15123 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentia | 93d ago |
| CVE-2026-15121 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary c | 93d ago |
| CVE-2026-15118 | 8.8 | — | — | — | google / chrome | Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-15116 | 8.8 | — | — | — | google / chrome | Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-15114 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to poten | 93d ago |
| CVE-2026-15112 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit | 93d ago |
| CVE-2026-15110 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to | 93d ago |
| CVE-2026-15107 | 8.8 | — | — | — | google / chrome | Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrar | 93d ago |
| CVE-2026-10037 | 8.8 | — | — | — | — | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. | 94d ago |
| CVE-2026-58253 | 8.8 | — | — | — | linuxfoundation / nats-server | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. | 94d ago |
| CVE-2026-60102 | 8.8 | — | — | — | — | Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_S | 94d ago |
| CVE-2026-15067 | 8.8 | — | — | — | — | Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL inje | 94d ago |
| CVE-2026-59257 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the leg | 94d ago |
| CVE-2026-56086 | 8.8 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 94d ago |
| CVE-2026-14495 | 8.8 | — | — | — | — | The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in al | 94d ago |
| CVE-2026-14489 | 8.8 | — | — | — | — | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation | 94d ago |
| CVE-2026-14482 | 8.8 | — | — | — | — | The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. | 94d ago |
| CVE-2026-14158 | 8.8 | — | — | — | — | The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc | 94d ago |
| CVE-2026-14380 | 8.8 | — | — | — | perl / dbi | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. | 94d ago |
| CVE-2026-48958 | 8.8 | — | — | — | joomla / joomla\! | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | 95d ago |
| CVE-2026-48957 | 8.8 | — | — | — | joomla / joomla\! | An improper access check allows unauthorized users to access com_privacy datasets. | 95d ago |
| CVE-2026-48948 | 8.8 | — | — | — | joomla / joomla\! | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | 95d ago |
| CVE-2026-23697 | 8.8 | — | — | — | — | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to ac | 95d ago |
| CVE-2026-44938 | 8.8 | — | — | — | — | A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys f | 95d ago |
| CVE-2026-13696 | 8.8 | — | — | — | — | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc | 95d ago |
| CVE-2026-14474 | 8.8 | — | — | — | — | A flaw was found in SSSD's LDAP sudo provider. | 95d ago |
| CVE-2026-11610 | 8.8 | — | — | — | — | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). | 95d ago |
| CVE-2026-34158 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-42200 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-42143 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-34168 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-34152 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-34058 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-34057 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-34035 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-34034 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 95d ago |
| CVE-2026-42204 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 96d ago |
| CVE-2026-42153 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 96d ago |
| CVE-2026-34599 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 96d ago |
| CVE-2026-34153 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 96d ago |
| CVE-2026-25268 | 8.8 | — | — | — | qualcomm / wsa8835 firmware | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | 96d ago |
| CVE-2026-14536 | 8.8 | — | — | — | devolutions / devolutions server | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an | 96d ago |
| CVE-2026-46590 | 8.8 | — | — | — | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. | 96d ago |
| CVE-2026-11962 | 8.8 | — | — | — | — | The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management | 96d ago |
| CVE-2026-11855 | 8.8 | — | — | — | — | The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests wh | 96d ago |
| CVE-2026-10830 | 8.8 | — | — | — | — | The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-reg | 96d ago |
| CVE-2026-9085 | 8.8 | — | — | — | — | Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Soft | 97d ago |
| CVE-2026-14721 | 8.8 | — | — | — | — | A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 97d ago |