| CVE-2026-14535 | 8.8 | — | — | — | trailofbits / fickling | In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally c | 98d ago |
| CVE-2026-14534 | 8.8 | — | — | — | trailofbits / fickling | Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _pos | 98d ago |
| CVE-2026-53360 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB | 98d ago |
| CVE-2026-53359 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due | 98d ago |
| CVE-2025-71380 | 8.8 | — | — | — | — | The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where | 98d ago |
| CVE-2026-57981 | 8.8 | — | — | — | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 99d ago |
| CVE-2026-57974 | 8.8 | — | — | — | microsoft / edge chromium | Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code | 99d ago |
| CVE-2026-56645 | 8.8 | — | — | — | microsoft / edge chromium | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over | 99d ago |
| CVE-2026-27775 | 8.8 | — | — | — | — | Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session | 99d ago |
| CVE-2026-14460 | 8.8 | — | — | — | — | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software all | 99d ago |
| CVE-2026-14459 | 8.8 | — | — | — | — | Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM | 99d ago |
| CVE-2026-10054 | 8.8 | — | — | — | — | In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over | 99d ago |
| CVE-2026-8247 | 8.8 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same lo | 99d ago |
| CVE-2026-54998 | 8.8 | — | — | — | microsoft / exchange online | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a ne | 100d ago |
| CVE-2026-59093 | 8.8 | — | — | — | weaviate / weaviate | Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions g | 100d ago |
| CVE-2026-56841 | 8.8 | — | — | — | ui / unifi protect | A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulne | 100d ago |
| CVE-2026-55114 | 8.8 | — | — | — | ui / unifi network application | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi | 100d ago |
| CVE-2026-54404 | 8.8 | — | — | — | ui / unifi dream machine beast firmware | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Inject | 100d ago |
| CVE-2026-53358 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close chan | 100d ago |
| CVE-2026-57766 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. | 100d ago |
| CVE-2026-57759 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. | 100d ago |
| CVE-2026-56037 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. | 100d ago |
| CVE-2026-27414 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. | 100d ago |
| CVE-2026-27060 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. | 100d ago |
| CVE-2026-13125 | 8.8 | — | — | — | — | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that | 100d ago |
| CVE-2026-14432 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 101d ago |
| CVE-2026-14431 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 101d ago |
| CVE-2026-14430 | 8.8 | — | — | — | google / chrome | Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code | 101d ago |
| CVE-2026-14422 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia | 101d ago |
| CVE-2026-14415 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced | 101d ago |
| CVE-2026-14407 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar | 101d ago |
| CVE-2026-14403 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 101d ago |
| CVE-2026-14395 | 8.8 | — | — | — | google / chrome | Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary c | 101d ago |
| CVE-2026-14394 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap | 101d ago |
| CVE-2026-14393 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 101d ago |
| CVE-2026-14385 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform | 101d ago |
| CVE-2026-14383 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar | 101d ago |
| CVE-2026-58452 | 8.8 | — | — | — | — | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability | 101d ago |
| CVE-2026-57516 | 8.8 | — | — | — | anyscale / ray | Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attacker | 101d ago |
| CVE-2026-34105 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php | 101d ago |
| CVE-2026-34104 | 8.8 | — | — | — | — | Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (lin | 101d ago |
| CVE-2026-34103 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line | 101d ago |
| CVE-2026-34102 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (l | 101d ago |
| CVE-2026-34101 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line | 101d ago |
| CVE-2026-34100 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17) | 101d ago |
| CVE-2026-8857 | 8.8 | — | — | — | mediawiki / mediawiki | A vulnerability in Wikimedia Foundation timeline. | 101d ago |
| CVE-2026-13706 | 8.8 | — | — | — | mediawiki / mediawiki | Improper input validation vulnerability in Wikimedia Foundation UrlShortener. | 101d ago |
| CVE-2026-5136 | 8.8 | — | — | — | redhat / satellite | A flaw was found in Foreman. | 101d ago |
| CVE-2026-53354 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various | 101d ago |
| CVE-2026-13228 | 8.8 | — | — | — | — | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privileg | 101d ago |
| CVE-2026-12224 | 8.8 | — | — | — | — | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in | 101d ago |
| CVE-2026-12158 | 8.8 | — | — | — | — | The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Fo | 101d ago |
| CVE-2026-7838 | 8.8 | — | — | — | uvnc / ultravnc | UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol | 101d ago |
| CVE-2026-53488 | 8.8 | — | — | — | linuxfoundation / containerd | containerd is an open-source container runtime. | 101d ago |
| CVE-2026-57995 | 8.8 | — | — | — | — | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that all | 102d ago |
| CVE-2026-56247 | 8.8 | — | — | — | — | Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope | 102d ago |
| CVE-2026-56230 | 8.8 | — | — | — | — | Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts t | 102d ago |
| CVE-2026-14149 | 8.8 | — | — | — | google / chrome | Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbi | 102d ago |
| CVE-2026-14108 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary co | 102d ago |
| CVE-2026-14107 | 8.8 | — | — | — | google / chrome | Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrar | 102d ago |