| CVE-2026-41052 | 8.8 | — | — | — | suse / rancher | Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher vers | 103d ago |
| CVE-2026-13749 | 8.8 | — | — | — | snowflake / snowflake cli | Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to | 103d ago |
| CVE-2026-13583 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax EW-7478APC 1.04. | 103d ago |
| CVE-2026-13582 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7478APC 1.04. | 103d ago |
| CVE-2026-13580 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax EW-7478APC 1.04. | 103d ago |
| CVE-2026-55607 | 8.8 | — | — | — | anthropic / claude code | Claude Code is an agentic coding tool. | 103d ago |
| CVE-2026-40521 | 8.8 | — | — | — | — | FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows | 103d ago |
| CVE-2026-12856 | 8.8 | — | — | — | redhat / openshift dev spaces | A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. | 103d ago |
| CVE-2026-13564 | 8.8 | — | — | — | — | A vulnerability was found in Edimax EW-7478APC 1.04. | 103d ago |
| CVE-2026-13563 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax EW-7478APC 1.04. | 103d ago |
| CVE-2026-13562 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7478APC 1.04. | 103d ago |
| CVE-2026-25707 | 8.8 | — | — | — | opensuse / libzypp | A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used | 103d ago |
| CVE-2026-13545 | 8.8 | — | — | — | dlink / dcs-935l firmware | A vulnerability has been found in D-Link DCS-935L 1.10.01. | 103d ago |
| CVE-2026-13539 | 8.8 | — | — | — | — | A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. | 103d ago |
| CVE-2026-13519 | 8.8 | — | — | — | — | A vulnerability was found in Tenda JD12L 16.03.53.23. | 103d ago |
| CVE-2026-13518 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda JD12L 16.03.53.23. | 103d ago |
| CVE-2026-13517 | 8.8 | — | — | — | — | A flaw has been found in Tenda JD12L 16.03.53.23. | 103d ago |
| CVE-2026-13516 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda JD12L 16.03.53.23. | 104d ago |
| CVE-2026-13515 | 8.8 | — | — | — | — | A security vulnerability has been detected in Tenda JD12L 16.03.53.23. | 104d ago |
| CVE-2026-53322 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling fu | 106d ago |
| CVE-2026-53281 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or | 106d ago |
| CVE-2026-52784 | 8.8 | — | — | — | — | OpenProject is open-source, web-based project management software. | 106d ago |
| CVE-2026-32833 | 8.8 | — | — | — | — | Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows | 106d ago |
| CVE-2026-57518 | 8.8 | — | — | — | — | Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: m | 106d ago |
| CVE-2026-57659 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 version | 106d ago |
| CVE-2026-57527 | 8.8 | — | — | — | — | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that a | 106d ago |
| CVE-2026-56773 | 8.8 | — | — | — | — | Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to | 106d ago |
| CVE-2026-56055 | 8.8 | — | — | — | — | Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. | 106d ago |
| CVE-2026-56038 | 8.8 | — | — | — | — | Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions. | 106d ago |
| CVE-2026-56010 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | 106d ago |
| CVE-2026-56008 | 8.8 | — | — | — | — | Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. | 106d ago |
| CVE-2025-68052 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. | 106d ago |
| CVE-2026-50741 | 8.8 | — | — | — | revive-adserver / revive adserver | Bypass to the fix for CVE-2026-34916. | 106d ago |
| CVE-2026-56768 | 8.8 | — | — | — | — | Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing u | 107d ago |
| CVE-2026-56767 | 8.8 | — | — | — | — | Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook | 107d ago |
| CVE-2026-56766 | 8.8 | — | — | — | — | Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, P | 107d ago |
| CVE-2026-55698 | 8.8 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 107d ago |
| CVE-2026-50016 | 8.8 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 107d ago |
| CVE-2026-56053 | 8.8 | — | — | — | — | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. | 107d ago |
| CVE-2026-53277 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table | 107d ago |
| CVE-2026-53275 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processin | 107d ago |
| CVE-2026-53266exploited | 8.8 | 0.83% | 3/3 | +85d | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite w | 107d ago |
| CVE-2026-53248 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata ds | 107d ago |
| CVE-2026-53240 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix use-after-free on first_skb i | 107d ago |
| CVE-2026-53232 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probin | 107d ago |
| CVE-2026-53200 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix handling of XN[0] when !FE | 107d ago |
| CVE-2026-53198 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_l | 107d ago |
| CVE-2026-53188 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_ | 107d ago |
| CVE-2026-53171 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix arithmetic issues in dma_len | 107d ago |
| CVE-2026-53170 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uniniti | 107d ago |
| CVE-2026-53159 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due | 107d ago |
| CVE-2026-5305 | 8.8 | — | — | — | — | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does | 107d ago |
| CVE-2026-12244 | 8.8 | — | — | — | nlnetlabs / nsd | If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS | 107d ago |
| CVE-2026-9155 | 8.8 | — | — | — | gnu / sed | OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to e | 107d ago |
| CVE-2026-9787 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-9786 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-9785 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-9784 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-9783 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-9782 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. | 108d ago |