| CVE-2026-9781 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-9780 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. | 108d ago |
| CVE-2026-7570 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-7569 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. | 108d ago |
| CVE-2026-9773 | 8.8 | — | — | — | unraid / unraid | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-9772 | 8.8 | — | — | — | unraid / unraid | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. | 108d ago |
| CVE-2026-52800 | 8.8 | — | — | — | — | Gogs is an open source self-hosted Git service. | 108d ago |
| CVE-2026-49247 | 8.8 | — | — | — | — | Jellyfin is an open source self hosted media server. | 108d ago |
| CVE-2026-48793 | 8.8 | — | — | — | — | Jellyfin is an open source self hosted media server. | 108d ago |
| CVE-2026-13038 | 8.8 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execut | 108d ago |
| CVE-2026-13036 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary co | 108d ago |
| CVE-2026-13035 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute a | 108d ago |
| CVE-2026-13033 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote att | 108d ago |
| CVE-2026-13031 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary co | 108d ago |
| CVE-2026-13027 | 8.8 | — | — | — | google / chrome | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exp | 108d ago |
| CVE-2026-13026 | 8.8 | — | — | — | google / chrome | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to | 108d ago |
| CVE-2026-48732 | 8.8 | — | — | — | — | Warp is an agentic development environment. | 108d ago |
| CVE-2026-48720 | 8.8 | — | — | — | — | Warp is an agentic development environment. | 108d ago |
| CVE-2026-48704 | 8.8 | — | — | — | — | Warp is an agentic development environment. | 108d ago |
| CVE-2026-53075 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for | 108d ago |
| CVE-2026-53072 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt | 108d ago |
| CVE-2026-53071 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2c | 108d ago |
| CVE-2026-53057 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Add IOTINVAL after updating DDT/P | 108d ago |
| CVE-2026-53053 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix clone_alias() to use the origin | 108d ago |
| CVE-2026-52968 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: fix GAIT table indexing due to | 108d ago |
| CVE-2026-52952 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain | 108d ago |
| CVE-2026-57301 | 8.8 | — | — | — | jenkins / official owasp zap | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the ass | 108d ago |
| CVE-2026-57296 | 8.8 | — | — | — | — | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom | 108d ago |
| CVE-2026-57280 | 8.8 | — | — | — | jenkins / script security | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied t | 108d ago |
| CVE-2026-56232 | 8.8 | — | — | — | — | Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-l | 108d ago |
| CVE-2026-12242 | 8.8 | — | — | — | — | The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and in | 108d ago |
| CVE-2026-7761 | 8.8 | — | — | — | — | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in al | 108d ago |
| CVE-2026-52934 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packet | 108d ago |
| CVE-2026-52918 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_p | 108d ago |
| CVE-2026-4297 | 8.8 | — | — | — | — | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up t | 108d ago |
| CVE-2026-54639 | 8.8 | — | — | — | — | Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability start | 108d ago |
| CVE-2026-41862 | 8.8 | — | — | — | — | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted st | 109d ago |
| CVE-2026-56115 | 8.8 | — | — | — | bootimus / bootimus | Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged us | 109d ago |
| CVE-2026-44959 | 8.8 | — | — | — | — | A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. | 109d ago |
| CVE-2026-44790 | 8.8 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 109d ago |
| CVE-2026-34916 | 8.8 | — | — | — | — | A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could all | 109d ago |
| CVE-2026-33760 | 8.8 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 109d ago |
| CVE-2026-35018 | 8.8 | — | — | — | — | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulner | 109d ago |
| CVE-2026-10711 | 8.8 | — | — | — | — | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Tr | 109d ago |
| CVE-2026-8163 | 8.8 | — | — | — | — | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before us | 109d ago |
| CVE-2026-54232 | 8.8 | — | — | — | vllm / vllm | vLLM is an inference and serving engine for large language models (LLMs). | 110d ago |
| CVE-2026-44272 | 8.8 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elemen | 110d ago |
| CVE-2026-50178 | 8.8 | — | — | — | angular / angular language service | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. | 110d ago |
| CVE-2026-49241 | 8.8 | — | — | — | angular / angular language service | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. | 110d ago |
| CVE-2026-56425 | 8.8 | — | — | — | misp-project / misp | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 auth | 110d ago |
| CVE-2026-56424 | 8.8 | — | — | — | misp-project / misp | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wro | 110d ago |
| CVE-2026-56423 | 8.8 | — | — | — | misp-project / misp | MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. | 110d ago |
| CVE-2026-54099 | 8.8 | — | — | — | redhat / openshift container platform | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. | 110d ago |
| CVE-2026-8157 | 8.8 | — | — | — | — | The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating n | 110d ago |
| CVE-2026-12806 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax BR-6478AC V2 1.23. | 111d ago |
| CVE-2026-56396 | 8.8 | — | — | — | — | phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoint | 111d ago |
| CVE-2026-52911 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound s | 111d ago |
| CVE-2026-56340 | 8.8 | — | — | — | vllm / vllm | vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. | 112d ago |
| CVE-2026-56216 | 8.8 | — | — | — | — | Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that all | 112d ago |
| CVE-2026-47645 | 8.8 | — | — | — | microsoft / 365 copilot | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorize | 113d ago |