| CVE-2026-32208 | 8.8 | — | — | — | microsoft / edge chromium | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows | 113d ago |
| CVE-2026-48715 | 8.8 | — | — | — | radvd.litech / radvd | radvd is a router advertisement daemon for IPv6. | 113d ago |
| CVE-2019-25758 | 8.8 | — | — | — | wdmtech / vbizz | Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attacke | 113d ago |
| CVE-2026-39998 | 8.8 | — | — | — | apache / apisix | Improper Input Validation vulnerability in Apache APISIX. | 113d ago |
| CVE-2026-12044 | 8.8 | — | — | — | pgadmin / pgadmin 4 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... | 114d ago |
| CVE-2026-56078 | 8.8 | — | — | — | — | PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent | 114d ago |
| CVE-2026-56075 | 8.8 | — | — | — | — | PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode | 114d ago |
| CVE-2026-55237 | 8.8 | — | — | — | — | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence | 114d ago |
| CVE-2026-54104 | 8.8 | — | — | — | — | The U.S. | 114d ago |
| CVE-2026-46580 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace wer | 114d ago |
| CVE-2026-44691 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. | 114d ago |
| CVE-2026-44688 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part | 114d ago |
| CVE-2026-8461 | 8.8 | — | — | — | — | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows d | 114d ago |
| CVE-2026-55741 | 8.8 | — | — | — | — | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration c | 114d ago |
| CVE-2026-9860 | 8.8 | — | — | — | — | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in al | 114d ago |
| CVE-2026-12407 | 8.8 | — | — | — | — | The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions | 114d ago |
| CVE-2025-71322 | 8.8 | — | — | — | — | PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to | 115d ago |
| CVE-2026-35065 | 8.8 | — | — | — | dell / powerflex manager | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vul | 115d ago |
| CVE-2026-55738 | 8.8 | — | — | — | — | A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. | 115d ago |
| CVE-2025-69130 | 8.8 | — | — | — | — | Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. | 115d ago |
| CVE-2025-66391 | 8.8 | — | — | — | — | In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for w | 115d ago |
| CVE-2026-54805 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. | 115d ago |
| CVE-2026-42629 | 8.8 | — | — | — | — | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. | 115d ago |
| CVE-2026-22342 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. | 115d ago |
| CVE-2026-12466 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to ex | 115d ago |
| CVE-2026-12452 | 8.8 | — | — | — | google / chrome | Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to poten | 115d ago |
| CVE-2026-12448 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attac | 115d ago |
| CVE-2026-12447 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbit | 115d ago |
| CVE-2026-12443 | 8.8 | — | — | — | google / chrome | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute | 115d ago |
| CVE-2026-12442 | 8.8 | — | — | — | google / chrome | Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execu | 115d ago |
| CVE-2026-12441 | 8.8 | — | — | — | google / chrome | Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potent | 115d ago |
| CVE-2026-12439 | 8.8 | — | — | — | google / chrome | Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potent | 115d ago |
| CVE-2026-12256 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Avada <= 3.15.3 versions. | 115d ago |
| CVE-2026-12165 | 8.8 | — | — | — | — | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to | 115d ago |
| CVE-2025-69138 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Genemy <= 1.6.6 versions. | 115d ago |
| CVE-2025-59563 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions. | 115d ago |
| CVE-2026-46973 | 8.8 | — | — | — | oracle / outsourced manufacturing for discrete industries | Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: | 115d ago |
| CVE-2026-46972 | 8.8 | — | — | — | oracle / outsourced manufacturing for discrete industries | Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: | 115d ago |
| CVE-2026-46967 | 8.8 | — | — | — | oracle / public sector financials | Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component | 115d ago |
| CVE-2026-46965 | 8.8 | — | — | — | oracle / universal work queue | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site | 115d ago |
| CVE-2026-46962 | 8.8 | — | — | — | oracle / project portfolio analysis | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Ope | 115d ago |
| CVE-2026-46961 | 8.8 | — | — | — | oracle / project portfolio analysis | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Ope | 115d ago |
| CVE-2026-46952 | 8.8 | — | — | — | oracle / quality | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). | 115d ago |
| CVE-2026-46951 | 8.8 | — | — | — | oracle / quality | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). | 115d ago |
| CVE-2026-46950 | 8.8 | — | — | — | oracle / advanced outbound telephony | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Op | 115d ago |
| CVE-2026-46947 | 8.8 | — | — | — | oracle / advanced outbound telephony | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Op | 115d ago |
| CVE-2026-46942 | 8.8 | — | — | — | oracle / process manufacturing process planning | Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: | 115d ago |
| CVE-2026-46940 | 8.8 | — | — | — | oracle / cost management | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). | 115d ago |
| CVE-2026-46937 | 8.8 | — | — | — | oracle / isetup | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, | 115d ago |
| CVE-2026-46931 | 8.8 | — | — | — | oracle / enterprise asset management | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Op | 115d ago |
| CVE-2026-46929 | 8.8 | — | — | — | oracle / cost management | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). | 115d ago |
| CVE-2026-46928 | 8.8 | — | — | — | oracle / spares management | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). | 115d ago |
| CVE-2026-46926 | 8.8 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 115d ago |
| CVE-2026-46921 | 8.8 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 115d ago |
| CVE-2026-46916 | 8.8 | — | — | — | oracle / process manufacturing product development | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (componen | 115d ago |
| CVE-2026-46903 | 8.8 | — | — | — | oracle / jd edwards enterpriseone tools | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infras | 115d ago |
| CVE-2026-46886 | 8.8 | — | — | — | oracle / siebel apps - marketing | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). | 115d ago |
| CVE-2026-46885 | 8.8 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). | 115d ago |
| CVE-2026-46864 | 8.8 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agen | 115d ago |
| CVE-2026-46780 | 8.8 | — | — | — | oracle / webcenter content | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). | 115d ago |