| CVE-2026-42850 | 8.8 | — | — | — | kovidgoyal / kitty | Kitty is a cross-platform GPU based terminal. | 120d ago |
| CVE-2026-42947 | 8.8 | — | — | — | — | A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to si | 120d ago |
| CVE-2026-12043 | 8.8 | — | — | — | — | Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a r | 120d ago |
| CVE-2026-7387 | 8.8 | — | — | — | mattermost / mattermost server | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails t | 120d ago |
| CVE-2026-45833 | 8.8 | — | — | — | trychroma / chromadb | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated a | 120d ago |
| CVE-2026-45832 | 8.8 | — | — | — | trychroma / chromadb | All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the author | 120d ago |
| CVE-2026-45831 | 8.8 | — | — | — | trychroma / chromadb | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python proje | 120d ago |
| CVE-2026-45830 | 8.8 | — | — | — | trychroma / chromadb | A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authentica | 120d ago |
| CVE-2026-12059 | 8.8 | — | — | — | — | The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenti | 120d ago |
| CVE-2026-45170 | 8.8 | — | — | — | paloaltonetworks / idira privilege cloud connector | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration sce | 121d ago |
| CVE-2026-11933 | 8.8 | — | — | — | mongodb / mongodb | A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON docum | 121d ago |
| CVE-2026-45418 | 8.8 | — | — | — | — | ClipBucket v5 is an open source video sharing platform. | 121d ago |
| CVE-2026-45172 | 8.8 | — | — | — | paloaltonetworks / idira privileged session manager for ssh | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14 | 121d ago |
| CVE-2026-45171 | 8.8 | — | — | — | paloaltonetworks / idira privileged session manager | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager ( | 121d ago |
| CVE-2026-12035 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potential | 121d ago |
| CVE-2026-12020 | 8.8 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentiall | 121d ago |
| CVE-2026-12018 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker | 121d ago |
| CVE-2026-12007 | 8.8 | — | — | — | google / chrome | Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute ar | 121d ago |
| CVE-2026-53819 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspac | 121d ago |
| CVE-2026-53817 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers | 121d ago |
| CVE-2026-53811 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows | 121d ago |
| CVE-2026-53810 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can | 121d ago |
| CVE-2026-53807 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that all | 121d ago |
| CVE-2026-53806 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to | 121d ago |
| CVE-2026-47162 | 8.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 121d ago |
| CVE-2026-46519 | 8.8 | — | — | — | — | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. | 121d ago |
| CVE-2025-24284 | 8.8 | — | — | — | apple / macos | This issue was addressed with improved checks to prevent unauthorized actions. | 121d ago |
| CVE-2026-7870 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. | 121d ago |
| CVE-2026-50223 | 8.8 | — | — | — | apache / ofbiz | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged au | 122d ago |
| CVE-2026-47342 | 8.8 | — | — | — | apache / ofbiz | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher p | 122d ago |
| CVE-2026-44693 | 8.8 | — | — | — | — | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. | 122d ago |
| CVE-2026-42305 | 8.8 | — | — | — | — | Dulwich is a pure-Python implementation of the Git file formats and protocols. | 122d ago |
| CVE-2026-46612 | 8.8 | — | — | — | — | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and | 122d ago |
| CVE-2026-20251 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3. | 122d ago |
| CVE-2026-45564 | 8.8 | — | — | — | — | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. | 122d ago |
| CVE-2026-53435exploited | 8.8 | 2.2% | 1/3 | +5d | jenkins / jenkins | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize ar | 122d ago |
| CVE-2026-52758 | 8.8 | — | — | — | nsa / ghidra | Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied valu | 122d ago |
| CVE-2026-52754 | 8.8 | — | — | — | nsa / ghidra | Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that | 122d ago |
| CVE-2026-52751 | 8.8 | — | — | — | nsa / ghidra | Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection c | 122d ago |
| CVE-2026-49498 | 8.8 | — | — | — | nsa / ghidra | Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionD | 122d ago |
| CVE-2026-8071 | 8.8 | — | — | — | — | The Anti-Spam by CleanTalk. | 122d ago |
| CVE-2025-58468 | 8.8 | — | — | — | qnap / notification center | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. | 122d ago |
| CVE-2026-47932 | 8.8 | — | — | — | adobe / coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 123d ago |
| CVE-2026-36723 | 8.8 | — | — | — | — | An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated | 123d ago |
| CVE-2026-50636 | 8.8 | — | — | — | — | The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array in | 123d ago |
| CVE-2026-50635 | 8.8 | — | — | — | — | LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it | 123d ago |
| CVE-2026-9211 | 8.8 | — | — | — | netgear / cax30 firmware | An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its op | 123d ago |
| CVE-2026-49959 | 8.8 | — | — | — | — | Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated atta | 123d ago |
| CVE-2026-47653 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 123d ago |
| CVE-2026-47289 | 8.8 | — | — | — | microsoft / windows app | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 123d ago |
| CVE-2026-45648 | 8.8 | — | — | — | microsoft / windows server 2022 | Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over | 123d ago |
| CVE-2026-45504 | 8.8 | — | — | — | microsoft / exchange server | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privilege | 123d ago |
| CVE-2026-45484 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileg | 123d ago |
| CVE-2026-45447 | 8.8 | — | — | — | openssl / openssl | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 si | 123d ago |
| CVE-2026-42985 | 8.8 | — | — | — | microsoft / remote desktop client | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 123d ago |
| CVE-2026-40371 | 8.8 | — | — | — | microsoft / dynamics 365 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an auth | 123d ago |
| CVE-2026-32193 | 8.8 | — | — | — | microsoft / azure kubernetes service | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Servi | 123d ago |
| CVE-2026-46317 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind | 123d ago |
| CVE-2026-46748 | 8.8 | — | — | — | siemens / sinec ins | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). | 123d ago |
| CVE-2026-46746 | 8.8 | — | — | — | siemens / sinec ins | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). | 123d ago |