| CVE-2026-8365 | 8.8 | — | — | — | — | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blo | 123d ago |
| CVE-2026-11616 | 8.8 | — | — | — | — | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to | 123d ago |
| CVE-2026-11572 | 8.8 | — | — | — | — | Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to | 123d ago |
| CVE-2026-11699 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potential | 124d ago |
| CVE-2026-11698 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potential | 124d ago |
| CVE-2026-11688 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute | 124d ago |
| CVE-2026-11687 | 8.8 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially ex | 124d ago |
| CVE-2026-11683 | 8.8 | — | — | — | google / chrome | Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrar | 124d ago |
| CVE-2026-11681 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially | 124d ago |
| CVE-2026-11680 | 8.8 | — | — | — | google / chrome | Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute a | 124d ago |
| CVE-2026-11674 | 8.8 | — | — | — | google / chrome | Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra | 124d ago |
| CVE-2026-11673 | 8.8 | — | — | — | google / chrome | Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arb | 124d ago |
| CVE-2026-11670 | 8.8 | — | — | — | google / chrome | Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code | 124d ago |
| CVE-2026-11664 | 8.8 | — | — | — | google / chrome | Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially explo | 124d ago |
| CVE-2026-11662 | 8.8 | — | — | — | google / chrome | Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary | 124d ago |
| CVE-2026-11657 | 8.8 | — | — | — | google / chrome | Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute ar | 124d ago |
| CVE-2026-11650 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code | 124d ago |
| CVE-2026-11649 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code | 124d ago |
| CVE-2026-11648 | 8.8 | — | — | — | google / chrome | Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to pote | 124d ago |
| CVE-2026-11646 | 8.8 | — | — | — | google / chrome | Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute ar | 124d ago |
| CVE-2026-11645zero day | 8.8 | 2.4% | 3/3 | 1d before | google / chrome | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a | 124d ago |
| CVE-2026-11637 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbit | 124d ago |
| CVE-2026-11633 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute a | 124d ago |
| CVE-2026-11630 | 8.8 | — | — | — | google / chrome | Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exp | 124d ago |
| CVE-2026-11629 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit | 124d ago |
| CVE-2026-46490 | 8.8 | — | — | — | samlify project / samlify | samlify is a Node.js library for SAML single sign-on. | 124d ago |
| CVE-2026-11557 | 8.8 | — | — | — | — | A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. | 124d ago |
| CVE-2026-11556 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. | 124d ago |
| CVE-2026-11553 | 8.8 | — | — | — | — | A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. | 124d ago |
| CVE-2026-39910 | 8.8 | — | — | — | — | STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged at | 124d ago |
| CVE-2026-25856 | 8.8 | — | — | — | — | OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authen | 124d ago |
| CVE-2026-25855 | 8.8 | — | — | — | — | OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users t | 124d ago |
| CVE-2026-25559 | 8.8 | — | — | — | — | OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows aut | 124d ago |
| CVE-2026-46656 | 8.8 | — | — | — | — | Bludit is a content management system. | 124d ago |
| CVE-2026-46480 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 124d ago |
| CVE-2026-46479 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 124d ago |
| CVE-2026-46478 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 124d ago |
| CVE-2026-46477 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 124d ago |
| CVE-2026-46476 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 124d ago |
| CVE-2026-46475 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 124d ago |
| CVE-2026-46444 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 124d ago |
| CVE-2026-11528 | 8.8 | — | — | — | — | A vulnerability was found in Tenda AC18 15.03.05.05. | 124d ago |
| CVE-2026-11524 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda W20E 15.11.0.6. | 124d ago |
| CVE-2026-11523 | 8.8 | — | — | — | — | A flaw has been found in Tenda W20E 15.11.0.6. | 124d ago |
| CVE-2026-11522 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda W20E 15.11.0.6. | 124d ago |
| CVE-2026-11517 | 8.8 | — | — | — | — | A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. | 124d ago |
| CVE-2026-11504 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda CX12L 16.03.53.12. | 124d ago |
| CVE-2026-11503 | 8.8 | — | — | — | — | A security vulnerability has been detected in Tenda CX12L 16.03.53.12. | 124d ago |
| CVE-2026-11498 | 8.8 | — | — | — | — | A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. | 124d ago |
| CVE-2026-11413 | 8.8 | — | — | — | — | A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. | 126d ago |
| CVE-2026-7654 | 8.8 | — | — | — | — | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in ve | 127d ago |
| CVE-2026-11419 | 8.8 | — | — | — | altium / on-prem enterprise server | A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improp | 127d ago |
| CVE-2026-5415 | 8.8 | — | — | — | — | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin fo | 127d ago |
| CVE-2026-5411 | 8.8 | — | — | — | — | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin fo | 127d ago |
| CVE-2026-50733 | 8.8 | — | — | — | — | Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eva | 127d ago |
| CVE-2026-49493 | 8.8 | — | — | — | — | Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the | 127d ago |
| CVE-2026-49492 | 8.8 | — | — | — | — | Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does n | 127d ago |
| CVE-2026-48095 | 8.8 | — | — | — | 7-zip / 7-zip | 7-Zip is a file archiver with a high compression ratio. | 127d ago |
| CVE-2026-21837 | 8.8 | — | — | — | hcltech / digital experience | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. | 127d ago |
| CVE-2026-11307 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 128d ago |