| CVE-2026-73680 | 8.8 | — | — | — | — | Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows auth | 22d ago |
| CVE-2026-16879 | 8.8 | — | — | — | ibm / db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions | 22d ago |
| CVE-2026-19847 | 8.8 | — | — | — | — | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-19846 | 8.8 | — | — | — | — | A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-19679 | 8.8 | — | — | — | tenable / security center | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitizatio | 22d ago |
| CVE-2026-19635 | 8.8 | — | — | — | tenable / security center | A local privilege escalation vulnerability exists in Security Center. | 22d ago |
| CVE-2026-12366 | 8.8 | — | — | — | — | Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's stora | 22d ago |
| CVE-2026-19845 | 8.8 | — | — | — | — | A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-19844 | 8.8 | — | — | — | — | A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-73673 | 8.8 | — | — | — | — | Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unaut | 22d ago |
| CVE-2026-19824 | 8.8 | — | — | — | — | A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. | 22d ago |
| CVE-2026-19823 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. | 22d ago |
| CVE-2026-72837 | 8.8 | — | — | — | — | File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication au | 22d ago |
| CVE-2026-72833 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulne | 22d ago |
| CVE-2026-72831 | 8.8 | — | — | — | — | The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability | 22d ago |
| CVE-2026-72830 | 8.8 | — | — | — | — | Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, a | 22d ago |
| CVE-2026-72829 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersControlle | 22d ago |
| CVE-2026-72827 | 8.8 | — | — | — | — | Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that all | 22d ago |
| CVE-2026-72826 | 8.8 | — | — | — | — | The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are | 22d ago |
| CVE-2026-72824 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesControlle | 22d ago |
| CVE-2026-72822 | 8.8 | — | — | — | — | The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope cap | 22d ago |
| CVE-2026-72819 | 8.8 | — | — | — | — | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validati | 22d ago |
| CVE-2026-19822 | 8.8 | — | — | — | — | A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. | 22d ago |
| CVE-2026-19821 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. | 22d ago |
| CVE-2026-19815 | 8.8 | — | — | — | — | A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-19814 | 8.8 | — | — | — | — | A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-19813 | 8.8 | — | — | — | — | A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-19812 | 8.8 | — | — | — | — | A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 22d ago |
| CVE-2026-19811 | 8.8 | — | — | — | — | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 23d ago |
| CVE-2026-19792 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda G0 up to 20260625. | 23d ago |
| CVE-2026-19791 | 8.8 | — | — | — | — | A weakness has been identified in Tenda G0 up to 20260625. | 23d ago |
| CVE-2026-19790 | 8.8 | — | — | — | — | A vulnerability was identified in Tenda G0 up to 20260625. | 23d ago |
| CVE-2026-19789 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. | 23d ago |
| CVE-2026-19788 | 8.8 | — | — | — | — | A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. | 23d ago |
| CVE-2026-73841 | 8.8 | — | — | — | — | OpenChoreo is a complete, open-source developer platform for Kubernetes. | 23d ago |
| CVE-2026-73667 | 8.8 | — | — | — | — | OpenChoreo is a complete, open-source developer platform for Kubernetes. | 23d ago |
| CVE-2026-73305 | 8.8 | — | — | — | — | Budibase is an open-source low-code platform. | 23d ago |
| CVE-2026-72840 | 8.8 | — | — | — | — | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /e | 23d ago |
| CVE-2026-18101 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management o | 23d ago |
| CVE-2026-17481 | 8.8 | — | — | — | ibm / documentation offline | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to impro | 23d ago |
| CVE-2026-72642 | 8.8 | — | — | — | elastic / elasticsearch | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model | 23d ago |
| CVE-2026-17223 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer | 23d ago |
| CVE-2026-17029 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. | 23d ago |
| CVE-2026-16987 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation o | 23d ago |
| CVE-2026-16975 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-b | 23d ago |
| CVE-2026-16722 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to | 23d ago |
| CVE-2026-16674 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untru | 23d ago |
| CVE-2026-18428 | 8.8 | — | — | — | — | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote au | 23d ago |
| CVE-2026-59109 | 8.8 | — | — | — | — | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electro | 23d ago |
| CVE-2026-73514 | 8.8 | — | — | — | — | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds w | 23d ago |
| CVE-2026-68454 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable wit | 23d ago |
| CVE-2026-19293 | 8.8 | — | — | — | — | SMP security request (from peripheral) does not include the maximum encryption key size supported. | 23d ago |
| CVE-2026-19292 | 8.8 | — | — | — | — | Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easi | 23d ago |
| CVE-2026-19291 | 8.8 | — | — | — | — | Bluetooth re-pairing with an existing device can use a lower security level. | 23d ago |
| CVE-2026-16101 | 8.8 | — | — | — | — | Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. | 23d ago |
| CVE-2026-28176 | 8.8 | — | — | — | — | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | 23d ago |
| CVE-2026-28161 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | 23d ago |
| CVE-2026-19385 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute ar | 23d ago |
| CVE-2026-18408 | 8.8 | — | — | — | postgresql / postgresql | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbi | 23d ago |
| CVE-2026-16239 | 8.8 | — | — | — | postgresql / postgresql | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating sy | 23d ago |