| CVE-2026-36608 | 8.8 | — | — | — | — | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external por | 129d ago |
| CVE-2026-36607 | 8.8 | — | — | — | — | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the | 129d ago |
| CVE-2026-6657 | 8.8 | — | — | — | jupyter / jupyter server | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validatio | 129d ago |
| CVE-2026-35085 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system | 129d ago |
| CVE-2026-35084 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system a | 129d ago |
| CVE-2026-35083 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. | 129d ago |
| CVE-2026-35082 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insuff | 129d ago |
| CVE-2025-15656 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. | 129d ago |
| CVE-2025-14772 | 8.8 | — | — | — | abb / t-mac plus | Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. | 129d ago |
| CVE-2026-49443 | 8.8 | — | — | — | goauthentik / authentik | authentik is an open-source identity provider. | 130d ago |
| CVE-2026-49143 | 8.8 | — | — | — | — | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that al | 130d ago |
| CVE-2026-1829 | 8.8 | — | — | — | — | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions | 130d ago |
| CVE-2026-30652 | 8.8 | — | — | — | vivotek / fd8136 firmware | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vi | 130d ago |
| CVE-2026-30650 | 8.8 | — | — | — | vivotek / fd8136 firmware | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of | 130d ago |
| CVE-2026-10591 | 8.8 | — | — | — | amazon / kiro ide | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow | 130d ago |
| CVE-2026-7201 | 8.8 | — | — | — | progress / sitefinity | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2 | 130d ago |
| CVE-2026-7195 | 8.8 | — | — | — | progress / sitefinity | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4. | 130d ago |
| CVE-2025-53345 | 8.8 | — | — | — | — | Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in Thim | 130d ago |
| CVE-2026-1784 | 8.8 | — | — | — | redhat / openshift container platform | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. | 130d ago |
| CVE-2026-25277 | 8.8 | — | — | — | qualcomm / cq8750m firmware | Memory corruption while using Strongbox due to buffer overflow. | 131d ago |
| CVE-2026-25276 | 8.8 | — | — | — | qualcomm / cq8750m firmware | Memory corruption while using Strongbox due to missing bounds check. | 131d ago |
| CVE-2026-10293 | 8.8 | — | — | — | — | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. | 131d ago |
| CVE-2026-10292 | 8.8 | — | — | — | — | A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. | 131d ago |
| CVE-2026-9614 | 8.8 | — | — | — | — | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authent | 131d ago |
| CVE-2026-7770 | 8.8 | — | — | — | ibm / i access client solutions | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execu | 131d ago |
| CVE-2026-43623 | 8.8 | — | — | — | — | microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src | 131d ago |
| CVE-2026-10270 | 8.8 | — | — | — | dlink / di-7001mini-8g firmware | A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. | 131d ago |
| CVE-2026-10259 | 8.8 | — | — | — | — | A security vulnerability has been detected in H3C Magic B0 up to 100R002. | 131d ago |
| CVE-2026-49298 | 8.8 | — | — | — | apache / airflow | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Exe | 131d ago |
| CVE-2026-49157 | 8.8 | — | — | — | apache / activemq | Incorrect Default Permissions vulnerability in Apache ActiveMQ. | 131d ago |
| CVE-2026-45505 | 8.8 | — | — | — | apache / activemq | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Activ | 131d ago |
| CVE-2026-42359 | 8.8 | — | — | — | apache / airflow | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API us | 131d ago |
| CVE-2026-10206 | 8.8 | — | — | — | — | A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. | 132d ago |
| CVE-2026-10192 | 8.8 | — | — | — | — | A vulnerability was identified in Tenda W12 3.0.0.7(4763). | 132d ago |
| CVE-2026-10191 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda W12 3.0.0.7(4763). | 132d ago |
| CVE-2026-10189 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda W12 3.0.0.7(4763). | 132d ago |
| CVE-2026-10188 | 8.8 | — | — | — | — | A flaw has been found in Tenda W12 3.0.0.7(4763). | 132d ago |
| CVE-2026-10183 | 8.8 | — | — | — | — | A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. | 132d ago |
| CVE-2026-10181 | 8.8 | — | — | — | — | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. | 132d ago |
| CVE-2026-10179 | 8.8 | — | — | — | — | A flaw has been found in TRENDnet TEW-432BRP 3.10B20. | 132d ago |
| CVE-2026-10165 | 8.8 | — | — | — | — | A vulnerability was identified in Edimax BR-6478AC 1.23. | 133d ago |
| CVE-2026-10164 | 8.8 | — | — | — | — | A vulnerability was found in Edimax BR-6478AC 1.23. | 133d ago |
| CVE-2026-10163 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax BR-6478AC 1.23. | 133d ago |
| CVE-2026-10162 | 8.8 | — | — | — | — | A flaw has been found in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10161 | 8.8 | — | — | — | — | A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10160 | 8.8 | — | — | — | — | A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10159 | 8.8 | — | — | — | — | A weakness has been identified in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10158 | 8.8 | — | — | — | — | A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10126 | 8.8 | — | — | — | — | A security flaw has been discovered in Edimax BR-6478AC 1.23. | 133d ago |
| CVE-2026-10125 | 8.8 | — | — | — | — | A vulnerability was identified in Edimax BR-6478AC 1.23. | 133d ago |
| CVE-2026-10124 | 8.8 | — | — | — | — | A vulnerability was determined in Shibby Tomato up to 1.28. | 133d ago |
| CVE-2026-10123 | 8.8 | — | — | — | — | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10122 | 8.8 | — | — | — | — | A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10121 | 8.8 | — | — | — | — | A flaw has been found in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2018-25409 | 8.8 | — | — | — | — | SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malici | 133d ago |
| CVE-2026-10120 | 8.8 | — | — | — | — | A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-10119 | 8.8 | — | — | — | — | A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. | 133d ago |
| CVE-2026-7465exploited | 8.8 | 0.97% | 1/3 | +3d | — | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Co | 133d ago |
| CVE-2026-48557 | 8.8 | — | — | — | — | Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaul | 134d ago |
| CVE-2026-44421 | 8.8 | — | — | — | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 134d ago |