| CVE-2026-46827 | 8.8 | — | — | — | oracle / e-business suite | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). | 135d ago |
| CVE-2026-46826 | 8.8 | — | — | — | oracle / e-business suite | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). | 135d ago |
| CVE-2026-4944 | 8.8 | — | — | — | — | vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded | 135d ago |
| CVE-2026-8697 | 8.8 | — | — | — | tp-link / archer c64 firmware | Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH servic | 135d ago |
| CVE-2026-35671 | 8.8 | — | — | — | — | phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password en | 135d ago |
| CVE-2026-46238 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator po | 135d ago |
| CVE-2026-46212 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: prevent use-after-free when d | 135d ago |
| CVE-2026-46198 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix integer overflow on buff_pos F | 135d ago |
| CVE-2026-46174 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper isolation of sha | 135d ago |
| CVE-2026-46166 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: use safe list iteration in rad | 135d ago |
| CVE-2026-46152 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'static' from fast- | 135d ago |
| CVE-2026-46125 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection p | 135d ago |
| CVE-2026-46113 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due | 135d ago |
| CVE-2026-6226 | 8.8 | — | — | — | — | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in vers | 135d ago |
| CVE-2026-9227 | 8.8 | — | — | — | — | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, | 135d ago |
| CVE-2026-9009 | 8.8 | — | — | — | — | The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all | 136d ago |
| CVE-2026-7802 | 8.8 | — | — | — | — | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, | 136d ago |
| CVE-2026-8915 | 8.8 | — | — | — | samsung / escargot | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. | 136d ago |
| CVE-2026-46414 | 8.8 | — | — | — | — | Microsoft UFO open-source framework for intelligent automation across devices and platforms. | 136d ago |
| CVE-2026-9208 | 8.8 | — | — | — | tanium / connect | Tanium addressed an unauthorized code execution vulnerability in Connect. | 136d ago |
| CVE-2026-44713 | 8.8 | — | — | — | — | pam_usb provides hardware authentication for Linux using ordinary removable media. | 136d ago |
| CVE-2026-45717 | 8.8 | — | — | — | — | Budibase is an open-source low-code platform. | 136d ago |
| CVE-2026-45716 | 8.8 | — | — | — | — | Budibase is an open-source low-code platform. | 136d ago |
| CVE-2026-44521 | 8.8 | — | — | — | — | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. | 136d ago |
| CVE-2026-44346 | 8.8 | — | — | — | bentoml / bentoml | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. | 136d ago |
| CVE-2026-44345 | 8.8 | — | — | — | bentoml / bentoml | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. | 136d ago |
| CVE-2026-38807 | 8.8 | — | — | — | — | Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the Use | 136d ago |
| CVE-2026-48920 | 8.8 | — | — | — | jenkins / email extension | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content | 136d ago |
| CVE-2026-44988 | 8.8 | — | — | — | — | LibVNCClient is a library for easy implementation of a VNC client. | 136d ago |
| CVE-2026-42184 | 8.8 | — | — | — | tauri / tauri | Tauri is a framework for building binaries for all major desktop platforms. | 136d ago |
| CVE-2026-8179 | 8.8 | — | — | — | ibm / aspera high-speed transfer endpoint | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3. | 136d ago |
| CVE-2026-5065 | 8.8 | — | — | — | ibm / controller | IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptograp | 136d ago |
| CVE-2026-46056 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in SSP | 136d ago |
| CVE-2026-45945 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix race condition during PASID en | 136d ago |
| CVE-2026-36044 | 8.8 | — | — | — | — | @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. | 136d ago |
| CVE-2026-8832 | 8.8 | — | — | — | — | The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vul | 136d ago |
| CVE-2025-41669 | 8.8 | — | — | — | — | The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device dow | 136d ago |
| CVE-2026-8787 | 8.8 | — | — | — | — | The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions u | 137d ago |
| CVE-2026-9632 | 8.8 | — | — | — | — | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 137d ago |
| CVE-2026-9631 | 8.8 | — | — | — | — | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 137d ago |
| CVE-2026-9628 | 8.8 | — | — | — | — | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. | 137d ago |
| CVE-2026-9627 | 8.8 | — | — | — | — | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. | 137d ago |
| CVE-2026-9207 | 8.8 | — | — | — | tanium / connect | Tanium addressed an unauthorized code execution vulnerability in Connect. | 137d ago |
| CVE-2026-8676 | 8.8 | — | — | — | — | An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing t | 137d ago |
| CVE-2026-44832 | 8.8 | — | — | — | snipeitapp / snipe-it | Snipe-IT is an IT asset/license management system. | 137d ago |
| CVE-2026-24187 | 8.8 | — | — | — | nvidia / gpu display driver | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. | 137d ago |
| CVE-2026-46368 | 8.8 | — | — | — | — | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, di | 137d ago |
| CVE-2026-40033 | 8.8 | — | — | — | freerdp / freerdp | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attac | 137d ago |
| CVE-2026-45216 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. | 138d ago |
| CVE-2026-9482 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9481 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9480 | 8.8 | — | — | — | — | A vulnerability was detected in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9479 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9463 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9462 | 8.8 | — | — | — | — | A vulnerability was detected in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9461 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9460 | 8.8 | — | — | — | — | A weakness has been identified in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9459 | 8.8 | — | — | — | — | A security flaw has been discovered in Edimax EW-7438RPn 1.31. | 138d ago |
| CVE-2026-9443 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax BR-6478AC 1.23. | 138d ago |
| CVE-2026-9442 | 8.8 | — | — | — | — | A weakness has been identified in Edimax BR-6478AC 1.23. | 138d ago |