| CVE-2026-9431 | 8.8 | — | — | — | — | A vulnerability was identified in Tenda F1202 1.2.0.20(408). | 139d ago |
| CVE-2026-9430 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda F1202 1.2.0.20(408). | 139d ago |
| CVE-2026-9429 | 8.8 | — | — | — | — | A vulnerability was found in Tenda F1202 1.2.0.20(408). | 139d ago |
| CVE-2026-9428 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda F1202 1.2.0.20(408). | 139d ago |
| CVE-2026-9427 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7438RPn 1.31. | 139d ago |
| CVE-2026-9426 | 8.8 | — | — | — | — | A vulnerability was detected in Edimax EW-7438RPn 1.31. | 139d ago |
| CVE-2026-9425 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. | 139d ago |
| CVE-2026-9403 | 8.8 | — | — | — | — | A vulnerability was determined in Edimax BR-6675nD 1.12. | 139d ago |
| CVE-2026-9401 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax BR-6675nD 1.12. | 139d ago |
| CVE-2026-9399 | 8.8 | — | — | — | — | A vulnerability was detected in Edimax BR-6675nD 1.12. | 139d ago |
| CVE-2026-9393 | 8.8 | — | — | — | — | A vulnerability was found in H3C Magic B0 up to 100R002. | 139d ago |
| CVE-2026-9389 | 8.8 | — | — | — | — | A security vulnerability has been detected in Tenda F456 1.0.0.5. | 139d ago |
| CVE-2026-9382 | 8.8 | — | — | — | — | A flaw has been found in Edimax BR-6675nD 1.12. | 139d ago |
| CVE-2026-9381 | 8.8 | — | — | — | — | A vulnerability was detected in Edimax BR-6675nD 1.12. | 139d ago |
| CVE-2026-9380 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax BR-6675nD 1.12. | 139d ago |
| CVE-2026-9360 | 8.8 | — | — | — | — | A security flaw has been discovered in Edimax EW-7438RPn 1.28a. | 139d ago |
| CVE-2026-9348 | 8.8 | — | — | — | — | A vulnerability was found in Edimax EW-7438RPn up to 1.31. | 140d ago |
| CVE-2026-9346 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7438RPn up to 1.31. | 140d ago |
| CVE-2026-9345 | 8.8 | — | — | — | — | A vulnerability was detected in Edimax EW-7438RPn up to 1.31. | 140d ago |
| CVE-2026-9344 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. | 140d ago |
| CVE-2018-25353 | 8.8 | — | — | — | — | Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticat | 140d ago |
| CVE-2026-43503 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker thro | 140d ago |
| CVE-2026-9295 | 8.8 | — | — | — | — | A security flaw has been discovered in Edimax BR-6428NS 1.10. | 140d ago |
| CVE-2026-9294 | 8.8 | — | — | — | — | A vulnerability was identified in Edimax BR-6428NS 1.10. | 140d ago |
| CVE-2026-6898 | 8.8 | — | — | — | — | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi | 141d ago |
| CVE-2026-6897 | 8.8 | — | — | — | — | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi | 141d ago |
| CVE-2026-6895 | 8.8 | — | — | — | — | The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Di | 141d ago |
| CVE-2026-6419 | 8.8 | — | — | — | — | The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in version | 141d ago |
| CVE-2026-45659exploited | 8.8 | 2.7% | 3/3 | +40d | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 141d ago |
| CVE-2026-35430 | 8.8 | — | — | — | microsoft / azure privileged identity management | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorize | 141d ago |
| CVE-2026-41075 | 8.8 | — | — | — | — | RT is an open source, enterprise-grade issue and ticket tracking system. | 141d ago |
| CVE-2026-3294 | 8.8 | — | — | — | tp-link / re305 firmware | An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an | 141d ago |
| CVE-2026-6406 | 8.8 | — | — | — | docker / docker desktop | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. | 141d ago |
| CVE-2026-8992 | 8.8 | — | — | — | ivanti / secure access client | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unaut | 141d ago |
| CVE-2026-9018 | 8.8 | — | — | — | — | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escala | 142d ago |
| CVE-2026-8434 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 142d ago |
| CVE-2026-8433 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 142d ago |
| CVE-2026-8432 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 142d ago |
| CVE-2026-8427 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 142d ago |
| CVE-2026-8416 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file | 142d ago |
| CVE-2026-8415 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/expre | 142d ago |
| CVE-2026-8414 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event | 142d ago |
| CVE-2026-8413 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/ | 142d ago |
| CVE-2026-8412 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/ | 142d ago |
| CVE-2026-8411 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/ | 142d ago |
| CVE-2026-8410 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/ | 142d ago |
| CVE-2026-8409 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/ | 142d ago |
| CVE-2026-8428 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update') | 142d ago |
| CVE-2026-8426 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/ | 142d ago |
| CVE-2026-8421 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/ | 142d ago |
| CVE-2026-8417 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/ | 142d ago |
| CVE-2026-8350 | 8.8 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead | 142d ago |
| CVE-2026-47102 | 8.8 | — | — | — | litellm / litellm | LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. | 142d ago |
| CVE-2026-47101 | 8.8 | — | — | — | litellm / litellm | LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their | 142d ago |
| CVE-2026-47114 | 8.8 | — | — | — | — | IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute | 142d ago |
| CVE-2026-9089 | 8.8 | — | — | — | connectwise / automate | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading | 142d ago |
| CVE-2026-43495 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against m | 142d ago |
| CVE-2026-39461 | 8.8 | — | — | — | freebsd / freebsd | libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wai | 142d ago |
| CVE-2026-44048 | 8.8 | — | — | — | — | A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows | 142d ago |
| CVE-2026-44047 | 8.8 | — | — | — | — | An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authentic | 142d ago |