| CVE-2026-9126 | 8.8 | — | — | — | google / chrome | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary co | 143d ago |
| CVE-2026-9121 | 8.8 | — | — | — | google / chrome | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially expl | 143d ago |
| CVE-2026-9120 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary co | 143d ago |
| CVE-2026-9119 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arb | 143d ago |
| CVE-2026-9118 | 8.8 | — | — | — | google / chrome | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbit | 143d ago |
| CVE-2026-9114 | 8.8 | — | — | — | google / chrome | Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary c | 143d ago |
| CVE-2026-9112 | 8.8 | — | — | — | google / chrome | Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbi | 143d ago |
| CVE-2026-9111 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arb | 143d ago |
| CVE-2026-24217 | 8.8 | — | — | — | nvidia / bionemo framework | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a mali | 143d ago |
| CVE-2026-44926 | 8.8 | — | — | — | — | InfoScale CmdServer before 7.4.2 mishandles access control. | 143d ago |
| CVE-2026-44925 | 8.8 | — | — | — | veritas / infoscale operations manager | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker | 143d ago |
| CVE-2026-24425 | 8.8 | — | — | — | symfony / twig | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInte | 143d ago |
| CVE-2026-5200 | 8.8 | — | — | — | — | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress | 144d ago |
| CVE-2026-7522 | 8.8 | — | — | — | — | The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up t | 144d ago |
| CVE-2026-7467 | 8.8 | — | — | — | — | The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inc | 144d ago |
| CVE-2026-6456 | 8.8 | — | — | — | — | The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin | 144d ago |
| CVE-2026-32740 | 8.8 | — | — | — | struktur / libheif | libheif is a HEIF and AVIF file format decoder and encoder. | 144d ago |
| CVE-2026-8604 | 8.8 | — | — | — | scadabr / scadabr | In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through | 144d ago |
| CVE-2026-36828 | 8.8 | — | — | — | — | A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and in | 144d ago |
| CVE-2026-31069 | 8.8 | — | — | — | — | BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. | 144d ago |
| CVE-2026-8975 | 8.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. | 144d ago |
| CVE-2026-8974 | 8.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. | 144d ago |
| CVE-2026-8973 | 8.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox 150. | 144d ago |
| CVE-2026-8972 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the WebRTC: Audio/Video component. | 144d ago |
| CVE-2026-8970 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Security component. | 144d ago |
| CVE-2026-8957 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Enterprise Policies component. | 144d ago |
| CVE-2026-8955 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the DOM: Workers component. | 144d ago |
| CVE-2026-8952 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Application Update component. | 144d ago |
| CVE-2026-42097 | 8.8 | — | — | — | sparxsystems / pro cloud server | Sparx Pro Cloud Server requires authentication based on requested URL. | 144d ago |
| CVE-2026-42096 | 8.8 | — | — | — | sparxsystems / pro cloud server | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. | 144d ago |
| CVE-2026-46586 | 8.8 | — | — | — | apache / ofbiz | Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Ev | 145d ago |
| CVE-2026-27648 | 8.8 | — | — | — | — | in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. | 145d ago |
| CVE-2026-45495 | 8.8 | — | — | — | microsoft / edge chromium | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 145d ago |
| CVE-2026-41085 | 8.8 | — | — | — | — | Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow a | 145d ago |
| CVE-2025-57282 | 8.8 | — | — | — | — | ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection. | 145d ago |
| CVE-2026-7498 | 8.8 | — | — | — | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Infor | 146d ago |
| CVE-2026-3220 | 8.8 | — | — | — | — | The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPr | 146d ago |
| CVE-2026-8776 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax BR-6428NS 1.10. | 146d ago |
| CVE-2026-8775 | 8.8 | — | — | — | — | A flaw has been found in Edimax BR-6428NS 1.10. | 146d ago |
| CVE-2026-8719 | 8.8 | — | — | — | — | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escal | 147d ago |
| CVE-2021-47979 | 8.8 | — | — | — | — | WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authentica | 147d ago |
| CVE-2021-47976 | 8.8 | — | — | — | — | TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to up | 147d ago |
| CVE-2020-37227 | 8.8 | — | — | — | — | HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to byp | 147d ago |
| CVE-2026-45672 | 8.8 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 148d ago |
| CVE-2021-47964 | 8.8 | — | — | — | — | Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute a | 148d ago |
| CVE-2026-45035 | 8.8 | — | — | — | tabby / tabby | Tabby (formerly Terminus) is a highly configurable terminal emulator. | 148d ago |
| CVE-2026-6228 | 8.8 | — | — | — | — | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and i | 149d ago |
| CVE-2026-43490 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_i | 149d ago |
| CVE-2026-8587 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a us | 149d ago |
| CVE-2026-8581 | 8.8 | — | — | — | google / chrome | Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code | 149d ago |
| CVE-2026-8577 | 8.8 | — | — | — | google / chrome | Integer overflow in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary c | 149d ago |
| CVE-2026-8558 | 8.8 | — | — | — | google / chrome | Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrar | 149d ago |
| CVE-2026-8555 | 8.8 | — | — | — | google / chrome | Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbi | 149d ago |
| CVE-2026-8551 | 8.8 | — | — | — | google / chrome | Use after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user | 149d ago |
| CVE-2026-8549 | 8.8 | — | — | — | google / chrome | Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary cod | 149d ago |
| CVE-2026-8544 | 8.8 | — | — | — | google / chrome | Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary cod | 149d ago |
| CVE-2026-8540 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code i | 149d ago |
| CVE-2026-8532 | 8.8 | — | — | — | google / chrome | Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary cod | 149d ago |
| CVE-2026-8531 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to pote | 149d ago |
| CVE-2026-8529 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitr | 149d ago |