| CVE-2026-8527 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote a | 149d ago |
| CVE-2026-8526 | 8.8 | — | — | — | google / chrome | Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitra | 149d ago |
| CVE-2026-8524 | 8.8 | — | — | — | google / chrome | Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbit | 149d ago |
| CVE-2026-8522 | 8.8 | — | — | — | google / chrome | Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute ar | 149d ago |
| CVE-2026-8519 | 8.8 | — | — | — | google / chrome | Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform | 149d ago |
| CVE-2026-8518 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary cod | 149d ago |
| CVE-2026-8517 | 8.8 | — | — | — | google / chrome | Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who co | 149d ago |
| CVE-2026-8509 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitra | 149d ago |
| CVE-2026-43909 | 8.8 | — | — | — | openimageio / openimageio | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to V | 149d ago |
| CVE-2026-43908 | 8.8 | — | — | — | openimageio / openimageio | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to V | 149d ago |
| CVE-2026-8621 | 8.8 | — | — | — | — | Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers | 149d ago |
| CVE-2025-15024 | 8.8 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consultin | 149d ago |
| CVE-2025-15023 | 8.8 | — | — | — | — | Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems | 149d ago |
| CVE-2026-44827 | 8.8 | — | — | — | huggingface / diffusers | Diffusers is the a library for pretrained diffusion models. | 149d ago |
| CVE-2026-44513 | 8.8 | — | — | — | huggingface / diffusers | Diffusers is the a library for pretrained diffusion models. | 149d ago |
| CVE-2026-42559 | 8.8 | — | — | — | — | RMCP is an official Rust SDK for the Model Context Protocol. | 149d ago |
| CVE-2026-6637 | 8.8 | — | — | — | postgresql / postgresql | Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code | 149d ago |
| CVE-2026-6477 | 8.8 | — | — | — | postgresql / postgresql | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo | 149d ago |
| CVE-2026-6475 | 8.8 | — | — | — | postgresql / postgresql | Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite | 149d ago |
| CVE-2026-6473 | 8.8 | — | — | — | postgresql / postgresql | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server | 149d ago |
| CVE-2025-15025 | 8.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Traini | 149d ago |
| CVE-2025-12008 | 8.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. | 149d ago |
| CVE-2026-6506 | 8.8 | — | — | — | — | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, | 150d ago |
| CVE-2026-44447 | 8.8 | — | — | — | frappe / erpnext | ERPNext is a free and open source Enterprise Resource Planning tool. | 150d ago |
| CVE-2026-44446 | 8.8 | — | — | — | frappe / erpnext | ERPNext is a free and open source Enterprise Resource Planning tool. | 150d ago |
| CVE-2026-45229 | 8.8 | — | — | — | — | Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authent | 150d ago |
| CVE-2026-42550 | 8.8 | — | — | — | — | Flight is an extensible micro-framework for PHP. | 150d ago |
| CVE-2026-0259 | 8.8 | — | — | — | paloaltonetworks / pan-os | An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enab | 150d ago |
| CVE-2026-6281 | 8.8 | — | — | — | — | A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote auth | 150d ago |
| CVE-2026-44293 | 8.8 | — | — | — | protobufjs project / protobufjs | protobufjs compiles protobuf definitions into JavaScript (JS) functions. | 150d ago |
| CVE-2026-42266 | 8.8 | — | — | — | jupyter / jupyterlab | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook | 150d ago |
| CVE-2026-41957 | 8.8 | — | — | — | f5 / big-ip access policy manager | An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ C | 150d ago |
| CVE-2026-3425 | 8.8 | — | — | — | — | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, a | 150d ago |
| CVE-2026-8053 | 8.8 | — | — | — | mongodb / mongodb | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write | 151d ago |
| CVE-2026-42289 | 8.8 | — | — | — | — | ChurchCRM is an open-source church management system. | 151d ago |
| CVE-2026-45227 | 8.8 | — | — | — | — | Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenti | 151d ago |
| CVE-2026-42844 | 8.8 | — | — | — | getgrav / grav | Grav is a file-based Web platform. | 151d ago |
| CVE-2026-44224 | 8.8 | — | — | — | requarks / wiki.js | Wiki.js is an open source wiki app built on Node.js. | 151d ago |
| CVE-2026-7474 | 8.8 | — | — | — | — | HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a p | 151d ago |
| CVE-2026-8429 | 8.8 | — | — | — | — | SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attack | 151d ago |
| CVE-2026-23819 | 8.8 | — | — | — | arubanetworks / arubaos | A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allo | 151d ago |
| CVE-2026-43892 | 8.8 | — | — | — | — | AntSword is a cross-platform website management toolkit. | 151d ago |
| CVE-2026-41613 | 8.8 | — | — | — | microsoft / visual studio code | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 151d ago |
| CVE-2026-41109 | 8.8 | — | — | — | microsoft / visual studio code | Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copil | 151d ago |
| CVE-2026-41094 | 8.8 | — | — | — | microsoft / data formulator | Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized atta | 151d ago |
| CVE-2026-41086 | 8.8 | — | — | — | microsoft / windows admin center | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network | 151d ago |
| CVE-2026-40420 | 8.8 | — | — | — | microsoft / 365 apps | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 151d ago |
| CVE-2026-40403 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 151d ago |
| CVE-2026-40370 | 8.8 | — | — | — | microsoft / sql server 2016 | External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | 151d ago |
| CVE-2026-40365 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 151d ago |
| CVE-2026-40357 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 151d ago |
| CVE-2026-35439 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 151d ago |
| CVE-2026-35436 | 8.8 | — | — | — | microsoft / 365 apps | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 151d ago |
| CVE-2026-34329 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adja | 151d ago |
| CVE-2026-33112 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 151d ago |
| CVE-2026-33110 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 151d ago |
| CVE-2026-31232 | 8.8 | — | — | — | — | The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deser | 151d ago |
| CVE-2025-53844 | 8.8 | — | — | — | fortinet / fortios | A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS | 151d ago |
| CVE-2025-43524 | 8.8 | — | — | — | apple / macos | An access issue was addressed with additional sandbox restrictions. | 151d ago |
| CVE-2025-35990 | 8.8 | — | — | — | intel / endpoint management assistant | Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within | 151d ago |