| CVE-2026-31225 | 8.8 | — | — | — | — | The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing c | 151d ago |
| CVE-2026-31224 | 8.8 | — | — | — | snorkel / snorkel | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClas | 151d ago |
| CVE-2026-31223 | 8.8 | — | — | — | snorkel / snorkel | The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseL | 151d ago |
| CVE-2026-31222 | 8.8 | — | — | — | snorkel / snorkel | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load( | 151d ago |
| CVE-2026-31219 | 8.8 | — | — | — | — | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481 | 151d ago |
| CVE-2026-31218 | 8.8 | — | — | — | — | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481 | 151d ago |
| CVE-2026-30810 | 8.8 | — | — | — | artica / pandora fms | Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. | 151d ago |
| CVE-2026-30807 | 8.8 | — | — | — | artica / pandora fms | Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. | 151d ago |
| CVE-2026-8111 | 8.8 | — | — | — | ivanti / endpoint manager | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated a | 151d ago |
| CVE-2026-43937 | 8.8 | — | — | — | — | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. | 151d ago |
| CVE-2026-8389 | 8.8 | — | — | — | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 151d ago |
| CVE-2026-2465 | 8.8 | — | — | — | — | Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Indust | 152d ago |
| CVE-2026-6001 | 8.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. | 152d ago |
| CVE-2026-7256 | 8.8 | — | — | — | zyxel / wre6505 firmware | ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware v | 152d ago |
| CVE-2026-41489 | 8.8 | — | — | — | — | Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. | 152d ago |
| CVE-2026-28995 | 8.8 | — | — | — | apple / ipados | A logic issue was addressed with improved restrictions. | 152d ago |
| CVE-2026-28978 | 8.8 | — | — | — | apple / macos | A permissions issue was addressed with additional restrictions. | 152d ago |
| CVE-2026-28955 | 8.8 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28947 | 8.8 | — | — | — | apple / ipados | A use-after-free issue was addressed with improved memory management. | 152d ago |
| CVE-2026-28940 | 8.8 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-28923 | 8.8 | — | — | — | apple / macos | A logging issue was addressed with improved data redaction. | 152d ago |
| CVE-2026-28847 | 8.8 | — | — | — | apple / ipados | The issue was addressed with improved memory handling. | 152d ago |
| CVE-2026-36734 | 8.8 | — | — | — | — | EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. | 152d ago |
| CVE-2026-45223 | 8.8 | — | — | — | — | Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification pa | 152d ago |
| CVE-2026-45006 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and | 152d ago |
| CVE-2026-42843 | 8.8 | — | — | — | getgrav / grav-plugin-api | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, co | 152d ago |
| CVE-2026-42603 | 8.8 | — | — | — | — | OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, | 152d ago |
| CVE-2026-7816 | 8.8 | — | — | — | pgadmin / pgadmin 4 | OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. | 152d ago |
| CVE-2026-7815 | 8.8 | — | — | — | pgadmin / pgadmin 4 | SQL injection vulnerability in pgAdmin 4 Maintenance Tool. | 152d ago |
| CVE-2026-8260 | 8.8 | — | — | — | dlink / dcs-935l firmware | A vulnerability was found in D-Link DCS-935L up to 1.10.01. | 153d ago |
| CVE-2022-50944 | 8.8 | — | — | — | — | Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrar | 153d ago |
| CVE-2021-47949 | 8.8 | — | — | — | — | CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary fi | 153d ago |
| CVE-2021-47943 | 8.8 | — | — | — | — | TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execut | 153d ago |
| CVE-2021-47939 | 8.8 | — | — | — | — | Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module cre | 153d ago |
| CVE-2021-47938 | 8.8 | — | — | — | — | ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that all | 153d ago |
| CVE-2021-47937 | 8.8 | — | — | — | — | e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installat | 153d ago |
| CVE-2021-47935 | 8.8 | — | — | — | sentry / sentry | Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitr | 153d ago |
| CVE-2026-8234 | 8.8 | — | — | — | — | A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. | 154d ago |
| CVE-2026-30932 | 8.8 | — | — | — | froxlor / froxlor | Froxlor is open source server administration software. | 200d ago |
| CVE-2026-33336 | 8.8 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 200d ago |
| CVE-2026-29839 | 8.8 | — | — | — | dedecms / dedecms | DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php. | 200d ago |
| CVE-2026-33310 | 8.8 | — | — | — | intake / intake | Intake is a package for finding, investigating, loading and disseminating data. | 200d ago |
| CVE-2026-4722 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the IPC component. | 200d ago |
| CVE-2019-25647 | 8.8 | — | — | — | phreesoft / phreebookserp | PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated | 201d ago |
| CVE-2019-25630 | 8.8 | — | — | — | phreesoft / phreebookserp | PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows au | 201d ago |
| CVE-2025-41660 | 8.8 | — | — | — | — | A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system | 201d ago |
| CVE-2026-33854 | 8.8 | — | — | — | molotovcherry / android-imagemagick7 | Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: b | 201d ago |
| CVE-2026-33849 | 8.8 | — | — | — | linkingvision / rapidvms | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th | 201d ago |
| CVE-2026-33848 | 8.8 | — | — | — | linkingvision / rapidvms | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th | 201d ago |
| CVE-2026-4639 | 8.8 | — | — | — | gss / vitalsesp | Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticate | 201d ago |
| CVE-2026-4680 | 8.8 | — | — | — | google / chrome | Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary cod | 201d ago |
| CVE-2026-4679 | 8.8 | — | — | — | google / chrome | Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of b | 201d ago |
| CVE-2026-4678 | 8.8 | — | — | — | google / chrome | Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary co | 201d ago |
| CVE-2026-4677 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perf | 201d ago |
| CVE-2026-4676 | 8.8 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a | 201d ago |
| CVE-2026-4675 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out | 201d ago |
| CVE-2026-4674 | 8.8 | — | — | — | google / chrome | Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of boun | 201d ago |
| CVE-2026-4673 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an o | 201d ago |
| CVE-2026-3533 | 8.8 | — | — | — | — | The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on impor | 201d ago |
| CVE-2026-33046 | 8.8 | — | — | — | cern / indico | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. | 201d ago |