| CVE-2026-33634zero day | 8.8 | 1.7% | 3/3 | same day | aquasec / setup-trivy | Trivy is a security scanner. | 201d ago |
| CVE-2026-32276 | 8.8 | — | — | — | opensource-workshop / connect-cms | Connect-CMS is a content management system. | 201d ago |
| CVE-2025-60947 | 8.8 | — | — | — | csprousers / csweb | Census CSWeb 8.0.1 allows arbitrary file upload. | 201d ago |
| CVE-2025-60946 | 8.8 | — | — | — | csprousers / csweb | Census CSWeb 8.0.1 allows arbitrary file path input. | 201d ago |
| CVE-2026-23480 | 8.8 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 201d ago |
| CVE-2026-33717 | 8.8 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-33648 | 8.8 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-33647 | 8.8 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-33507 | 8.8 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-24516 | 8.8 | — | — | — | — | A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. | 201d ago |
| CVE-2026-33479 | 8.8 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 202d ago |
| CVE-2026-31847 | 8.8 | — | — | — | nexxtsolutions / nebula300plus firmware | Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 1 | 202d ago |
| CVE-2026-4566 | 8.8 | — | — | — | belkin / f9k1122 firmware | A flaw has been found in Belkin F9K1122 1.00.33. | 202d ago |
| CVE-2026-4565 | 8.8 | — | — | — | tenda / ac21 firmware | A vulnerability was detected in Tenda AC21 16.03.08.16. | 202d ago |
| CVE-2026-4558 | 8.8 | — | — | — | linksys / mr9600 firmware | A flaw has been found in Linksys MR9600 2.0.6.206937. | 202d ago |
| CVE-2026-4555 | 8.8 | — | — | — | dlink / dir-513 firmware | A weakness has been identified in D-Link DIR-513 1.10. | 202d ago |
| CVE-2026-4553 | 8.8 | — | — | — | tenda / f453 firmware | A vulnerability was identified in Tenda F453 1.0.0.3. | 202d ago |
| CVE-2026-4552 | 8.8 | — | — | — | tenda / f453 firmware | A vulnerability was determined in Tenda F453 1.0.0.3. | 203d ago |
| CVE-2026-4551 | 8.8 | — | — | — | tenda / f453 firmware | A vulnerability was found in Tenda F453 1.0.0.3. | 203d ago |
| CVE-2026-4535 | 8.8 | — | — | — | tenda / fh451 firmware | A vulnerability has been found in Tenda FH451 1.0.0.9. | 203d ago |
| CVE-2026-4534 | 8.8 | — | — | — | tenda / fh451 firmware | A flaw has been found in Tenda FH451 1.0.0.9. | 203d ago |
| CVE-2026-4314 | 8.8 | — | — | — | — | The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in al | 203d ago |
| CVE-2026-4529 | 8.8 | — | — | — | dlink / dhp-1320 firmware | A vulnerability was identified in D-Link DHP-1320 1.00WWB04. | 203d ago |
| CVE-2026-4261 | 8.8 | — | — | — | — | The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1 | 204d ago |
| CVE-2026-3334 | 8.8 | — | — | — | — | The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', | 204d ago |
| CVE-2026-2941 | 8.8 | — | — | — | — | The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a miss | 204d ago |
| CVE-2026-32051 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated call | 204d ago |
| CVE-2026-32042 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired devi | 204d ago |
| CVE-2026-4493 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda A18 Pro 02.03.02.28. | 204d ago |
| CVE-2026-4492 | 8.8 | — | — | — | — | A vulnerability was found in Tenda A18 Pro 02.03.02.28. | 204d ago |
| CVE-2026-4491 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda A18 Pro 02.03.02.28. | 204d ago |
| CVE-2026-4490 | 8.8 | — | — | — | — | A flaw has been found in Tenda A18 Pro 02.03.02.28. | 204d ago |
| CVE-2026-4489 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda A18 Pro 02.03.02.28. | 204d ago |
| CVE-2026-4488 | 8.8 | — | — | — | — | A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 204d ago |
| CVE-2026-32989 | 8.8 | — | — | — | precurio / intranet portal | Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce a | 204d ago |
| CVE-2025-67260 | 8.8 | — | — | — | aster-te / terrapack tkservercgi | The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file uploa | 204d ago |
| CVE-2026-4487 | 8.8 | — | — | — | — | A vulnerability was determined in UTT HiPER 1200GW up to 2.5.3-170306. | 205d ago |
| CVE-2026-4486 | 8.8 | — | — | — | dlink / dir-513 firmware | A vulnerability was found in D-Link DIR-513 1.10. | 205d ago |
| CVE-2026-33124 | 8.8 | — | — | — | frigate / frigate | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. | 205d ago |
| CVE-2026-33075 | 8.8 | — | — | — | fastgpt / fastgpt | FastGPT is an AI Agent building platform. | 205d ago |
| CVE-2026-33068 | 8.8 | — | — | — | anthropic / claude code | Claude Code is an agentic coding tool. | 205d ago |
| CVE-2026-4475 | 8.8 | — | — | — | — | A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. | 205d ago |
| CVE-2026-33053 | 8.8 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 205d ago |
| CVE-2026-33025 | 8.8 | — | — | — | wwbn / avideo-encoder | AVideo is a video-sharing Platform. | 205d ago |
| CVE-2026-32950 | 8.8 | — | — | — | fit2cloud / sqlbot | SQLBot is an intelligent data query system based on a large language model and RAG. | 205d ago |
| CVE-2026-32888 | 8.8 | — | — | — | opensourcepos / open source point of sale | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. | 205d ago |
| CVE-2026-4464 | 8.8 | — | — | — | google / chrome | Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit | 205d ago |
| CVE-2026-4463 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially ex | 205d ago |
| CVE-2026-4462 | 8.8 | — | — | — | google / chrome | Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of | 205d ago |
| CVE-2026-4461 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentiall | 205d ago |
| CVE-2026-4460 | 8.8 | — | — | — | google / chrome | Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of | 205d ago |
| CVE-2026-4459 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to pote | 205d ago |
| CVE-2026-4458 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to i | 205d ago |
| CVE-2026-4457 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap | 205d ago |
| CVE-2026-4456 | 8.8 | — | — | — | google / chrome | Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who ha | 205d ago |
| CVE-2026-4455 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially ex | 205d ago |
| CVE-2026-4454 | 8.8 | — | — | — | google / chrome | Use after free in Network in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit | 205d ago |
| CVE-2026-4452 | 8.8 | — | — | — | google / chrome | Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentia | 205d ago |
| CVE-2026-4451 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote | 205d ago |
| CVE-2026-4450 | 8.8 | — | — | — | google / chrome | Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit | 205d ago |