| CVE-2026-16238 | 8.8 | — | — | — | postgresql / postgresql | Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as th | 23d ago |
| CVE-2026-15742 | 8.8 | — | — | — | postgresql / postgresql | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, execut | 23d ago |
| CVE-2026-15741 | 8.8 | — | — | — | postgresql / postgresql | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a | 23d ago |
| CVE-2026-14680 | 8.8 | — | — | — | postgresql / postgresql | Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the ope | 23d ago |
| CVE-2026-14677 | 8.8 | — | — | — | postgresql / postgresql | Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to | 23d ago |
| CVE-2026-14676 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the ope | 23d ago |
| CVE-2026-14671 | 8.8 | — | — | — | postgresql / postgresql | Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating s | 23d ago |
| CVE-2026-14670 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary cod | 23d ago |
| CVE-2026-14669 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrar | 23d ago |
| CVE-2026-14664 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating syste | 23d ago |
| CVE-2026-14662 | 8.8 | — | — | — | postgresql / postgresql | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to | 23d ago |
| CVE-2026-73625 | 8.8 | — | — | — | gitpython project / gitpython | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard t | 23d ago |
| CVE-2026-73615 | 8.8 | — | — | — | — | Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates ra | 23d ago |
| CVE-2026-73614 | 8.8 | — | — | — | — | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatt | 23d ago |
| CVE-2026-73601 | 8.8 | — | — | — | flowiseai / flowise | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP | 23d ago |
| CVE-2026-73486 | 8.8 | — | — | — | flowiseai / flowise | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that | 23d ago |
| CVE-2026-73485 | 8.8 | — | — | — | flowiseai / flowise | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticate | 23d ago |
| CVE-2026-73483 | 8.8 | — | — | — | flowiseai / flowise | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowis | 23d ago |
| CVE-2026-12263 | 8.8 | — | — | — | — | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to | 23d ago |
| CVE-2026-11840 | 8.8 | — | — | — | — | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are | 24d ago |
| CVE-2026-49473 | 8.8 | — | — | — | — | @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorizat | 24d ago |
| CVE-2026-13622 | 8.8 | — | — | — | — | A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. | 24d ago |
| CVE-2026-13105 | 8.8 | — | — | — | ibm / i access client solutions | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when impor | 24d ago |
| CVE-2026-17642 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr | 24d ago |
| CVE-2026-17417 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr | 24d ago |
| CVE-2026-17082 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improp | 24d ago |
| CVE-2026-13361 | 8.8 | — | — | — | ibm / informix dynamic server | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | 24d ago |
| CVE-2026-69106 | 8.8 | — | — | — | — | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers | 24d ago |
| CVE-2026-49467 | 8.8 | — | — | — | — | Pingvin Share X is a secure and easy self-hosted file sharing platform. | 24d ago |
| CVE-2026-44741 | 8.8 | — | — | — | — | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. | 24d ago |
| CVE-2026-18713 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. | 24d ago |
| CVE-2026-18669 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vuln | 24d ago |
| CVE-2026-17110 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain | 24d ago |
| CVE-2026-16906 | 8.8 | — | — | — | ibm / i | IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privile | 24d ago |
| CVE-2026-16856 | 8.8 | — | — | — | ibm / i | IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of spec | 24d ago |
| CVE-2026-18847 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing | 24d ago |
| CVE-2026-18683 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. | 24d ago |
| CVE-2026-73293 | 8.8 | — | — | — | — | Semaphore UI is a web interface for managing DevOps tools. | 24d ago |
| CVE-2026-67587 | 8.8 | — | — | — | apache / airflow | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which im | 24d ago |
| CVE-2026-65941 | 8.8 | — | — | — | progress / whatsup gold | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the a | 24d ago |
| CVE-2026-58076 | 8.8 | — | — | — | apache / airflow | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name ta | 24d ago |
| CVE-2026-73284 | 8.8 | — | — | — | — | RustFS is a distributed object storage system built in Rust. | 24d ago |
| CVE-2026-11325 | 8.8 | — | — | — | — | Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repositor | 24d ago |
| CVE-2026-13613 | 8.8 | — | — | — | — | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before u | 25d ago |
| CVE-2026-68432 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device net | 25d ago |
| CVE-2026-66875 | 8.8 | — | — | — | — | In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE | 25d ago |
| CVE-2026-5917 | 8.8 | — | — | — | — | libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a | 25d ago |
| CVE-2026-19560 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary co | 25d ago |
| CVE-2026-19559 | 8.8 | — | — | — | google / chrome | Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary cod | 25d ago |
| CVE-2026-19556 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code | 25d ago |
| CVE-2026-55676 | 8.8 | — | — | — | — | Malcolm is a network traffic analysis tool suite. | 25d ago |
| CVE-2026-15606 | 8.8 | — | — | — | — | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, | 25d ago |
| CVE-2026-14863 | 8.8 | — | — | — | — | FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authentica | 25d ago |
| CVE-2026-73226 | 8.8 | — | — | — | — | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. | 25d ago |
| CVE-2026-73224 | 8.8 | — | — | — | — | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. | 25d ago |
| CVE-2026-73222 | 8.8 | — | — | — | — | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. | 25d ago |
| CVE-2026-18692 | 8.8 | — | — | — | — | An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write | 25d ago |
| CVE-2026-18691 | 8.8 | — | — | — | — | An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to in | 25d ago |
| CVE-2026-15426 | 8.8 | — | — | — | — | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPres | 25d ago |
| CVE-2026-71387 | 8.8 | — | — | — | adobe / coldfusion | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution i | 25d ago |