| CVE-2026-4449 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit h | 205d ago |
| CVE-2026-4448 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exp | 205d ago |
| CVE-2026-4447 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute ar | 205d ago |
| CVE-2026-4446 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit | 205d ago |
| CVE-2026-4445 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit | 205d ago |
| CVE-2026-4444 | 8.8 | — | — | — | google / chrome | Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially e | 205d ago |
| CVE-2026-4443 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbi | 205d ago |
| CVE-2026-4442 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially explo | 205d ago |
| CVE-2026-4441 | 8.8 | — | — | — | google / chrome | Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit he | 205d ago |
| CVE-2026-4440 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform | 205d ago |
| CVE-2026-4439 | 8.8 | — | — | — | google / chrome | Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker | 205d ago |
| CVE-2026-33289 | 8.8 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 205d ago |
| CVE-2026-33288 | 8.8 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 205d ago |
| CVE-2026-32756 | 8.8 | — | — | — | admidio / admidio | Admidio is an open-source user management solution. | 205d ago |
| CVE-2026-29099 | 8.8 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 205d ago |
| CVE-2026-4342 | 8.8 | — | — | — | kubernetes / nginx ingress controller | A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject c | 205d ago |
| CVE-2026-32013 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents. | 205d ago |
| CVE-2026-32622 | 8.8 | — | — | — | fit2cloud / sqlbot | SQLBot is an intelligent data query system based on a large language model and RAG. | 205d ago |
| CVE-2026-30711 | 8.8 | — | — | — | — | Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/se | 206d ago |
| CVE-2025-71260 | 8.8 | — | — | — | bmc / footprints | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerabili | 206d ago |
| CVE-2026-25445 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.T | 206d ago |
| CVE-2026-32321 | 8.8 | — | — | — | oxygenz / clipbucket | ClipBucket v5 is an open source video sharing platform. | 206d ago |
| CVE-2025-58112 | 8.8 | — | — | — | — | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized rep | 206d ago |
| CVE-2026-31962 | 8.8 | — | — | — | htslib / htslib | HTSlib is a library for reading and writing bioinformatics file formats. | 206d ago |
| CVE-2026-1463 | 8.8 | — | — | — | — | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File | 206d ago |
| CVE-2026-33001 | 8.8 | — | — | — | jenkins / jenkins | Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of | 206d ago |
| CVE-2025-55044 | 8.8 | — | — | — | murasoftware / mura cms | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from t | 206d ago |
| CVE-2025-55040 | 8.8 | — | — | — | murasoftware / mura cms | The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious for | 206d ago |
| CVE-2026-32693 | 8.8 | — | — | — | canonical / juju | In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, | 207d ago |
| CVE-2026-23246 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80 | 207d ago |
| CVE-2026-22730 | 8.8 | — | — | — | vmware / spring ai | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass | 207d ago |
| CVE-2026-29056 | 8.8 | — | — | — | kanboard / kanboard | Kanboard is project management software focused on Kanban methodology. | 207d ago |
| CVE-2026-27894 | 8.8 | — | — | — | ldap-account-manager / ldap account manager | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. | 207d ago |
| CVE-2026-27811 | 8.8 | — | — | — | roxy-wi / roxy-wi | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. | 207d ago |
| CVE-2026-21570 | 8.8 | — | — | — | atlassian / bamboo | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10. | 207d ago |
| CVE-2026-4148 | 8.8 | — | — | — | mongodb / mongodb | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who | 207d ago |
| CVE-2026-4318 | 8.8 | — | — | — | — | A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. | 208d ago |
| CVE-2026-4208 | 8.8 | — | — | — | mrsilaz / mfa mail | The extension fails to properly reset the generated MFA code after successful authentication. | 208d ago |
| CVE-2026-1323 | 8.8 | — | — | — | cps-it / mailqueue | The extension fails to properly define allowed classes used when deserializing transport failure metadata. | 208d ago |
| CVE-2025-50881 | 8.8 | — | — | — | — | The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote C | 208d ago |
| CVE-2026-30881 | 8.8 | — | — | — | chamilo / chamilo lms | Chamilo LMS is a learning management system. | 208d ago |
| CVE-2026-30875 | 8.8 | — | — | — | chamilo / chamilo lms | Chamilo LMS is a learning management system. | 208d ago |
| CVE-2025-69784 | 8.8 | — | — | — | xcitium / openedr | A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driv | 208d ago |
| CVE-2026-4227 | 8.8 | — | — | — | lb-link / bl-wr9000 firmware | A security vulnerability has been detected in LB-LINK BL-WR9000 2.4.9. | 209d ago |
| CVE-2026-4226 | 8.8 | — | — | — | lb-link / bl-wr9000 firmware | A weakness has been identified in LB-LINK BL-WR9000 2.4.9. | 209d ago |
| CVE-2026-4214 | 8.8 | — | — | — | dlink / dnr-202l firmware | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-3 | 209d ago |
| CVE-2026-4213 | 8.8 | — | — | — | dlink / dnr-202l firmware | A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L | 209d ago |
| CVE-2026-4212 | 8.8 | — | — | — | dlink / dnr-202l firmware | A security vulnerability has been detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS | 209d ago |
| CVE-2026-4211 | 8.8 | — | — | — | dlink / dnr-202l firmware | A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32 | 209d ago |
| CVE-2026-4188 | 8.8 | — | — | — | — | A security flaw has been discovered in D-Link DIR-619L 2.06B01. | 209d ago |
| CVE-2026-4167 | 8.8 | — | — | — | — | A vulnerability was determined in Belkin F9K1122 1.00.33. | 209d ago |
| CVE-2026-3838 | 8.8 | — | — | — | unraid / unraid | Unraid Update Request Path Traversal Remote Code Execution Vulnerability. | 209d ago |
| CVE-2026-3562 | 8.8 | — | — | — | philips / hue bridge v2 firmware | Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. | 209d ago |
| CVE-2026-3560 | 8.8 | — | — | — | philips / hue bridge v2 firmware | Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. | 209d ago |
| CVE-2026-3556 | 8.8 | — | — | — | philips / hue bridge v2 firmware | Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. | 209d ago |
| CVE-2026-3085 | 8.8 | — | — | — | gstreamer / gstreamer | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. | 209d ago |
| CVE-2026-3083 | 8.8 | — | — | — | gstreamer / gstreamer | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. | 209d ago |
| CVE-2026-3023 | 8.8 | — | — | — | wakyma / wakyma | Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 've | 209d ago |
| CVE-2026-32628 | 8.8 | — | — | — | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 209d ago |
| CVE-2026-28519 | 8.8 | — | — | — | tuya / arduino-tuyaopen | arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer compone | 209d ago |