| CVE-2025-69240 | 8.8 | — | — | — | raytha / raytha | Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. | 209d ago |
| CVE-2025-54920 | 8.8 | — | — | — | apache / spark | This issue affects Apache Spark: before 3.5.7 and 4.0.1. | 209d ago |
| CVE-2025-15540 | 8.8 | — | — | — | raytha / raytha | "Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. | 209d ago |
| CVE-2025-14287 | 8.8 | — | — | — | lfprojects / mlflow | A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sage | 209d ago |
| CVE-2016-20034 | 8.8 | — | — | — | wowza / streaming engine | Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only use | 209d ago |
| CVE-2016-20025 | 8.8 | — | — | — | — | ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated u | 209d ago |
| CVE-2026-4092 | 8.8 | — | — | — | google / clasp | Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a | 211d ago |
| CVE-2026-3999 | 8.8 | — | — | — | pointsharp / id server | A broken access control may allow an authenticated user to perform a horizontal privilege escalation. | 211d ago |
| CVE-2026-3910zero day | 8.8 | 1.1% | 3/3 | 1d before | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arb | 211d ago |
| CVE-2026-3909zero day | 8.8 | 2.3% | 3/3 | 1d before | google / chrome | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bou | 211d ago |
| CVE-2026-32355 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This is | 211d ago |
| CVE-2026-25817 | 8.8 | — | — | — | — | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmw | 211d ago |
| CVE-2026-3841 | 8.8 | — | — | — | tp-link / tl-mr6400 firmware | A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR64 | 212d ago |
| CVE-2026-32140 | 8.8 | — | — | — | dataease / dataease | Dataease is an open source data visualization analysis tool. | 212d ago |
| CVE-2026-32137 | 8.8 | — | — | — | dataease / dataease | Dataease is an open source data visualization analysis tool. | 212d ago |
| CVE-2026-26794 | 8.8 | — | — | — | gl-inet / ar300m16 firmware | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. | 212d ago |
| CVE-2026-21672 | 8.8 | — | — | — | — | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. | 212d ago |
| CVE-2026-4043 | 8.8 | — | — | — | tenda / i12 firmware | A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). | 213d ago |
| CVE-2026-4042 | 8.8 | — | — | — | tenda / i12 firmware | A weakness has been identified in Tenda i12 1.0.0.6(2204). | 213d ago |
| CVE-2026-4041 | 8.8 | — | — | — | tenda / i12 firmware | A security flaw has been discovered in Tenda i12 1.0.0.6(2204). | 213d ago |
| CVE-2026-21668 | 8.8 | — | — | — | veeam / veeam backup \& replication | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a B | 213d ago |
| CVE-2026-4008 | 8.8 | — | — | — | tenda / w3 firmware | A flaw has been found in Tenda W3 1.0.0.3(2204). | 213d ago |
| CVE-2026-4007 | 8.8 | — | — | — | tenda / w3 firmware | A vulnerability was detected in Tenda W3 1.0.0.3(2204). | 213d ago |
| CVE-2026-3978 | 8.8 | — | — | — | dlink / dir-513 firmware | A vulnerability was detected in D-Link DIR-513 1.10. | 213d ago |
| CVE-2026-3976 | 8.8 | — | — | — | tenda / w3 firmware | A weakness has been identified in Tenda W3 1.0.0.3(2204). | 213d ago |
| CVE-2026-3975 | 8.8 | — | — | — | tenda / w3 firmware | A security flaw has been discovered in Tenda W3 1.0.0.3(2204). | 213d ago |
| CVE-2026-3974 | 8.8 | — | — | — | tenda / w3 firmware | A vulnerability was identified in Tenda W3 1.0.0.3(2204). | 213d ago |
| CVE-2026-3973 | 8.8 | — | — | — | tenda / w3 firmware | A vulnerability was determined in Tenda W3 1.0.0.3(2204). | 213d ago |
| CVE-2026-3972 | 8.8 | — | — | — | tenda / w3 firmware | A vulnerability was found in Tenda W3 1.0.0.3(2204). | 213d ago |
| CVE-2026-3971 | 8.8 | — | — | — | tenda / i3 firmware | A vulnerability has been found in Tenda i3 1.0.0.6(2204). | 213d ago |
| CVE-2026-3970 | 8.8 | — | — | — | tenda / i3 firmware | A flaw has been found in Tenda i3 1.0.0.6(2204). | 213d ago |
| CVE-2023-43010 | 8.8 | — | — | — | apple / safari | The issue was addressed with improved memory handling. | 213d ago |
| CVE-2026-3936 | 8.8 | — | — | — | google / chrome | Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potential | 213d ago |
| CVE-2026-3931 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bo | 213d ago |
| CVE-2026-3926 | 8.8 | — | — | — | google / chrome | Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds | 213d ago |
| CVE-2026-3923 | 8.8 | — | — | — | google / chrome | Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit | 213d ago |
| CVE-2026-3922 | 8.8 | — | — | — | google / chrome | Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially expl | 213d ago |
| CVE-2026-3921 | 8.8 | — | — | — | google / chrome | Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exp | 213d ago |
| CVE-2026-3920 | 8.8 | — | — | — | google / chrome | Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potential | 213d ago |
| CVE-2026-3919 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to in | 213d ago |
| CVE-2026-3918 | 8.8 | — | — | — | google / chrome | Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit h | 213d ago |
| CVE-2026-3917 | 8.8 | — | — | — | google / chrome | Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit h | 213d ago |
| CVE-2026-3915 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out o | 213d ago |
| CVE-2026-3914 | 8.8 | — | — | — | google / chrome | Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit | 213d ago |
| CVE-2026-3913 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially expl | 213d ago |
| CVE-2026-32127 | 8.8 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 213d ago |
| CVE-2026-32097 | 8.8 | — | — | — | harvard / pingpong | PingPong is a platform for using large language models (LLMs) for teaching and learning. | 213d ago |
| CVE-2026-31979 | 8.8 | — | — | — | himmelblau-idm / himmelblau | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. | 213d ago |
| CVE-2026-31895 | 8.8 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 213d ago |
| CVE-2026-31861 | 8.8 | — | — | — | cloudcli / cloud cli | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. | 213d ago |
| CVE-2026-31858 | 8.8 | — | — | — | craftcms / craft cms | Craft is a content management system (CMS). | 213d ago |
| CVE-2026-31857 | 8.8 | — | — | — | craftcms / craft cms | Craft is a content management system (CMS). | 213d ago |
| CVE-2026-31854 | 8.8 | — | — | — | anysphere / cursor | Cursor is a code editor built for programming with AI. | 213d ago |
| CVE-2026-20046 | 8.8 | — | — | — | cisco / ios xr | A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authen | 213d ago |
| CVE-2026-20040 | 8.8 | — | — | — | cisco / ios xr | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitr | 213d ago |
| CVE-2025-68623 | 8.8 | — | — | — | — | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable fi | 213d ago |
| CVE-2026-0799 | 8.7 | — | — | — | — | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32- | 35d ago |
| CVE-2026-86123 | 8.7 | — | — | — | — | SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters an | 36d ago |
| CVE-2026-85781 | 8.7 | — | — | — | — | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver befor | 36d ago |
| CVE-2026-71404 | 8.7 | — | — | — | — | A flaw was found in Rancher Manager. | 38d ago |