| CVE-2026-18982 | 8.8 | — | — | — | — | A flaw was found in the RHOAI training-operator. | 26d ago |
| CVE-2026-18951 | 8.8 | — | — | — | — | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. | 26d ago |
| CVE-2026-18950 | 8.8 | — | — | — | — | A flaw was found in odh-dashboard. | 26d ago |
| CVE-2026-18949 | 8.8 | — | — | — | — | A flaw was found in odh-dashboard. | 26d ago |
| CVE-2026-18617 | 8.8 | — | — | — | — | A flaw was found in the Data Science Pipelines Operator (DSPO). | 26d ago |
| CVE-2026-13717 | 8.8 | — | — | — | — | A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. | 26d ago |
| CVE-2026-72883 | 8.8 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-72875 | 8.8 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-71966 | 8.8 | — | — | — | — | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote | 26d ago |
| CVE-2026-71965 | 8.8 | — | — | — | — | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the re | 26d ago |
| CVE-2026-69118 | 8.8 | — | — | — | — | Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that a | 26d ago |
| CVE-2026-72866 | 8.8 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 26d ago |
| CVE-2026-66738 | 8.8 | — | — | — | — | SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. | 26d ago |
| CVE-2026-68409 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu fre | 26d ago |
| CVE-2026-68397 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found | 26d ago |
| CVE-2026-68393 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: extend conn_hash lookup c | 26d ago |
| CVE-2026-68390 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold hdev->lock for hci_c | 26d ago |
| CVE-2026-68389 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on inv | 26d ago |
| CVE-2026-68354 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassem | 26d ago |
| CVE-2026-68341 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ovpn: fix use after free in unlock_ovpn() unlo | 26d ago |
| CVE-2026-68329 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of retu | 26d ago |
| CVE-2026-68326 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound uAP association event IEs | 26d ago |
| CVE-2026-68294 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the ini | 26d ago |
| CVE-2026-68283 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free freeing trigger pr | 26d ago |
| CVE-2026-68240 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: publish dpagemap early to avoid de | 26d ago |
| CVE-2026-68199 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADD | 26d ago |
| CVE-2026-68198 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset | 26d ago |
| CVE-2026-68192 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers id | 26d ago |
| CVE-2026-68142 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device ne | 26d ago |
| CVE-2026-68140 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv | 26d ago |
| CVE-2026-68128 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_p | 26d ago |
| CVE-2026-68125 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than t | 26d ago |
| CVE-2026-68108 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image | 26d ago |
| CVE-2026-68107 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param leng | 26d ago |
| CVE-2026-68098 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs se | 26d ago |
| CVE-2026-68097 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-autho | 26d ago |
| CVE-2026-68091 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start pro | 26d ago |
| CVE-2026-72578 | 8.8 | — | — | — | — | A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attac | 26d ago |
| CVE-2026-72573 | 8.8 | — | — | — | — | An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to | 26d ago |
| CVE-2026-66405 | 8.8 | — | — | — | — | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. | 27d ago |
| CVE-2026-18786 | 8.8 | — | — | — | — | The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes | 27d ago |
| CVE-2026-17540 | 8.8 | — | — | — | — | The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing | 27d ago |
| CVE-2026-16985 | 8.8 | — | — | — | — | The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data | 27d ago |
| CVE-2026-14293 | 8.8 | — | — | — | — | The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling o | 27d ago |
| CVE-2026-19346 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda CH22 1.0.0.1. | 27d ago |
| CVE-2026-19341 | 8.8 | — | — | — | — | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. | 28d ago |
| CVE-2026-48169 | 8.8 | — | — | — | — | PraisonAI is a multi-agent teams system. | 29d ago |
| CVE-2026-9169 | 8.8 | — | — | — | — | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute a | 30d ago |
| CVE-2026-16263 | 8.8 | — | — | — | — | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does | 30d ago |
| CVE-2026-15215 | 8.8 | — | — | — | — | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before insta | 30d ago |
| CVE-2026-65668 | 8.8 | — | — | — | microsoft / purview ediscovery | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a | 30d ago |
| CVE-2026-49163 | 8.8 | — | — | — | microsoft / application insights profiler | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler al | 30d ago |
| CVE-2026-67687 | 8.8 | — | — | — | — | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /syst | 30d ago |
| CVE-2026-48054 | 8.8 | — | — | — | — | OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZep | 30d ago |
| CVE-2026-19174 | 8.8 | — | — | — | google / chrome | Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary cod | 30d ago |
| CVE-2026-19169 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a | 30d ago |
| CVE-2026-19168 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute a | 30d ago |
| CVE-2026-19162 | 8.8 | — | — | — | google / chrome | Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary | 30d ago |
| CVE-2026-19151 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code | 30d ago |
| CVE-2026-19150 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute a | 30d ago |