| CVE-2026-19145 | 8.8 | — | — | — | google / chrome | Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrar | 30d ago |
| CVE-2026-19144 | 8.8 | — | — | — | google / chrome | Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit h | 30d ago |
| CVE-2024-39024 | 8.8 | — | — | — | — | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. | 30d ago |
| CVE-2026-18258 | 8.8 | — | — | — | escriptorium / escriptorium | Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/e | 30d ago |
| CVE-2026-65542 | 8.8 | — | — | — | — | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | 30d ago |
| CVE-2026-28111 | 8.8 | — | — | — | — | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | 30d ago |
| CVE-2026-64598 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_al | 31d ago |
| CVE-2026-64586 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device | 31d ago |
| CVE-2026-15991 | 8.8 | — | — | — | — | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid | 31d ago |
| CVE-2026-68746 | 8.8 | — | — | — | livebook / livebook | Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network cli | 31d ago |
| CVE-2026-66298 | 8.8 | — | — | — | livebook / livebook | Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trig | 31d ago |
| CVE-2026-9201 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryp | 31d ago |
| CVE-2026-8478 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to | 31d ago |
| CVE-2026-8182 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the s | 31d ago |
| CVE-2026-17632 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to | 31d ago |
| CVE-2026-70432 | 8.8 | — | — | — | — | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allow | 31d ago |
| CVE-2026-70431 | 8.8 | — | — | — | — | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate w | 31d ago |
| CVE-2026-20312 | 8.8 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN enginee | 31d ago |
| CVE-2026-20200 | 8.8 | — | — | — | cisco / unified computing system | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker w | 31d ago |
| CVE-2026-17626 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose se | 31d ago |
| CVE-2026-17623 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands du | 31d ago |
| CVE-2026-15572 | 8.8 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. | 31d ago |
| CVE-2026-67623 | 8.8 | — | — | — | — | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitra | 31d ago |
| CVE-2026-71291 | 8.8 | — | — | — | — | Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension r | 31d ago |
| CVE-2026-71288 | 8.8 | — | — | — | — | Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamicall | 31d ago |
| CVE-2026-71287 | 8.8 | — | — | — | — | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . | 31d ago |
| CVE-2026-71281 | 8.8 | — | — | — | — | Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, a | 31d ago |
| CVE-2026-71243 | 8.8 | — | — | — | — | The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source | 31d ago |
| CVE-2026-71235 | 8.8 | — | — | — | — | Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed serv | 31d ago |
| CVE-2026-60009 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in | 31d ago |
| CVE-2026-6147 | 8.8 | — | — | — | — | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation | 32d ago |
| CVE-2026-55997 | 8.8 | — | — | — | — | Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. | 32d ago |
| CVE-2026-70375 | 8.8 | — | — | — | — | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. | 32d ago |
| CVE-2026-70374 | 8.8 | — | — | — | — | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail | 32d ago |
| CVE-2026-8761 | 8.8 | — | — | — | — | The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. | 32d ago |
| CVE-2026-18322 | 8.8 | — | — | — | — | The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and | 32d ago |
| CVE-2026-18898 | 8.8 | — | — | — | — | A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. | 32d ago |
| CVE-2026-18897 | 8.8 | — | — | — | — | A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. | 32d ago |
| CVE-2026-18895 | 8.8 | — | — | — | — | A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 32d ago |
| CVE-2026-70619 | 8.8 | — | — | — | — | Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin | 32d ago |
| CVE-2026-16793 | 8.8 | — | — | — | — | An improper neutralization of special elements used in an operating system command vulnerability was reported in L | 32d ago |
| CVE-2026-18787 | 8.8 | — | — | — | — | A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. | 32d ago |
| CVE-2026-15307 | 8.8 | — | — | — | djangoproject / django | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. | 32d ago |
| CVE-2026-69100 | 8.8 | — | — | — | — | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerabi | 32d ago |
| CVE-2026-67195 | 8.8 | — | — | — | — | Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute | 32d ago |
| CVE-2026-18650 | 8.8 | — | — | — | — | Missing Authorization vulnerability in HAVELSAN Inc. | 32d ago |
| CVE-2026-17070 | 8.8 | — | — | — | — | Missing Authorization vulnerability in HAVELSAN Inc. | 32d ago |
| CVE-2026-70373 | 8.8 | — | — | — | — | Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate b | 32d ago |
| CVE-2026-70372 | 8.8 | — | — | — | — | Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled requ | 32d ago |
| CVE-2026-70371 | 8.8 | — | — | — | — | Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled re | 32d ago |
| CVE-2026-70370 | 8.8 | — | — | — | — | Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line an | 32d ago |
| CVE-2026-70369 | 8.8 | — | — | — | — | Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the us | 32d ago |
| CVE-2026-64562 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEA | 33d ago |
| CVE-2026-64561 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *aft | 33d ago |
| CVE-2026-62870 | 8.8 | — | — | — | microsoft / 365 apps | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | 33d ago |
| CVE-2026-18733 | 8.8 | — | — | — | — | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote | 33d ago |
| CVE-2026-41453 | 8.8 | — | — | — | — | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticat | 33d ago |
| CVE-2026-18607 | 8.8 | — | — | — | — | A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. | 33d ago |
| CVE-2026-69096 | 8.8 | — | — | — | — | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend | 33d ago |
| CVE-2026-18600 | 8.8 | — | — | — | — | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. | 33d ago |