| CVE-2026-18598 | 8.8 | — | — | — | — | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. | 33d ago |
| CVE-2026-67356 | 8.8 | — | — | — | — | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, a | 34d ago |
| CVE-2026-67343 | 8.8 | — | — | — | — | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allo | 35d ago |
| CVE-2026-67325 | 8.8 | — | — | — | gitpython project / gitpython | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-op | 35d ago |
| CVE-2026-16635 | 8.8 | — | — | — | — | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, | 36d ago |
| CVE-2026-15988 | 8.8 | — | — | — | — | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Req | 36d ago |
| CVE-2026-14596 | 8.8 | — | — | — | — | The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used | 36d ago |
| CVE-2026-15414 | 8.8 | — | — | — | — | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, an | 36d ago |
| CVE-2026-50986 | 8.8 | — | — | — | — | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). | 36d ago |
| CVE-2026-17346 | 8.8 | — | — | — | pgadmin / pgadmin 4 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pg | 36d ago |
| CVE-2026-16236 | 8.8 | — | — | — | — | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and includ | 37d ago |
| CVE-2026-13609 | 8.8 | — | — | — | — | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field va | 37d ago |
| CVE-2026-66420 | 8.8 | — | — | — | — | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthent | 37d ago |
| CVE-2026-65423 | 8.8 | — | — | — | — | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker | 37d ago |
| CVE-2026-12562 | 8.8 | — | — | — | — | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting | 37d ago |
| CVE-2026-67207 | 8.8 | — | — | — | — | Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows aut | 37d ago |
| CVE-2026-67206 | 8.8 | — | — | — | — | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authe | 37d ago |
| CVE-2026-66416 | 8.8 | — | — | — | — | Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perfor | 37d ago |
| CVE-2026-58222 | 8.8 | — | — | — | — | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Direct | 37d ago |
| CVE-2026-28813 | 8.8 | — | — | — | apache / jspwiki | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. | 37d ago |
| CVE-2026-14522 | 8.8 | — | — | — | ibm / app connect enterprise | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacke | 37d ago |
| CVE-2026-67351 | 8.8 | — | — | — | — | Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and | 37d ago |
| CVE-2026-54368 | 8.8 | — | — | — | — | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that | 37d ago |
| CVE-2026-22622 | 8.8 | — | — | — | — | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware co | 37d ago |
| CVE-2026-16526 | 8.8 | — | — | — | — | A flaw in the PCP linux_sockets module exposes an unsecured internal connection. | 38d ago |
| CVE-2026-67248 | 8.8 | — | — | — | asustor / data master | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. | 38d ago |
| CVE-2026-14356 | 8.8 | — | — | — | — | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, | 38d ago |
| CVE-2026-18017 | 8.8 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code | 38d ago |
| CVE-2026-18012 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 38d ago |
| CVE-2026-17989 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 38d ago |
| CVE-2026-17971 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti | 38d ago |
| CVE-2026-17969 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exe | 38d ago |
| CVE-2026-17967 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to poten | 38d ago |
| CVE-2026-17956 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex | 38d ago |
| CVE-2026-17951 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out | 38d ago |
| CVE-2026-17950 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attac | 38d ago |
| CVE-2026-17935 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitr | 38d ago |
| CVE-2026-17922 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex | 38d ago |
| CVE-2026-17920 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a | 38d ago |
| CVE-2026-17918 | 8.8 | — | — | — | google / chrome | Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code | 38d ago |
| CVE-2026-17899 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convin | 38d ago |
| CVE-2026-17894 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially | 38d ago |
| CVE-2026-17886 | 8.8 | — | — | — | google / chrome | Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially expl | 38d ago |
| CVE-2026-17884 | 8.8 | — | — | — | google / chrome | Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially | 38d ago |
| CVE-2026-17881 | 8.8 | — | — | — | google / chrome | Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary c | 38d ago |
| CVE-2026-17875 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 38d ago |
| CVE-2026-17868 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perfor | 38d ago |
| CVE-2026-17836 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 38d ago |
| CVE-2026-17807 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 38d ago |
| CVE-2026-17786 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker | 38d ago |
| CVE-2026-17784 | 8.8 | — | — | — | google / chrome | Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromis | 38d ago |
| CVE-2026-17778 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrar | 38d ago |
| CVE-2026-17752 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially ex | 38d ago |
| CVE-2026-17751 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exec | 38d ago |
| CVE-2026-17729 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the ren | 38d ago |
| CVE-2026-17725 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 38d ago |
| CVE-2026-17719 | 8.8 | — | — | — | google / chrome | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary cod | 38d ago |
| CVE-2026-17712 | 8.8 | — | — | — | google / chrome | Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code in | 38d ago |
| CVE-2026-17705 | 8.8 | — | — | — | google / chrome | Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary | 38d ago |
| CVE-2026-17694 | 8.8 | — | — | — | google / chrome | Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code | 38d ago |