| CVE-2026-17685 | 8.8 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary | 38d ago |
| CVE-2026-17678 | 8.8 | — | — | — | google / chrome | Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised | 38d ago |
| CVE-2026-17677 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker | 38d ago |
| CVE-2026-17665 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 38d ago |
| CVE-2026-17661 | 8.8 | — | — | — | google / chrome | Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 38d ago |
| CVE-2026-17658 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 38d ago |
| CVE-2026-5490 | 8.8 | — | — | — | — | DriveLock SQL Injection Privilege Escalation Vulnerability. | 38d ago |
| CVE-2026-18022 | 8.8 | — | — | — | pgvector project / pgvector | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bou | 38d ago |
| CVE-2026-65944 | 8.8 | — | — | — | rolandd / ro csvi | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | 38d ago |
| CVE-2026-65885zero day | 8.8 | 0.29% | 1/3 | same day | balbooa / gridbox | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods all | 38d ago |
| CVE-2026-14270 | 8.8 | — | — | — | — | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vul | 38d ago |
| CVE-2026-50622 | 8.8 | — | — | — | apache / atlas | Description: Missing Authorization in Apache Atlas. | 38d ago |
| CVE-2026-64557 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_ | 39d ago |
| CVE-2026-12144 | 8.8 | — | — | — | — | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an | 39d ago |
| CVE-2026-54653 | 8.8 | — | — | — | koxudaxi / datamodel-code-generator | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JS | 39d ago |
| CVE-2026-57510 | 8.8 | — | — | — | — | SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC hand | 39d ago |
| CVE-2026-16347 | 8.8 | — | — | — | — | MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against e | 39d ago |
| CVE-2026-49258 | 8.8 | — | — | — | — | Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. | 39d ago |
| CVE-2026-16771 | 8.8 | — | — | — | — | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authenticati | 39d ago |
| CVE-2026-15992 | 8.8 | — | — | — | — | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and includ | 39d ago |
| CVE-2026-66748 | 8.8 | — | — | — | — | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allow | 39d ago |
| CVE-2026-63727 | 8.8 | — | — | — | — | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability | 39d ago |
| CVE-2026-7187 | 8.8 | — | — | — | — | Missing authentication for critical function vulnerability in Universal Software Inc. | 39d ago |
| CVE-2026-62427 | 8.8 | — | — | — | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond | 39d ago |
| CVE-2026-62426 | 8.8 | — | — | — | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond | 39d ago |
| CVE-2026-14328 | 8.8 | — | — | — | — | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to | 39d ago |
| CVE-2026-14168 | 8.8 | — | — | — | — | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path | 40d ago |
| CVE-2026-14167 | 8.8 | — | — | — | — | A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level | 40d ago |
| CVE-2021-32087 | 8.8 | — | — | — | quest / kace systems management appliance | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. | 40d ago |
| CVE-2021-32085 | 8.8 | — | — | — | quest / kace systems management appliance | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. | 40d ago |
| CVE-2026-64783 | 8.8 | — | — | — | apple / safari | A use-after-free issue was addressed with improved memory management. | 40d ago |
| CVE-2026-64757 | 8.8 | — | — | — | apple / safari | A memory corruption issue was addressed with improved state management. | 40d ago |
| CVE-2026-64739 | 8.8 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64555 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hy | 40d ago |
| CVE-2026-64554 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale prevhdr pointer i | 40d ago |
| CVE-2026-43818 | 8.8 | — | — | — | apple / ipados | An integer overflow was addressed with improved input validation. | 40d ago |
| CVE-2026-28931 | 8.8 | — | — | — | apple / ipados | A buffer overflow was addressed with improved bounds checking. | 40d ago |
| CVE-2026-66014 | 8.8 | — | — | — | jfrog / artifactory | JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific | 40d ago |
| CVE-2026-65921 | 8.8 | — | — | — | jfrog / artifactory | A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be writ | 40d ago |
| CVE-2026-65617 | 8.8 | — | — | — | jfrog / artifactory | A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confi | 40d ago |
| CVE-2026-65616 | 8.8 | — | — | — | jfrog / artifactory | Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog admi | 40d ago |
| CVE-2026-56748 | 8.8 | — | — | — | cribl / cribl stream | Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote | 40d ago |
| CVE-2026-56747 | 8.8 | — | — | — | cribl / cribl stream | Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allo | 40d ago |
| CVE-2026-42017 | 8.8 | — | — | — | jfrog / artifactory | An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileg | 40d ago |
| CVE-2026-55578 | 8.8 | — | — | — | — | Pheditor is a single-file editor and file manager written in PHP. | 40d ago |
| CVE-2026-54540 | 8.8 | — | — | — | — | Pheditor is a single-file editor and file manager written in PHP. | 40d ago |
| CVE-2026-17568 | 8.8 | — | — | — | devolutions / devolutions server | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated n | 40d ago |
| CVE-2026-15962 | 8.8 | — | — | — | — | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, | 42d ago |
| CVE-2026-64522 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix eswitch mode block underflow on | 42d ago |
| CVE-2026-64516 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce1: Fix VCE 1 firmware size and o | 42d ago |
| CVE-2026-64475 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Release the VGA arbiter client on re | 42d ago |
| CVE-2026-64467 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64 stride when cleaning up | 42d ago |
| CVE-2026-64445 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow a | 42d ago |
| CVE-2026-64441 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_s | 42d ago |
| CVE-2026-64438 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in | 42d ago |
| CVE-2026-64437 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_l | 42d ago |
| CVE-2026-64434 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout b | 42d ago |
| CVE-2026-64408 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during n | 42d ago |
| CVE-2026-64396 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOC | 42d ago |
| CVE-2026-64394 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SM | 42d ago |