| CVE-2026-64390 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: track the connection owning a byte-rang | 43d ago |
| CVE-2026-64382 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() re | 43d ago |
| CVE-2026-64366 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix slab-out-of-bounds write in wa | 43d ago |
| CVE-2026-64364 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access | 43d ago |
| CVE-2026-64313 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multip | 43d ago |
| CVE-2026-64280 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in | 43d ago |
| CVE-2026-61892 | 8.8 | — | — | — | — | Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. | 43d ago |
| CVE-2026-60134 | 8.8 | — | — | — | — | Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. | 43d ago |
| CVE-2026-66041 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_qui | 43d ago |
| CVE-2026-66040 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG | 43d ago |
| CVE-2026-66039 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio | 43d ago |
| CVE-2026-66036 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d | 43d ago |
| CVE-2026-66032 | 8.8 | — | — | — | libssh2 / libssh2 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function | 43d ago |
| CVE-2026-64255 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before f | 43d ago |
| CVE-2026-16801 | 8.8 | — | — | — | devolutions / powershell universal | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Unive | 43d ago |
| CVE-2026-16800 | 8.8 | — | — | — | devolutions / powershell universal | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Univer | 43d ago |
| CVE-2026-45813 | 8.8 | — | — | — | apache / nimble | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. | 43d ago |
| CVE-2026-16870 | 8.8 | — | — | — | — | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code | 44d ago |
| CVE-2026-16807 | 8.8 | — | — | — | google / chrome | Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially pe | 44d ago |
| CVE-2026-16806 | 8.8 | — | — | — | google / chrome | Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary c | 44d ago |
| CVE-2026-16805 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary co | 44d ago |
| CVE-2026-15212 | 8.8 | — | — | — | — | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi | 44d ago |
| CVE-2026-65917 | 8.8 | — | — | — | — | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerabili | 44d ago |
| CVE-2026-65690 | 8.8 | — | — | — | syncfusion / standalone report designer | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its | 44d ago |
| CVE-2026-65906 | 8.8 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | 44d ago |
| CVE-2026-65897 | 8.8 | — | — | — | — | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allow | 44d ago |
| CVE-2026-65608 | 8.8 | — | — | — | — | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. | 44d ago |
| CVE-2026-59541 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | 44d ago |
| CVE-2026-57785 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | 44d ago |
| CVE-2026-16745 | 8.8 | — | — | — | — | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). | 44d ago |
| CVE-2026-64876 | 8.8 | — | — | — | — | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Databa | 45d ago |
| CVE-2026-15017 | 8.8 | — | — | — | — | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in | 45d ago |
| CVE-2026-61246 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-60455 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-60439 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-60373 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-60368 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 45d ago |
| CVE-2026-64791 | 8.8 | — | — | — | — | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension M | 45d ago |
| CVE-2026-63685 | 8.8 | — | — | — | — | Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and repl | 45d ago |
| CVE-2026-63684 | 8.8 | — | — | — | — | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/exp | 45d ago |
| CVE-2026-63280 | 8.8 | — | — | — | — | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions | 45d ago |
| CVE-2025-50330 | 8.8 | — | — | — | — | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and e | 45d ago |
| CVE-2025-50327 | 8.8 | — | — | — | — | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execut | 45d ago |
| CVE-2025-50324 | 8.8 | — | — | — | — | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the One | 45d ago |
| CVE-2025-44090 | 8.8 | — | — | — | — | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a c | 45d ago |
| CVE-2025-44089 | 8.8 | — | — | — | — | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executin | 45d ago |
| CVE-2026-22049 | 8.8 | — | — | — | netapp / ontap | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a v | 45d ago |
| CVE-2026-64835 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder wi | 45d ago |
| CVE-2026-64832 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within | 45d ago |
| CVE-2026-65013 | 8.8 | — | — | — | — | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that al | 45d ago |
| CVE-2026-64831 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decod | 45d ago |
| CVE-2026-64830 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer tha | 45d ago |
| CVE-2026-49499 | 8.8 | — | — | — | dell / powerprotect data manager | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens v | 45d ago |
| CVE-2026-65603 | 8.8 | — | — | — | — | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authentica | 45d ago |
| CVE-2026-65602 | 8.8 | — | — | — | traefik / traefik | Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for Ing | 45d ago |
| CVE-2026-65601 | 8.8 | — | — | — | traefik / traefik | Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API pro | 45d ago |
| CVE-2026-65595 | 8.8 | — | — | — | n8n / n8n | n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module re | 45d ago |
| CVE-2026-65591 | 8.8 | — | — | — | n8n / n8n | n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. | 45d ago |
| CVE-2026-65016 | 8.8 | — | — | — | n8n / n8n | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO in | 45d ago |
| CVE-2026-65015 | 8.8 | — | — | — | n8n / n8n | n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-ex | 45d ago |