| CVE-2026-84668 | 8.8 | high | — | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file | 3d ago |
| CVE-2026-84650 | 8.8 | high | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, a | 3d ago |
| CVE-2026-84649 | 8.8 | high | — | In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, in | 3d ago |
| CVE-2026-84648 | 8.8 | high | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata ( | 3d ago |
| CVE-2026-84647 | 8.8 | high | — | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier | 3d ago |
| CVE-2026-84645 | 8.8 | high | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in i | 3d ago |
| CVE-2026-66842 | 8.8 | high | — | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accou | 3d ago |
| CVE-2026-84801 | 8.8 | high | — | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowin | 3d ago |
| CVE-2026-84796 | 8.8 | high | — | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers th | 3d ago |
| CVE-2026-84770 | 8.8 | high | — | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | 3d ago |
| CVE-2026-84764 | 8.8 | high | — | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | 3d ago |
| CVE-2026-81772 | 8.8 | high | — | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | 3d ago |
| CVE-2026-81769 | 8.8 | high | — | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. | 3d ago |
| CVE-2026-81283 | 8.8 | high | — | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | 3d ago |
| CVE-2026-14828 | 8.8 | high | — | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager | 3d ago |
| CVE-2026-81807 | 8.8 | high | — | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, al | 3d ago |
| CVE-2026-81737 | 8.8 | high | — | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated | 3d ago |
| CVE-2026-19116 | 8.8 | high | — | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserializ | 3d ago |
| CVE-2026-14357 | 8.8 | high | — | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0 | 3d ago |
| CVE-2026-84715 | 8.8 | high | — | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, | 4d ago |
| CVE-2026-84694 | 8.8 | high | — | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH | 4d ago |
| CVE-2026-84350 | 8.8 | high | google / chrome | Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social eng | 4d ago |
| CVE-2026-84347 | 8.8 | high | google / chrome | Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary co | 4d ago |
| CVE-2026-84326 | 8.8 | high | google / chrome | Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrar | 4d ago |
| CVE-2026-84482 | 8.8 | high | — | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and is | 4d ago |
| CVE-2026-73782 | 8.8 | high | hpe / arubaos-cx | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated re | 4d ago |
| CVE-2026-73753 | 8.8 | high | — | Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute | 4d ago |
| CVE-2026-73752 | 8.8 | high | hpe / arubaos-cx | An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. | 4d ago |
| CVE-2026-73751 | 8.8 | high | — | An authenticated user with low-privileged access could submit crafted input through the web-based management inter | 4d ago |
| CVE-2026-73750 | 8.8 | high | — | Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. | 4d ago |
| CVE-2026-71981 | 8.8 | high | — | Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute a | 4d ago |
| CVE-2026-73705 | 8.8 | high | arubanetworks / fabric composer | An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated lo | 4d ago |
| CVE-2026-73704 | 8.8 | high | arubanetworks / fabric composer | A command sanitization bypass exists in the API of HPE Networking Fabric Composer. | 4d ago |
| CVE-2026-73703 | 8.8 | high | arubanetworks / fabric composer | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthentic | 4d ago |
| CVE-2026-73702 | 8.8 | high | arubanetworks / fabric composer | A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. | 4d ago |
| CVE-2026-72649 | 8.8 | high | elastic / elasticsearch | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote cod | 4d ago |
| CVE-2026-51974 | 8.8 | high | — | An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 | 4d ago |
| CVE-2026-19591 | 8.8 | high | — | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain Power | 4d ago |
| CVE-2026-58566 | 8.8 | high | — | Dell PowerStore, an Incorrect Authorization vulnerability. | 4d ago |
| CVE-2026-84268 | 8.8 | high | — | A flaw was found in the SFTP backend in gvfs. | 4d ago |
| CVE-2026-84202 | 8.8 | high | — | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution | 4d ago |
| CVE-2026-79682 | 8.8 | high | — | Dell PowerStore contains a Command Injection vulnerability. | 4d ago |
| CVE-2026-58567 | 8.8 | high | — | Dell PowerStore contains an OS Command Injection vulnerability. | 4d ago |
| CVE-2026-10195 | 8.8 | high | — | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. | 4d ago |
| CVE-2026-79686 | 8.8 | high | — | Dell PowerStore contains a Protection Mechanism Failure vulnerability. | 4d ago |
| CVE-2026-58569 | 8.8 | high | — | Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. | 4d ago |
| CVE-2026-18630 | 8.8 | high | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine | 4d ago |
| CVE-2026-79684 | 8.8 | high | — | Dell PowerStore contains a Protection Mechanism Failure vulnerability. | 4d ago |
| CVE-2026-58572 | 8.8 | high | — | Dell PowerStore contains a Code Injection vulnerability. | 4d ago |
| CVE-2026-58571 | 8.8 | high | — | Dell PowerStore contains an OS Command Injection vulnerability. | 4d ago |
| CVE-2026-84131 | 8.8 | high | mozilla / firefox | Privilege escalation due to invalid pointer in the Graphics component. | 4d ago |
| CVE-2026-84128 | 8.8 | high | mozilla / firefox | Privilege escalation in the WebDriver BiDi component. | 4d ago |
| CVE-2026-84123 | 8.8 | high | mozilla / firefox | Privilege escalation due to use-after-free in the Graphics: WebGPU component. | 4d ago |
| CVE-2026-84117 | 8.8 | high | mozilla / firefox mobile | Privilege escalation in Firefox for Android. | 4d ago |
| CVE-2026-79683 | 8.8 | high | — | Dell PowerStore contains a Protection Mechanism Failure vulnerability. | 4d ago |
| CVE-2026-58575 | 8.8 | high | — | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. | 4d ago |
| CVE-2026-76111 | 8.8 | high | — | Dell PowerStore contains an Incorrect Authorization vulnerability. | 4d ago |
| CVE-2026-59681 | 8.8 | high | — | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configu | 4d ago |
| CVE-2026-19806 | 8.8 | high | — | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress | 4d ago |
| CVE-2026-65643 | 8.8 | high | cpanel / cpanel | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as roo | 5d ago |