| CVE-2026-16366 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the DOM: Navigation component. | 46d ago |
| CVE-2026-16365 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the DOM: Workers component. | 46d ago |
| CVE-2026-16362 | 8.8 | — | — | — | mozilla / firefox | Use-after-free in the WebRTC: Audio/Video component. | 46d ago |
| CVE-2026-11767 | 8.8 | — | — | — | — | The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values | 47d ago |
| CVE-2026-15904 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced | 47d ago |
| CVE-2026-15903 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute a | 47d ago |
| CVE-2026-15902 | 8.8 | — | — | — | google / chrome | Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary cod | 47d ago |
| CVE-2026-53593 | 8.8 | — | — | — | — | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. | 47d ago |
| CVE-2026-63108 | 8.8 | — | — | — | — | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows | 47d ago |
| CVE-2026-12341 | 8.8 | — | — | — | sailpoint / identityiq | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access t | 47d ago |
| CVE-2026-64206 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work befor | 47d ago |
| CVE-2026-44178 | 8.8 | — | — | — | neutrinolabs / xrdp | xrdp is an open source RDP server. | 47d ago |
| CVE-2026-25039 | 8.8 | — | — | — | — | Parsec is a cloud-based application for simple and cryptographically secure file sharing. | 47d ago |
| CVE-2026-21824 | 8.8 | — | — | — | — | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user | 47d ago |
| CVE-2026-63090 | 8.8 | — | — | — | proftpd / proftpd | ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module tha | 47d ago |
| CVE-2026-16248 | 8.8 | — | — | — | — | A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. | 47d ago |
| CVE-2026-63763 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. | 47d ago |
| CVE-2026-63757 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method retu | 47d ago |
| CVE-2026-10081 | 8.8 | — | — | — | — | The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review cont | 48d ago |
| CVE-2026-64178 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bne | 48d ago |
| CVE-2026-64153 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value | 48d ago |
| CVE-2026-64138 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descrip | 48d ago |
| CVE-2026-64124 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: devmem: reject dma-buf bind with non-page | 48d ago |
| CVE-2026-64117 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: capture fast-RX rate before me | 48d ago |
| CVE-2026-64115 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix UAF when peer resets connectio | 48d ago |
| CVE-2026-64109 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail->len in unix_str | 48d ago |
| CVE-2026-64096 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_ | 48d ago |
| CVE-2026-64093 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer | 48d ago |
| CVE-2026-64088 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative tt_buff_len batad | 48d ago |
| CVE-2026-64042 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting | 48d ago |
| CVE-2026-64030 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80 | 48d ago |
| CVE-2026-64010 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: Fix use-after-free race in nfc_llcp | 48d ago |
| CVE-2026-63976 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: clear chan->ident on ECRED r | 48d ago |
| CVE-2026-63975 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix possible crash on l2cap_ | 48d ago |
| CVE-2026-63974 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUE | 48d ago |
| CVE-2026-63947 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: fix missing length checks in | 48d ago |
| CVE-2026-63946 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix UAF in iso_recv_frame iso_ | 48d ago |
| CVE-2026-63944 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix UAF in hci_le_create_ | 48d ago |
| CVE-2026-63941 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly cap ZCR_EL2 provided by | 48d ago |
| CVE-2026-63937 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Use READ_ONCE() when reading entries | 48d ago |
| CVE-2026-63923 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbo | 48d ago |
| CVE-2026-63921 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevpriva | 48d ago |
| CVE-2026-63919 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transp | 48d ago |
| CVE-2026-63917 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink() | 48d ago |
| CVE-2026-63916 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: Fix OOB write in wacom_hid_set_dev | 48d ago |
| CVE-2026-63915 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nfc: hci: fix out-of-bounds read in HCP header | 48d ago |
| CVE-2026-63885 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/gem: fix race between change_handle and ha | 48d ago |
| CVE-2026-63866 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Clear wcid pointer in mt79 | 48d ago |
| CVE-2026-63865 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Drop task_to_inode and inet_conn_establis | 48d ago |
| CVE-2026-63863 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: Fix unbalanced unlock in drm_gpusv | 48d ago |
| CVE-2026-63832 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: add wcid publish check in mt76_sta | 48d ago |
| CVE-2026-63831 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: add skb_cow_data() before in | 48d ago |
| CVE-2026-63829 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ip_gre: require CAP_NET_ADMIN in the devi | 48d ago |
| CVE-2026-63807 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot be | 48d ago |
| CVE-2026-63801 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aea | 48d ago |
| CVE-2026-63796 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descripto | 48d ago |
| CVE-2026-53375 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patche | 49d ago |
| CVE-2026-53374 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allo | 49d ago |
| CVE-2026-11826 | 8.8 | — | — | — | — | OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. | 49d ago |
| CVE-2025-71390 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames | 49d ago |