| CVE-2024-58362 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup o | 49d ago |
| CVE-2023-54366 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, an | 49d ago |
| CVE-2026-16097 | 8.8 | — | — | — | — | A vulnerability was found in Shibby Tomato 1.28. | 50d ago |
| CVE-2026-16096 | 8.8 | — | — | — | — | A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. | 50d ago |
| CVE-2026-16095 | 8.8 | — | — | — | — | A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. | 50d ago |
| CVE-2026-47871 | 8.8 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a directory traversal vulnerability. | 50d ago |
| CVE-2026-8056 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via th | 50d ago |
| CVE-2026-7755 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enfor | 50d ago |
| CVE-2026-7667 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an at | 50d ago |
| CVE-2026-50289 | 8.8 | — | — | — | systeminformation / systeminformation | systeminformation is a System and OS information library for node.js. | 50d ago |
| CVE-2026-14499 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands wit | 50d ago |
| CVE-2026-58195 | 8.8 | — | — | — | — | Agentic-Flow is an AI agent orchestration platform. | 50d ago |
| CVE-2026-60025 | 8.8 | — | — | — | — | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Boo | 50d ago |
| CVE-2026-63093 | 8.8 | — | — | — | anysphere / cursor | Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve | 50d ago |
| CVE-2026-13352 | 8.8 | — | — | — | — | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profi | 51d ago |
| CVE-2026-62238 | 8.8 | — | — | — | openremote / openremote | OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export end | 51d ago |
| CVE-2026-62233 | 8.8 | — | — | — | — | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa end | 51d ago |
| CVE-2026-62229 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allow | 51d ago |
| CVE-2026-62228 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-tr | 51d ago |
| CVE-2026-62223 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that a | 51d ago |
| CVE-2026-62218 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve featu | 51d ago |
| CVE-2026-62217 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. | 51d ago |
| CVE-2026-62207 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers t | 51d ago |
| CVE-2026-62203 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails | 51d ago |
| CVE-2026-62202 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that | 51d ago |
| CVE-2026-63085 | 8.8 | — | — | — | — | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authen | 51d ago |
| CVE-2025-45868 | 8.8 | — | — | — | — | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component | 51d ago |
| CVE-2026-5674 | 8.8 | — | — | — | — | A flaw was found in PipeWire, a multimedia server. | 51d ago |
| CVE-2026-15103 | 8.8 | — | — | — | — | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable | 52d ago |
| CVE-2026-15005 | 8.8 | — | — | — | — | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc | 52d ago |
| CVE-2026-13741 | 8.8 | — | — | — | — | The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in | 52d ago |
| CVE-2026-12525 | 8.8 | — | — | — | — | The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when savi | 52d ago |
| CVE-2026-62312 | 8.8 | — | — | — | — | 9Router is an AI router & token saver. | 52d ago |
| CVE-2026-49987 | 8.8 | — | — | — | yamadashy / repomix | Repomix is a tool that packs repositories into AI-friendly files. | 52d ago |
| CVE-2026-40501 | 8.8 | — | — | — | — | Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerabilit | 52d ago |
| CVE-2026-20150 | 8.8 | — | — | — | cisco / roomos | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team | 52d ago |
| CVE-2026-55242 | 8.8 | — | — | — | — | ERPNext is a free and open source Enterprise Resource Planning tool. | 52d ago |
| CVE-2026-45805 | 8.8 | — | — | — | — | Penpot is an open-source design tool for design and code collaboration. | 52d ago |
| CVE-2026-61457 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API medi | 53d ago |
| CVE-2026-58655 | 8.8 | — | — | — | — | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side | 53d ago |
| CVE-2026-57996 | 8.8 | — | — | — | — | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-S | 53d ago |
| CVE-2026-35152 | 8.8 | — | — | — | apache / fineract | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions u | 53d ago |
| CVE-2026-15804 | 8.8 | — | — | — | — | The HCM developed by MetaGuru has a SQL Injection vulnerability. | 53d ago |
| CVE-2026-59733 | 8.8 | — | — | — | rclone / rclone | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. | 53d ago |
| CVE-2026-50130 | 8.8 | — | — | — | pi-hole / pi-hole | Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. | 53d ago |
| CVE-2026-46640 | 8.8 | — | — | — | symfony / twig | Twig is a template language for PHP. | 53d ago |
| CVE-2026-15776 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute a | 53d ago |
| CVE-2026-15767 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to ex | 53d ago |
| CVE-2026-47303 | 8.8 | — | — | — | microsoft / .net | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privilege | 53d ago |
| CVE-2026-47301 | 8.8 | — | — | — | microsoft / configuration manager 2503 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges ove | 53d ago |
| CVE-2026-47300 | 8.8 | — | — | — | microsoft / .net | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate priv | 53d ago |
| CVE-2026-58626 | 8.8 | — | — | — | microsoft / windows 10 21h2 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-58594 | 8.8 | — | — | — | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-58534 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privile | 53d ago |
| CVE-2026-58277 | 8.8 | — | — | — | microsoft / sharepoint server | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a n | 53d ago |
| CVE-2026-57102 | 8.8 | — | — | — | microsoft / visual studio code | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to | 53d ago |
| CVE-2026-57094 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-57090 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-57087 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-56647 | 8.8 | — | — | — | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to el | 53d ago |