| CVE-2026-57371 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This i | 55d ago |
| CVE-2026-15548 | 8.8 | — | — | — | — | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. | 55d ago |
| CVE-2026-15545 | 8.8 | — | — | — | — | A vulnerability was identified in Shibby Tomato up to 1.28.0000. | 55d ago |
| CVE-2026-15544 | 8.8 | — | — | — | — | A vulnerability was determined in Shibby Tomato up to 1.28.0000. | 55d ago |
| CVE-2026-15543 | 8.8 | — | — | — | — | A vulnerability was found in Tenda CH22 1.0.0.1. | 55d ago |
| CVE-2026-61876 | 8.8 | — | — | — | — | LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent | 56d ago |
| CVE-2026-61875 | 8.8 | — | — | — | — | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inje | 56d ago |
| CVE-2026-59260 | 8.8 | — | — | — | — | OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated u | 56d ago |
| CVE-2026-15484 | 8.8 | — | — | — | — | A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. | 56d ago |
| CVE-2026-15483 | 8.8 | — | — | — | — | A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. | 56d ago |
| CVE-2026-15481 | 8.8 | — | — | — | — | A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. | 56d ago |
| CVE-2026-15480 | 8.8 | — | — | — | — | A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. | 56d ago |
| CVE-2026-57828 | 8.8 | — | — | — | phoca / download | Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extensio | 57d ago |
| CVE-2026-1359 | 8.8 | — | — | — | — | The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data | 57d ago |
| CVE-2026-15155 | 8.8 | — | — | — | — | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to A | 57d ago |
| CVE-2025-6784 | 8.8 | — | — | — | — | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0 | 57d ago |
| CVE-2026-2354 | 8.8 | — | — | — | — | The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type vali | 57d ago |
| CVE-2026-14262 | 8.8 | — | — | — | — | The Simple JWT Login – Allows you to use JWT on REST endpoints. | 57d ago |
| CVE-2026-13353 | 8.8 | — | — | — | — | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable t | 57d ago |
| CVE-2026-13756 | 8.8 | — | — | — | — | The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin | 57d ago |
| CVE-2026-44795 | 8.8 | — | — | — | linuxfoundation / spinnaker | Spinnaker is an open source, multi-cloud continuous delivery platform. | 57d ago |
| CVE-2026-57215 | 8.8 | — | — | — | broadcom / rabbitmq server | RabbitMQ is a messaging and streaming broker. | 57d ago |
| CVE-2026-6212 | 8.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. | 57d ago |
| CVE-2026-61461 | 8.8 | — | — | — | dify / dify | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows atta | 57d ago |
| CVE-2026-61460 | 8.8 | — | — | — | — | Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonContr | 57d ago |
| CVE-2025-30007 | 8.8 | — | — | — | hestiacp / control panel | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authe | 57d ago |
| CVE-2026-2398 | 8.8 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. | 57d ago |
| CVE-2026-54149 | 8.8 | — | — | — | — | MaxKB is an open-source AI assistant for enterprise. | 57d ago |
| CVE-2026-61434 | 8.8 | — | — | — | — | PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows | 57d ago |
| CVE-2026-59793 | 8.8 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | 57d ago |
| CVE-2026-54469 | 8.8 | — | — | — | dell / unisphere for powermax | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnera | 58d ago |
| CVE-2026-15070 | 8.8 | — | — | — | — | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve | 58d ago |
| CVE-2026-58143 | 8.8 | — | — | — | — | Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated a | 58d ago |
| CVE-2026-55207 | 8.8 | — | — | — | — | Pimcore is an Open Source Data & Experience Management Platform. | 58d ago |
| CVE-2026-59148 | 8.8 | — | — | — | — | Mockoon provides way to design and run mock APIs. | 58d ago |
| CVE-2026-13492 | 8.8 | — | — | — | — | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65 | 58d ago |
| CVE-2026-59734 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 58d ago |
| CVE-2026-58378 | 8.8 | — | — | — | — | Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. | 58d ago |
| CVE-2026-4275 | 8.8 | — | — | — | — | The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Requ | 59d ago |
| CVE-2026-47830 | 8.8 | — | — | — | — | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-priv | 59d ago |
| CVE-2026-47828 | 8.8 | — | — | — | cloudfoundry / bosh cli | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to th | 59d ago |
| CVE-2026-5523 | 8.8 | — | — | — | — | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, | 59d ago |
| CVE-2026-59723 | 8.8 | — | — | — | cline / cline | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. | 59d ago |
| CVE-2026-15133 | 8.8 | — | — | — | google / chrome | Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arb | 59d ago |
| CVE-2026-15132 | 8.8 | — | — | — | google / chrome | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 59d ago |
| CVE-2026-15129 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit | 59d ago |
| CVE-2026-15126 | 8.8 | — | — | — | google / chrome | Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 59d ago |
| CVE-2026-15125 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execut | 59d ago |
| CVE-2026-15123 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentia | 59d ago |
| CVE-2026-15121 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary c | 59d ago |
| CVE-2026-15118 | 8.8 | — | — | — | google / chrome | Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 59d ago |
| CVE-2026-15116 | 8.8 | — | — | — | google / chrome | Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary co | 59d ago |
| CVE-2026-15114 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to poten | 59d ago |
| CVE-2026-15112 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit | 59d ago |
| CVE-2026-15110 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to | 59d ago |
| CVE-2026-15107 | 8.8 | — | — | — | google / chrome | Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrar | 59d ago |
| CVE-2026-10037 | 8.8 | — | — | — | — | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. | 59d ago |
| CVE-2026-58253 | 8.8 | — | — | — | linuxfoundation / nats-server | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. | 59d ago |
| CVE-2026-60102 | 8.8 | — | — | — | — | Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_S | 59d ago |
| CVE-2026-15067 | 8.8 | — | — | — | — | Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL inje | 59d ago |