| CVE-2026-59257 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the leg | 59d ago |
| CVE-2026-56086 | 8.8 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 59d ago |
| CVE-2026-14495 | 8.8 | — | — | — | — | The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in al | 60d ago |
| CVE-2026-14489 | 8.8 | — | — | — | — | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation | 60d ago |
| CVE-2026-14482 | 8.8 | — | — | — | — | The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. | 60d ago |
| CVE-2026-14158 | 8.8 | — | — | — | — | The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc | 60d ago |
| CVE-2026-14380 | 8.8 | — | — | — | perl / dbi | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. | 60d ago |
| CVE-2026-48958 | 8.8 | — | — | — | joomla / joomla\! | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | 60d ago |
| CVE-2026-48957 | 8.8 | — | — | — | joomla / joomla\! | An improper access check allows unauthorized users to access com_privacy datasets. | 60d ago |
| CVE-2026-48948 | 8.8 | — | — | — | joomla / joomla\! | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | 60d ago |
| CVE-2026-23697 | 8.8 | — | — | — | — | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to ac | 60d ago |
| CVE-2026-44938 | 8.8 | — | — | — | — | A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys f | 60d ago |
| CVE-2026-13696 | 8.8 | — | — | — | — | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc | 61d ago |
| CVE-2026-14474 | 8.8 | — | — | — | — | A flaw was found in SSSD's LDAP sudo provider. | 61d ago |
| CVE-2026-11610 | 8.8 | — | — | — | — | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). | 61d ago |
| CVE-2026-34158 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-42200 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-42143 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34168 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34152 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34058 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34057 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34035 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34034 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-42204 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-42153 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34599 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-34153 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-25268 | 8.8 | — | — | — | qualcomm / wsa8835 firmware | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | 61d ago |
| CVE-2026-14536 | 8.8 | — | — | — | devolutions / devolutions server | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an | 61d ago |
| CVE-2026-46590 | 8.8 | — | — | — | apache / camel | Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. | 62d ago |
| CVE-2026-11962 | 8.8 | — | — | — | — | The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management | 62d ago |
| CVE-2026-11855 | 8.8 | — | — | — | — | The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests wh | 62d ago |
| CVE-2026-10830 | 8.8 | — | — | — | — | The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-reg | 62d ago |
| CVE-2026-9085 | 8.8 | — | — | — | — | Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Soft | 62d ago |
| CVE-2026-14721 | 8.8 | — | — | — | — | A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 63d ago |
| CVE-2026-14535 | 8.8 | — | — | — | trailofbits / fickling | In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally c | 63d ago |
| CVE-2026-14534 | 8.8 | — | — | — | trailofbits / fickling | Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _pos | 63d ago |
| CVE-2026-53360 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB | 64d ago |
| CVE-2026-53359 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due | 64d ago |
| CVE-2025-71380 | 8.8 | — | — | — | — | The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where | 64d ago |
| CVE-2026-57981 | 8.8 | — | — | — | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-57974 | 8.8 | — | — | — | microsoft / edge chromium | Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code | 64d ago |
| CVE-2026-56645 | 8.8 | — | — | — | microsoft / edge chromium | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over | 64d ago |
| CVE-2026-27775 | 8.8 | — | — | — | — | Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session | 64d ago |
| CVE-2026-14460 | 8.8 | — | — | — | — | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software all | 64d ago |
| CVE-2026-14459 | 8.8 | — | — | — | — | Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM | 64d ago |
| CVE-2026-10054 | 8.8 | — | — | — | — | In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over | 65d ago |
| CVE-2026-8247 | 8.8 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same lo | 65d ago |
| CVE-2026-54998 | 8.8 | — | — | — | microsoft / exchange online | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a ne | 65d ago |
| CVE-2026-59093 | 8.8 | — | — | — | weaviate / weaviate | Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions g | 65d ago |
| CVE-2026-56841 | 8.8 | — | — | — | ui / unifi protect | A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulne | 65d ago |
| CVE-2026-55114 | 8.8 | — | — | — | ui / unifi network application | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerabi | 65d ago |
| CVE-2026-54404 | 8.8 | — | — | — | ui / unifi dream machine beast firmware | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Inject | 65d ago |
| CVE-2026-53358 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close chan | 65d ago |
| CVE-2026-57766 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. | 66d ago |
| CVE-2026-57759 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. | 66d ago |
| CVE-2026-56037 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. | 66d ago |
| CVE-2026-27414 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. | 66d ago |
| CVE-2026-27060 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. | 66d ago |