| CVE-2026-13125 | 8.8 | — | — | — | — | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that | 66d ago |
| CVE-2026-14432 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 66d ago |
| CVE-2026-14431 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 66d ago |
| CVE-2026-14430 | 8.8 | — | — | — | google / chrome | Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code | 66d ago |
| CVE-2026-14422 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia | 66d ago |
| CVE-2026-14415 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced | 66d ago |
| CVE-2026-14407 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar | 66d ago |
| CVE-2026-14403 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 66d ago |
| CVE-2026-14395 | 8.8 | — | — | — | google / chrome | Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary c | 66d ago |
| CVE-2026-14394 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap | 66d ago |
| CVE-2026-14393 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code i | 66d ago |
| CVE-2026-14385 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform | 66d ago |
| CVE-2026-14383 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar | 66d ago |
| CVE-2026-58452 | 8.8 | — | — | — | — | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability | 66d ago |
| CVE-2026-57516 | 8.8 | — | — | — | anyscale / ray | Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attacker | 66d ago |
| CVE-2026-34105 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php | 66d ago |
| CVE-2026-34104 | 8.8 | — | — | — | — | Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (lin | 66d ago |
| CVE-2026-34103 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line | 66d ago |
| CVE-2026-34102 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (l | 66d ago |
| CVE-2026-34101 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line | 66d ago |
| CVE-2026-34100 | 8.8 | — | — | — | — | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17) | 66d ago |
| CVE-2026-8857 | 8.8 | — | — | — | mediawiki / mediawiki | A vulnerability in Wikimedia Foundation timeline. | 66d ago |
| CVE-2026-13706 | 8.8 | — | — | — | mediawiki / mediawiki | Improper input validation vulnerability in Wikimedia Foundation UrlShortener. | 66d ago |
| CVE-2026-5136 | 8.8 | — | — | — | redhat / satellite | A flaw was found in Foreman. | 67d ago |
| CVE-2026-53354 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various | 67d ago |
| CVE-2026-13228 | 8.8 | — | — | — | — | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privileg | 67d ago |
| CVE-2026-12224 | 8.8 | — | — | — | — | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in | 67d ago |
| CVE-2026-12158 | 8.8 | — | — | — | — | The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Fo | 67d ago |
| CVE-2026-7838 | 8.8 | — | — | — | uvnc / ultravnc | UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol | 67d ago |
| CVE-2026-53488 | 8.8 | — | — | — | linuxfoundation / containerd | containerd is an open-source container runtime. | 67d ago |
| CVE-2026-57995 | 8.8 | — | — | — | — | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that all | 67d ago |
| CVE-2026-56247 | 8.8 | — | — | — | — | Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope | 67d ago |
| CVE-2026-56230 | 8.8 | — | — | — | — | Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts t | 67d ago |
| CVE-2026-14149 | 8.8 | — | — | — | google / chrome | Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbi | 67d ago |
| CVE-2026-14108 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary co | 67d ago |
| CVE-2026-14107 | 8.8 | — | — | — | google / chrome | Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrar | 67d ago |
| CVE-2026-14102 | 8.8 | — | — | — | google / chrome | Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially explo | 67d ago |
| CVE-2026-14099 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who conv | 67d ago |
| CVE-2026-14091 | 8.8 | — | — | — | google / chrome | Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary | 67d ago |
| CVE-2026-14087 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had | 67d ago |
| CVE-2026-14086 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execut | 67d ago |
| CVE-2026-14084 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote | 67d ago |
| CVE-2026-14078 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote atta | 67d ago |
| CVE-2026-14067 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to execu | 67d ago |
| CVE-2026-14041 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to per | 67d ago |
| CVE-2026-14040 | 8.8 | — | — | — | google / chrome | Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to i | 67d ago |
| CVE-2026-14036 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to | 67d ago |
| CVE-2026-14027 | 8.8 | — | — | — | google / chrome | Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to | 67d ago |
| CVE-2026-14025 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a u | 67d ago |
| CVE-2026-14024 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a | 67d ago |
| CVE-2026-14009 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to pot | 67d ago |
| CVE-2026-14006 | 8.8 | — | — | — | google / chrome | Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrar | 67d ago |
| CVE-2026-14005 | 8.8 | — | — | — | google / chrome | Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinc | 67d ago |
| CVE-2026-13967 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary | 67d ago |
| CVE-2026-13965 | 8.8 | — | — | — | google / chrome | Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary co | 67d ago |
| CVE-2026-13938 | 8.8 | — | — | — | google / chrome | Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of b | 67d ago |
| CVE-2026-13928 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote | 67d ago |
| CVE-2026-13918 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to poten | 67d ago |
| CVE-2026-13915 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who conv | 67d ago |
| CVE-2026-13903 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to | 67d ago |