| CVE-2026-13899 | 8.8 | — | — | — | google / chrome | Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code | 67d ago |
| CVE-2026-13898 | 8.8 | — | — | — | google / chrome | Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbit | 67d ago |
| CVE-2026-13897 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to | 67d ago |
| CVE-2026-13888 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrar | 67d ago |
| CVE-2026-13885 | 8.8 | — | — | — | google / chrome | Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arb | 67d ago |
| CVE-2026-13884 | 8.8 | — | — | — | google / chrome | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitra | 67d ago |
| CVE-2026-13870 | 8.8 | — | — | — | google / chrome | Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute | 67d ago |
| CVE-2026-13850 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe | 67d ago |
| CVE-2026-13848 | 8.8 | — | — | — | google / chrome | Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary cod | 67d ago |
| CVE-2026-13845 | 8.8 | — | — | — | google / chrome | Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code | 67d ago |
| CVE-2026-13835 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potential | 67d ago |
| CVE-2026-13830 | 8.8 | — | — | — | google / chrome | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute | 67d ago |
| CVE-2026-13825 | 8.8 | — | — | — | google / chrome | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit | 67d ago |
| CVE-2026-13821 | 8.8 | — | — | — | google / chrome | Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary co | 67d ago |
| CVE-2026-13817 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attack | 67d ago |
| CVE-2026-13815 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary cod | 67d ago |
| CVE-2026-13811 | 8.8 | — | — | — | google / chrome | Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code | 67d ago |
| CVE-2026-13805 | 8.8 | — | — | — | google / chrome | Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrar | 67d ago |
| CVE-2026-13788 | 8.8 | — | — | — | google / chrome | Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execu | 67d ago |
| CVE-2026-13786 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary cod | 67d ago |
| CVE-2026-13784 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to | 67d ago |
| CVE-2026-13783 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to | 67d ago |
| CVE-2026-13777 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remo | 67d ago |
| CVE-2026-58168 | 8.8 | — | — | — | — | DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to | 67d ago |
| CVE-2026-58165 | 8.8 | — | — | — | — | OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authent | 67d ago |
| CVE-2026-48307 | 8.8 | — | — | — | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabili | 67d ago |
| CVE-2026-27957 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 67d ago |
| CVE-2026-41053 | 8.8 | — | — | — | suse / rancher | Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider c | 68d ago |
| CVE-2026-11589 | 8.8 | — | — | — | — | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded fi | 68d ago |
| CVE-2026-34597 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 68d ago |
| CVE-2026-34594 | 8.8 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 68d ago |
| CVE-2026-43731 | 8.8 | — | — | — | apple / safari | A use-after-free issue was addressed with improved memory management. | 68d ago |
| CVE-2026-43715 | 8.8 | — | — | — | apple / safari | A use-after-free issue was addressed with improved memory management. | 68d ago |
| CVE-2026-43705 | 8.8 | — | — | — | apple / safari | A type confusion issue was addressed with improved checks. | 68d ago |
| CVE-2026-58000 | 8.8 | — | — | — | — | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the gene | 68d ago |
| CVE-2026-57999 | 8.8 | — | — | — | — | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that | 68d ago |
| CVE-2026-41052 | 8.8 | — | — | — | suse / rancher | Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher vers | 68d ago |
| CVE-2026-13749 | 8.8 | — | — | — | snowflake / snowflake cli | Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to | 68d ago |
| CVE-2026-13583 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax EW-7478APC 1.04. | 68d ago |
| CVE-2026-13582 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7478APC 1.04. | 68d ago |
| CVE-2026-13580 | 8.8 | — | — | — | — | A security vulnerability has been detected in Edimax EW-7478APC 1.04. | 68d ago |
| CVE-2026-55607 | 8.8 | — | — | — | anthropic / claude code | Claude Code is an agentic coding tool. | 68d ago |
| CVE-2026-40521 | 8.8 | — | — | — | — | FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows | 69d ago |
| CVE-2026-12856 | 8.8 | — | — | — | redhat / openshift dev spaces | A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. | 69d ago |
| CVE-2026-13564 | 8.8 | — | — | — | — | A vulnerability was found in Edimax EW-7478APC 1.04. | 69d ago |
| CVE-2026-13563 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax EW-7478APC 1.04. | 69d ago |
| CVE-2026-13562 | 8.8 | — | — | — | — | A flaw has been found in Edimax EW-7478APC 1.04. | 69d ago |
| CVE-2026-25707 | 8.8 | — | — | — | opensuse / libzypp | A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used | 69d ago |
| CVE-2026-13545 | 8.8 | — | — | — | dlink / dcs-935l firmware | A vulnerability has been found in D-Link DCS-935L 1.10.01. | 69d ago |
| CVE-2026-13539 | 8.8 | — | — | — | — | A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. | 69d ago |
| CVE-2026-13519 | 8.8 | — | — | — | — | A vulnerability was found in Tenda JD12L 16.03.53.23. | 69d ago |
| CVE-2026-13518 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda JD12L 16.03.53.23. | 69d ago |
| CVE-2026-13517 | 8.8 | — | — | — | — | A flaw has been found in Tenda JD12L 16.03.53.23. | 69d ago |
| CVE-2026-13516 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda JD12L 16.03.53.23. | 69d ago |
| CVE-2026-13515 | 8.8 | — | — | — | — | A security vulnerability has been detected in Tenda JD12L 16.03.53.23. | 69d ago |
| CVE-2026-53322 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling fu | 71d ago |
| CVE-2026-53281 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or | 71d ago |
| CVE-2026-52784 | 8.8 | — | — | — | — | OpenProject is open-source, web-based project management software. | 71d ago |
| CVE-2026-32833 | 8.8 | — | — | — | — | Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows | 71d ago |
| CVE-2026-57518 | 8.8 | — | — | — | — | Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: m | 71d ago |