| CVE-2026-57659 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 version | 72d ago |
| CVE-2026-57527 | 8.8 | — | — | — | — | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that a | 72d ago |
| CVE-2026-56773 | 8.8 | — | — | — | — | Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to | 72d ago |
| CVE-2026-56055 | 8.8 | — | — | — | — | Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. | 72d ago |
| CVE-2026-56038 | 8.8 | — | — | — | — | Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions. | 72d ago |
| CVE-2026-56010 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | 72d ago |
| CVE-2026-56008 | 8.8 | — | — | — | — | Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. | 72d ago |
| CVE-2025-68052 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. | 72d ago |
| CVE-2026-50741 | 8.8 | — | — | — | revive-adserver / revive adserver | Bypass to the fix for CVE-2026-34916. | 72d ago |
| CVE-2026-56768 | 8.8 | — | — | — | — | Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing u | 72d ago |
| CVE-2026-56767 | 8.8 | — | — | — | — | Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook | 72d ago |
| CVE-2026-56766 | 8.8 | — | — | — | — | Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, P | 72d ago |
| CVE-2026-55698 | 8.8 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 72d ago |
| CVE-2026-50016 | 8.8 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 72d ago |
| CVE-2026-56053 | 8.8 | — | — | — | — | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. | 73d ago |
| CVE-2026-53277 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table | 73d ago |
| CVE-2026-53275 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processin | 73d ago |
| CVE-2026-53266 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite w | 73d ago |
| CVE-2026-53248 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata ds | 73d ago |
| CVE-2026-53240 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix use-after-free on first_skb i | 73d ago |
| CVE-2026-53232 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probin | 73d ago |
| CVE-2026-53200 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix handling of XN[0] when !FE | 73d ago |
| CVE-2026-53198 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_l | 73d ago |
| CVE-2026-53188 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_ | 73d ago |
| CVE-2026-53171 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix arithmetic issues in dma_len | 73d ago |
| CVE-2026-53170 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uniniti | 73d ago |
| CVE-2026-53159 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due | 73d ago |
| CVE-2026-5305 | 8.8 | — | — | — | — | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does | 73d ago |
| CVE-2026-12244 | 8.8 | — | — | — | nlnetlabs / nsd | If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS | 73d ago |
| CVE-2026-9155 | 8.8 | — | — | — | gnu / sed | OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to e | 73d ago |
| CVE-2026-9787 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9786 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9785 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9784 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9783 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9782 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9781 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9780 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. | 73d ago |
| CVE-2026-7570 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-7569 | 8.8 | — | — | — | quest / netvault backup | Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. | 73d ago |
| CVE-2026-9773 | 8.8 | — | — | — | unraid / unraid | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9772 | 8.8 | — | — | — | unraid / unraid | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-52800 | 8.8 | — | — | — | — | Gogs is an open source self-hosted Git service. | 73d ago |
| CVE-2026-49247 | 8.8 | — | — | — | — | Jellyfin is an open source self hosted media server. | 73d ago |
| CVE-2026-48793 | 8.8 | — | — | — | — | Jellyfin is an open source self hosted media server. | 73d ago |
| CVE-2026-13038 | 8.8 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execut | 73d ago |
| CVE-2026-13036 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary co | 73d ago |
| CVE-2026-13035 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute a | 73d ago |
| CVE-2026-13033 | 8.8 | — | — | — | google / chrome | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote att | 73d ago |
| CVE-2026-13031 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary co | 73d ago |
| CVE-2026-13027 | 8.8 | — | — | — | google / chrome | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exp | 73d ago |
| CVE-2026-13026 | 8.8 | — | — | — | google / chrome | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to | 73d ago |
| CVE-2026-48732 | 8.8 | — | — | — | — | Warp is an agentic development environment. | 73d ago |
| CVE-2026-48720 | 8.8 | — | — | — | — | Warp is an agentic development environment. | 73d ago |
| CVE-2026-48704 | 8.8 | — | — | — | — | Warp is an agentic development environment. | 73d ago |
| CVE-2026-53075 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for | 73d ago |
| CVE-2026-53072 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix locking in hci_conn_request_evt | 73d ago |
| CVE-2026-53071 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2c | 73d ago |
| CVE-2026-53057 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Add IOTINVAL after updating DDT/P | 73d ago |
| CVE-2026-53053 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix clone_alias() to use the origin | 73d ago |