| CVE-2026-52968 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: fix GAIT table indexing due to | 73d ago |
| CVE-2026-52952 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain | 73d ago |
| CVE-2026-57301 | 8.8 | — | — | — | jenkins / official owasp zap | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the ass | 74d ago |
| CVE-2026-57296 | 8.8 | — | — | — | — | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom | 74d ago |
| CVE-2026-57280 | 8.8 | — | — | — | jenkins / script security | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied t | 74d ago |
| CVE-2026-56232 | 8.8 | — | — | — | — | Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-l | 74d ago |
| CVE-2026-12242 | 8.8 | — | — | — | — | The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and in | 74d ago |
| CVE-2026-7761 | 8.8 | — | — | — | — | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in al | 74d ago |
| CVE-2026-52934 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packet | 74d ago |
| CVE-2026-52918 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_p | 74d ago |
| CVE-2026-4297 | 8.8 | — | — | — | — | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up t | 74d ago |
| CVE-2026-54639 | 8.8 | — | — | — | — | Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability start | 74d ago |
| CVE-2026-41862 | 8.8 | — | — | — | — | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted st | 74d ago |
| CVE-2026-56115 | 8.8 | — | — | — | bootimus / bootimus | Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged us | 74d ago |
| CVE-2026-44959 | 8.8 | — | — | — | — | A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. | 74d ago |
| CVE-2026-44790 | 8.8 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-34916 | 8.8 | — | — | — | — | A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could all | 74d ago |
| CVE-2026-33760 | 8.8 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-35018 | 8.8 | — | — | — | — | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulner | 75d ago |
| CVE-2026-10711 | 8.8 | — | — | — | — | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Tr | 75d ago |
| CVE-2026-8163 | 8.8 | — | — | — | — | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before us | 75d ago |
| CVE-2026-54232 | 8.8 | — | — | — | vllm / vllm | vLLM is an inference and serving engine for large language models (LLMs). | 75d ago |
| CVE-2026-44272 | 8.8 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elemen | 75d ago |
| CVE-2026-50178 | 8.8 | — | — | — | angular / angular language service | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. | 75d ago |
| CVE-2026-49241 | 8.8 | — | — | — | angular / angular language service | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. | 75d ago |
| CVE-2026-56425 | 8.8 | — | — | — | misp-project / misp | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 auth | 76d ago |
| CVE-2026-56424 | 8.8 | — | — | — | misp-project / misp | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wro | 76d ago |
| CVE-2026-56423 | 8.8 | — | — | — | misp-project / misp | MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. | 76d ago |
| CVE-2026-54099 | 8.8 | — | — | — | redhat / openshift container platform | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. | 76d ago |
| CVE-2026-8157 | 8.8 | — | — | — | — | The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating n | 76d ago |
| CVE-2026-12806 | 8.8 | — | — | — | — | A vulnerability has been found in Edimax BR-6478AC V2 1.23. | 76d ago |
| CVE-2026-56396 | 8.8 | — | — | — | — | phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoint | 77d ago |
| CVE-2026-52911 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound s | 77d ago |
| CVE-2026-56340 | 8.8 | — | — | — | vllm / vllm | vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. | 77d ago |
| CVE-2026-56216 | 8.8 | — | — | — | — | Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that all | 78d ago |
| CVE-2026-47645 | 8.8 | — | — | — | microsoft / 365 copilot | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorize | 78d ago |
| CVE-2026-32208 | 8.8 | — | — | — | microsoft / edge chromium | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows | 78d ago |
| CVE-2026-48715 | 8.8 | — | — | — | radvd.litech / radvd | radvd is a router advertisement daemon for IPv6. | 78d ago |
| CVE-2019-25758 | 8.8 | — | — | — | wdmtech / vbizz | Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attacke | 78d ago |
| CVE-2026-39998 | 8.8 | — | — | — | apache / apisix | Improper Input Validation vulnerability in Apache APISIX. | 79d ago |
| CVE-2026-12044 | 8.8 | — | — | — | pgadmin / pgadmin 4 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... | 79d ago |
| CVE-2026-56078 | 8.8 | — | — | — | — | PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent | 79d ago |
| CVE-2026-56075 | 8.8 | — | — | — | — | PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode | 79d ago |
| CVE-2026-55237 | 8.8 | — | — | — | — | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence | 79d ago |
| CVE-2026-54104 | 8.8 | — | — | — | — | The U.S. | 79d ago |
| CVE-2026-46580 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace wer | 79d ago |
| CVE-2026-44691 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. | 79d ago |
| CVE-2026-44688 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part | 79d ago |
| CVE-2026-8461 | 8.8 | — | — | — | — | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows d | 80d ago |
| CVE-2026-55741 | 8.8 | — | — | — | — | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration c | 80d ago |
| CVE-2026-9860 | 8.8 | — | — | — | — | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in al | 80d ago |
| CVE-2026-12407 | 8.8 | — | — | — | — | The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions | 80d ago |
| CVE-2025-71322 | 8.8 | — | — | — | — | PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to | 80d ago |
| CVE-2026-35065 | 8.8 | — | — | — | dell / powerflex manager | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vul | 81d ago |
| CVE-2026-55738 | 8.8 | — | — | — | — | A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. | 81d ago |
| CVE-2025-69130 | 8.8 | — | — | — | — | Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. | 81d ago |
| CVE-2025-66391 | 8.8 | — | — | — | — | In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for w | 81d ago |
| CVE-2026-54805 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. | 81d ago |
| CVE-2026-42629 | 8.8 | — | — | — | — | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. | 81d ago |
| CVE-2026-22342 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. | 81d ago |