| CVE-2026-82882 | 8.8 | high | — | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, a | 5d ago |
| CVE-2026-83596 | 8.8 | high | — | A flaw was found in WebKitGTK. | 5d ago |
| CVE-2026-82908 | 8.8 | high | — | A vulnerability was found in MSI Dragon Center up to 2.0.155.0. | 5d ago |
| CVE-2026-83497 | 8.8 | high | — | Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin all | 5d ago |
| CVE-2026-79744 | 8.8 | high | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 5d ago |
| CVE-2026-82807 | 8.8 | high | — | A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. | 5d ago |
| CVE-2026-77966 | 8.8 | high | — | The affected Ebyte product does not provide separation between limited and administrative management functions. | 5d ago |
| CVE-2026-82217 | 8.8 | high | — | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileC | 5d ago |
| CVE-2026-5956 | 8.8 | high | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hostin | 5d ago |
| CVE-2026-12894 | 8.8 | high | — | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages | 5d ago |
| CVE-2026-82680 | 8.8 | high | — | A weakness has been identified in D-Link DSM-G600 1.01. | 5d ago |
| CVE-2026-82628 | 8.8 | high | — | A vulnerability was found in Colorful iGameCenter 2.0.0.81. | 5d ago |
| CVE-2026-82642 | 8.8 | high | — | Readest is an open-source e-book reader built on Tauri. | 6d ago |
| CVE-2026-82635 | 8.8 | high | faberon / pake | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Down | 6d ago |
| CVE-2026-81660 | 8.8 | high | — | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or es | 6d ago |
| CVE-2026-76585 | 8.8 | high | — | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of c | 6d ago |
| CVE-2026-82450 | 8.8 | high | — | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality t | 7d ago |
| CVE-2026-82447 | 8.8 | high | — | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first | 7d ago |
| CVE-2026-81532 | 8.8 | high | — | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a posit | 8d ago |
| CVE-2026-18729 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to | 8d ago |
| CVE-2026-82278 | 8.8 | high | — | BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows | 8d ago |
| CVE-2026-81849 | 8.8 | high | — | Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent | 8d ago |
| CVE-2026-72984 | 8.8 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 8d ago |
| CVE-2026-55521 | 8.8 | high | — | Yamcs is a mission control framework. | 8d ago |
| CVE-2026-55485 | 8.8 | high | — | Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. | 8d ago |
| CVE-2026-80724 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from | 8d ago |
| CVE-2026-80722 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params | 8d ago |
| CVE-2026-80721 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon refere | 8d ago |
| CVE-2026-80692 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_ | 8d ago |
| CVE-2026-80683 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: give the socket its own sco_co | 8d ago |
| CVE-2026-80672 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix u16 truncation of restart-area lengt | 8d ago |
| CVE-2026-80638 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_remove | 8d ago |
| CVE-2026-80635 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from short trigger | 8d ago |
| CVE-2026-80633 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: iommufd: Take dma_resv lock before dma_buf_unp | 8d ago |
| CVE-2026-80608 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix iommu domain lifetime race | 8d ago |
| CVE-2026-80604 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix OOB read in hid_get_report for | 8d ago |
| CVE-2026-80601 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: gw: acquire ethernet header only a | 8d ago |
| CVE-2026-82072 | 8.8 | high | google / chrome | Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 9d ago |
| CVE-2026-78037 | 8.8 | high | — | Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. | 9d ago |
| CVE-2026-76060 | 8.8 | high | — | An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. | 9d ago |
| CVE-2026-75814 | 8.8 | high | — | The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management | 9d ago |
| CVE-2026-75419 | 8.8 | high | — | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. | 9d ago |
| CVE-2026-75339 | 8.8 | high | — | The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. | 9d ago |
| CVE-2026-39944 | 8.8 | high | — | Ceph is an open-source distributed storage platform providing object, block, and file storage. | 9d ago |
| CVE-2026-18965 | 8.8 | high | — | PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device | 9d ago |
| CVE-2026-76639 | 8.8 | high | — | Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows | 9d ago |
| CVE-2026-54721 | 8.8 | high | — | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. | 9d ago |
| CVE-2026-10036 | 8.8 | high | — | SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbit | 9d ago |
| CVE-2026-26899 | 8.8 | high | — | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). | 9d ago |
| CVE-2026-81625 | 8.8 | high | — | A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affe | 9d ago |
| CVE-2026-81581 | 8.8 | high | — | Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an | 9d ago |
| CVE-2026-81579 | 8.8 | high | — | In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver | 9d ago |
| CVE-2026-81271 | 8.8 | high | — | Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | 9d ago |
| CVE-2026-78257 | 8.8 | high | — | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | 9d ago |
| CVE-2026-78333 | 8.8 | high | — | The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthe | 9d ago |
| CVE-2026-77018 | 8.8 | high | — | The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor vali | 9d ago |
| CVE-2026-74770 | 8.8 | high | dell / powerprotect one | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in | 10d ago |
| CVE-2026-68861 | 8.8 | high | dell / powerprotect one | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in | 10d ago |
| CVE-2026-58474 | 8.8 | high | — | whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remot | 10d ago |
| CVE-2025-56798 | 8.8 | high | — | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier a | 10d ago |