| CVE-2026-53843 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device s | 81d ago |
| CVE-2026-44932 | 8.8 | — | — | — | — | Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by | 81d ago |
| CVE-2024-24909 | 8.8 | — | — | — | — | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in | 81d ago |
| CVE-2026-12291 | 8.8 | — | — | — | mozilla / firefox | Use-after-free in the Networking: HTTP component. | 82d ago |
| CVE-2026-12289 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Graphics: WebRender component. | 82d ago |
| CVE-2026-5416 | 8.8 | — | — | — | — | Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker ca | 82d ago |
| CVE-2026-8444 | 8.8 | — | — | — | — | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of th | 82d ago |
| CVE-2026-8443 | 8.8 | — | — | — | — | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' para | 82d ago |
| CVE-2026-6933 | 8.8 | — | — | — | — | The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in ve | 82d ago |
| CVE-2026-7273 | 8.8 | — | — | — | — | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.9 | 82d ago |
| CVE-2026-12161 | 8.8 | — | — | — | devolutions / remote desktop manager | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create | 82d ago |
| CVE-2026-48017 | 8.8 | — | — | — | — | DbGate is cross-platform database manager. | 82d ago |
| CVE-2026-49780 | 8.8 | — | — | — | — | Customer Privilege Escalation in Dokan <= 5.0.2 versions. | 82d ago |
| CVE-2026-48889 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Amelia <= 2.3 versions. | 82d ago |
| CVE-2026-42661 | 8.8 | — | — | — | — | Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. | 82d ago |
| CVE-2026-39579 | 8.8 | — | — | — | — | Contributor Privilege Escalation in B Blocks <= 2.0.31 versions. | 82d ago |
| CVE-2026-39532 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions. | 82d ago |
| CVE-2026-39478 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions. | 82d ago |
| CVE-2026-39474 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions. | 82d ago |
| CVE-2026-52720 | 8.8 | — | — | — | — | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). | 82d ago |
| CVE-2026-50884 | 8.8 | — | — | — | — | Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and acces | 82d ago |
| CVE-2026-36670 | 8.8 | — | — | — | — | A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips- | 82d ago |
| CVE-2026-5242 | 8.8 | — | — | — | — | Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. | 83d ago |
| CVE-2026-49111 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. | 83d ago |
| CVE-2026-49062 | 8.8 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recov | 83d ago |
| CVE-2016-20075 | 8.8 | — | — | — | — | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated | 83d ago |
| CVE-2026-12192 | 8.8 | — | — | — | — | A vulnerability was determined in GALAYOU Y4 1.0.0. | 83d ago |
| CVE-2026-12187 | 8.8 | — | — | — | — | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. | 83d ago |
| CVE-2026-12186 | 8.8 | — | — | — | — | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. | 83d ago |
| CVE-2026-12174 | 8.8 | — | — | — | dlink / dcs-935l firmware | A security vulnerability has been detected in D-Link DCS-935L 1.10.01. | 84d ago |
| CVE-2026-11769 | 8.8 | — | — | — | grafana / grafana operator | We have released version 5.24.0 of the Grafana Operator. | 85d ago |
| CVE-2026-53836 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that a | 85d ago |
| CVE-2026-53828 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows aut | 85d ago |
| CVE-2026-53822 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between | 85d ago |
| CVE-2026-53821 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pair | 85d ago |
| CVE-2026-34195 | 8.8 | — | — | — | — | Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause o | 85d ago |
| CVE-2026-42850 | 8.8 | — | — | — | kovidgoyal / kitty | Kitty is a cross-platform GPU based terminal. | 85d ago |
| CVE-2026-42947 | 8.8 | — | — | — | — | A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to si | 85d ago |
| CVE-2026-12043 | 8.8 | — | — | — | — | Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a r | 85d ago |
| CVE-2026-7387 | 8.8 | — | — | — | mattermost / mattermost server | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails t | 85d ago |
| CVE-2026-45833 | 8.8 | — | — | — | trychroma / chromadb | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated a | 86d ago |
| CVE-2026-45832 | 8.8 | — | — | — | trychroma / chromadb | All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the author | 86d ago |
| CVE-2026-45831 | 8.8 | — | — | — | trychroma / chromadb | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python proje | 86d ago |
| CVE-2026-45830 | 8.8 | — | — | — | trychroma / chromadb | A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authentica | 86d ago |
| CVE-2026-12059 | 8.8 | — | — | — | — | The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenti | 86d ago |
| CVE-2026-45170 | 8.8 | — | — | — | paloaltonetworks / idira privilege cloud connector | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration sce | 86d ago |
| CVE-2026-11933 | 8.8 | — | — | — | mongodb / mongodb | A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON docum | 86d ago |
| CVE-2026-45418 | 8.8 | — | — | — | — | ClipBucket v5 is an open source video sharing platform. | 86d ago |
| CVE-2026-45172 | 8.8 | — | — | — | paloaltonetworks / idira privileged session manager for ssh | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14 | 86d ago |
| CVE-2026-45171 | 8.8 | — | — | — | paloaltonetworks / idira privileged session manager | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager ( | 86d ago |
| CVE-2026-12035 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potential | 86d ago |
| CVE-2026-12020 | 8.8 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentiall | 86d ago |
| CVE-2026-12018 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker | 86d ago |
| CVE-2026-12007 | 8.8 | — | — | — | google / chrome | Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute ar | 86d ago |
| CVE-2026-53819 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspac | 86d ago |
| CVE-2026-53817 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers | 86d ago |
| CVE-2026-53811 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows | 86d ago |
| CVE-2026-53810 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can | 86d ago |
| CVE-2026-53807 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that all | 86d ago |
| CVE-2026-53806 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to | 86d ago |