| CVE-2026-47162 | 8.8 | — | — | — | vim / vim | Vim is an open source, command line text editor. | 86d ago |
| CVE-2026-46519 | 8.8 | — | — | — | — | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. | 86d ago |
| CVE-2025-24284 | 8.8 | — | — | — | apple / macos | This issue was addressed with improved checks to prevent unauthorized actions. | 86d ago |
| CVE-2026-7870 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. | 87d ago |
| CVE-2026-50223 | 8.8 | — | — | — | apache / ofbiz | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged au | 87d ago |
| CVE-2026-47342 | 8.8 | — | — | — | apache / ofbiz | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher p | 87d ago |
| CVE-2026-44693 | 8.8 | — | — | — | — | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. | 87d ago |
| CVE-2026-42305 | 8.8 | — | — | — | — | Dulwich is a pure-Python implementation of the Git file formats and protocols. | 87d ago |
| CVE-2026-46612 | 8.8 | — | — | — | — | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and | 87d ago |
| CVE-2026-20251 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3. | 87d ago |
| CVE-2026-45564 | 8.8 | — | — | — | — | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. | 88d ago |
| CVE-2026-53435exploited | 8.8 | 53.1% | 1/3 | +5d | jenkins / jenkins | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize ar | 88d ago |
| CVE-2026-52758 | 8.8 | — | — | — | nsa / ghidra | Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied valu | 88d ago |
| CVE-2026-52754 | 8.8 | — | — | — | nsa / ghidra | Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that | 88d ago |
| CVE-2026-52751 | 8.8 | — | — | — | nsa / ghidra | Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection c | 88d ago |
| CVE-2026-49498 | 8.8 | — | — | — | nsa / ghidra | Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionD | 88d ago |
| CVE-2026-8071 | 8.8 | — | — | — | — | The Anti-Spam by CleanTalk. | 88d ago |
| CVE-2025-58468 | 8.8 | — | — | — | qnap / notification center | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. | 88d ago |
| CVE-2026-47932 | 8.8 | — | — | — | adobe / coldfusion | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 88d ago |
| CVE-2026-36723 | 8.8 | — | — | — | — | An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated | 88d ago |
| CVE-2026-50636 | 8.8 | — | — | — | — | The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array in | 88d ago |
| CVE-2026-50635 | 8.8 | — | — | — | — | LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it | 88d ago |
| CVE-2026-9211 | 8.8 | — | — | — | netgear / cax30 firmware | An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its op | 89d ago |
| CVE-2026-49959 | 8.8 | — | — | — | — | Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated atta | 89d ago |
| CVE-2026-47653 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 89d ago |
| CVE-2026-47289 | 8.8 | — | — | — | microsoft / windows app | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 89d ago |
| CVE-2026-45648 | 8.8 | — | — | — | microsoft / windows server 2022 | Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over | 89d ago |
| CVE-2026-45504 | 8.8 | — | — | — | microsoft / exchange server | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privilege | 89d ago |
| CVE-2026-45484 | 8.8 | — | — | — | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileg | 89d ago |
| CVE-2026-45447 | 8.8 | — | — | — | openssl / openssl | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 si | 89d ago |
| CVE-2026-42985 | 8.8 | — | — | — | microsoft / remote desktop client | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 89d ago |
| CVE-2026-40371 | 8.8 | — | — | — | microsoft / dynamics 365 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an auth | 89d ago |
| CVE-2026-32193 | 8.8 | — | — | — | microsoft / azure kubernetes service | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Servi | 89d ago |
| CVE-2026-46317 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind | 89d ago |
| CVE-2026-46748 | 8.8 | — | — | — | siemens / sinec ins | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). | 89d ago |
| CVE-2026-46746 | 8.8 | — | — | — | siemens / sinec ins | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). | 89d ago |
| CVE-2026-8365 | 8.8 | — | — | — | — | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blo | 89d ago |
| CVE-2026-11616 | 8.8 | — | — | — | — | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to | 89d ago |
| CVE-2026-11572 | 8.8 | — | — | — | — | Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to | 89d ago |
| CVE-2026-11699 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potential | 89d ago |
| CVE-2026-11698 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potential | 89d ago |
| CVE-2026-11688 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute | 89d ago |
| CVE-2026-11687 | 8.8 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially ex | 89d ago |
| CVE-2026-11683 | 8.8 | — | — | — | google / chrome | Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrar | 89d ago |
| CVE-2026-11681 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially | 89d ago |
| CVE-2026-11680 | 8.8 | — | — | — | google / chrome | Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute a | 89d ago |
| CVE-2026-11674 | 8.8 | — | — | — | google / chrome | Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra | 89d ago |
| CVE-2026-11673 | 8.8 | — | — | — | google / chrome | Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arb | 89d ago |
| CVE-2026-11670 | 8.8 | — | — | — | google / chrome | Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code | 89d ago |
| CVE-2026-11664 | 8.8 | — | — | — | google / chrome | Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially explo | 89d ago |
| CVE-2026-11662 | 8.8 | — | — | — | google / chrome | Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary | 89d ago |
| CVE-2026-11657 | 8.8 | — | — | — | google / chrome | Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute ar | 89d ago |
| CVE-2026-11650 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code | 89d ago |
| CVE-2026-11649 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code | 89d ago |
| CVE-2026-11648 | 8.8 | — | — | — | google / chrome | Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to pote | 89d ago |
| CVE-2026-11646 | 8.8 | — | — | — | google / chrome | Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute ar | 89d ago |
| CVE-2026-11645zero day | 8.8 | 2.2% | 3/3 | 1d before | google / chrome | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a | 89d ago |
| CVE-2026-11637 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbit | 89d ago |
| CVE-2026-11633 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute a | 89d ago |
| CVE-2026-11630 | 8.8 | — | — | — | google / chrome | Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exp | 89d ago |