| CVE-2026-16410 | 9.8 | — | — | — | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 47d ago |
| CVE-2026-16408 | 9.8 | — | — | — | mozilla / firefox | Integer overflow in the Audio/Video: Playback component. | 47d ago |
| CVE-2026-16407 | 9.8 | — | — | — | mozilla / firefox | Mitigation bypass in the DOM: Service Workers component. | 47d ago |
| CVE-2026-16402 | 9.8 | — | — | — | mozilla / firefox | Integer overflow in the Graphics: ImageLib component. | 47d ago |
| CVE-2026-16395 | 9.8 | — | — | — | mozilla / firefox | Integer overflow in the Audio/Video component. | 47d ago |
| CVE-2026-16389 | 9.8 | — | — | — | mozilla / firefox | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. | 47d ago |
| CVE-2026-16388 | 9.8 | — | — | — | mozilla / firefox | Sandbox escape in the DOM: Networking component. | 47d ago |
| CVE-2026-16387 | 9.8 | — | — | — | mozilla / firefox | Site isolation issue in the Networking component. | 47d ago |
| CVE-2026-16383 | 9.8 | — | — | — | mozilla / firefox | Mitigation bypass in the DOM: Networking component. | 47d ago |
| CVE-2026-16382 | 9.8 | — | — | — | mozilla / firefox | Mitigation bypass in the DOM: Service Workers component. | 47d ago |
| CVE-2026-16377 | 9.8 | — | — | — | mozilla / firefox | Mitigation bypass in the PDF Viewer component. | 47d ago |
| CVE-2026-16375 | 9.8 | — | — | — | mozilla / firefox | Site isolation issue in the Networking: HTTP component. | 47d ago |
| CVE-2026-16369 | 9.8 | — | — | — | mozilla / firefox | Integer overflow in the JavaScript: WebAssembly component. | 47d ago |
| CVE-2026-16368 | 9.8 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the JavaScript: WebAssembly component. | 47d ago |
| CVE-2026-16363 | 9.8 | — | — | — | mozilla / firefox | JIT miscompilation in the JavaScript: WebAssembly component. | 47d ago |
| CVE-2026-16361 | 9.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Thunderbird ESR 140.12. | 47d ago |
| CVE-2026-16360 | 9.8 | — | — | — | mozilla / firefox | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. | 47d ago |
| CVE-2026-16358 | 9.8 | — | — | — | mozilla / firefox | Site isolation issue in the Graphics: WebRender component. | 47d ago |
| CVE-2026-16357 | 9.8 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics component. | 47d ago |
| CVE-2026-16356 | 9.8 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 47d ago |
| CVE-2026-16355 | 9.8 | — | — | — | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 47d ago |
| CVE-2026-16353 | 9.8 | — | — | — | mozilla / firefox | Invalid pointer in the DOM: Bindings (WebIDL) component. | 47d ago |
| CVE-2026-16352 | 9.8 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 47d ago |
| CVE-2026-16351 | 9.8 | — | — | — | mozilla / firefox | Sandbox escape due to use-after-free in the DOM: Navigation component. | 47d ago |
| CVE-2026-16350 | 9.8 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: cubeb component. | 47d ago |
| CVE-2026-16349 | 9.8 | — | — | — | mozilla / firefox | Same-origin policy bypass in the DOM: Navigation component. | 47d ago |
| CVE-2026-65008 | 9.8 | — | — | — | — | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src | 47d ago |
| CVE-2026-1617 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Comm | 47d ago |
| CVE-2026-64606 | 9.8 | — | — | — | apache / fory | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Jav | 47d ago |
| CVE-2026-64608 | 9.8 | — | — | — | apache / fory | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. | 47d ago |
| CVE-2026-13439 | 9.8 | — | — | — | — | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to | 47d ago |
| CVE-2026-64625 | 9.8 | — | — | — | — | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in do | 47d ago |
| CVE-2026-52656 | 9.8 | — | — | — | — | An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allow | 47d ago |
| CVE-2024-51315 | 9.8 | — | — | — | — | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /gof | 47d ago |
| CVE-2024-51314 | 9.8 | — | — | — | — | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /gof | 47d ago |
| CVE-2024-51312 | 9.8 | — | — | — | — | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /gof | 47d ago |
| CVE-2024-51313 | 9.8 | — | — | — | — | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /gof | 47d ago |
| CVE-2024-51311 | 9.8 | — | — | — | — | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /gof | 47d ago |
| CVE-2026-63767 | 9.8 | — | — | — | — | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerabi | 47d ago |
| CVE-2026-63766 | 9.8 | — | — | — | — | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, deno | 47d ago |
| CVE-2026-64193 | 9.8 | — | — | — | — | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. | 47d ago |
| CVE-2026-41252 | 9.8 | — | — | — | neutrinolabs / xrdp | xrdp is an open source RDP server. | 47d ago |
| CVE-2026-35048 | 9.8 | — | — | — | — | The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes | 47d ago |
| CVE-2026-63071 | 9.8 | — | — | — | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 48d ago |
| CVE-2026-62183 | 9.8 | — | — | — | apache / syncope | Improper Privilege Management vulnerability in Apache Syncope. | 48d ago |
| CVE-2026-57308 | 9.8 | — | — | — | apache / syncope | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Synco | 48d ago |
| CVE-2026-53421 | 9.8 | — | — | — | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 48d ago |
| CVE-2026-53405 | 9.8 | — | — | — | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 48d ago |
| CVE-2026-64620 | 9.8 | — | — | — | freerdp / freerdp | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp | 48d ago |
| CVE-2026-16235 | 9.8 | — | — | — | — | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. | 48d ago |
| CVE-2026-64162 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock init in i | 49d ago |
| CVE-2026-64160 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i | 49d ago |
| CVE-2026-64150 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock befor | 49d ago |
| CVE-2026-64142 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m | 49d ago |
| CVE-2026-64136 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb | 49d ago |
| CVE-2026-64132 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_e | 49d ago |
| CVE-2026-64125 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setti | 49d ago |
| CVE-2026-64122 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_repo | 49d ago |
| CVE-2026-64113 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast | 49d ago |
| CVE-2026-64102 | 9.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow bef | 49d ago |