| CVE-2026-11629 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit | 89d ago |
| CVE-2026-46490 | 8.8 | — | — | — | samlify project / samlify | samlify is a Node.js library for SAML single sign-on. | 89d ago |
| CVE-2026-11557 | 8.8 | — | — | — | — | A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. | 89d ago |
| CVE-2026-11556 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. | 89d ago |
| CVE-2026-11553 | 8.8 | — | — | — | — | A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. | 89d ago |
| CVE-2026-39910 | 8.8 | — | — | — | — | STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged at | 90d ago |
| CVE-2026-25856 | 8.8 | — | — | — | — | OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authen | 90d ago |
| CVE-2026-25855 | 8.8 | — | — | — | — | OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users t | 90d ago |
| CVE-2026-25559 | 8.8 | — | — | — | — | OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows aut | 90d ago |
| CVE-2026-46656 | 8.8 | — | — | — | — | Bludit is a content management system. | 90d ago |
| CVE-2026-46480 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 90d ago |
| CVE-2026-46479 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 90d ago |
| CVE-2026-46478 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 90d ago |
| CVE-2026-46477 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 90d ago |
| CVE-2026-46476 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 90d ago |
| CVE-2026-46475 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 90d ago |
| CVE-2026-46444 | 8.8 | — | — | — | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 90d ago |
| CVE-2026-11528 | 8.8 | — | — | — | — | A vulnerability was found in Tenda AC18 15.03.05.05. | 90d ago |
| CVE-2026-11524 | 8.8 | — | — | — | — | A vulnerability has been found in Tenda W20E 15.11.0.6. | 90d ago |
| CVE-2026-11523 | 8.8 | — | — | — | — | A flaw has been found in Tenda W20E 15.11.0.6. | 90d ago |
| CVE-2026-11522 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda W20E 15.11.0.6. | 90d ago |
| CVE-2026-11517 | 8.8 | — | — | — | — | A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. | 90d ago |
| CVE-2026-11504 | 8.8 | — | — | — | — | A vulnerability was detected in Tenda CX12L 16.03.53.12. | 90d ago |
| CVE-2026-11503 | 8.8 | — | — | — | — | A security vulnerability has been detected in Tenda CX12L 16.03.53.12. | 90d ago |
| CVE-2026-11498 | 8.8 | — | — | — | — | A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. | 90d ago |
| CVE-2026-11413 | 8.8 | — | — | — | — | A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. | 92d ago |
| CVE-2026-7654 | 8.8 | — | — | — | — | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in ve | 92d ago |
| CVE-2026-11419 | 8.8 | — | — | — | altium / on-prem enterprise server | A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improp | 92d ago |
| CVE-2026-5415 | 8.8 | — | — | — | — | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin fo | 92d ago |
| CVE-2026-5411 | 8.8 | — | — | — | — | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin fo | 92d ago |
| CVE-2026-50733 | 8.8 | — | — | — | — | Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eva | 92d ago |
| CVE-2026-49493 | 8.8 | — | — | — | — | Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the | 92d ago |
| CVE-2026-49492 | 8.8 | — | — | — | — | Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does n | 92d ago |
| CVE-2026-48095 | 8.8 | — | — | — | 7-zip / 7-zip | 7-Zip is a file archiver with a high compression ratio. | 93d ago |
| CVE-2026-21837 | 8.8 | — | — | — | hcltech / digital experience | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. | 93d ago |
| CVE-2026-11307 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-11306 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-11305 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-11304 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit | 93d ago |
| CVE-2026-11303 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-11301 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to p | 93d ago |
| CVE-2026-11295 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attack | 93d ago |
| CVE-2026-11279 | 8.8 | — | — | — | google / chrome | Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitr | 93d ago |
| CVE-2026-11272 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed | 93d ago |
| CVE-2026-11262 | 8.8 | — | — | — | google / chrome | Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary | 93d ago |
| CVE-2026-11248 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to b | 93d ago |
| CVE-2026-11235 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker w | 93d ago |
| CVE-2026-11230 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar | 93d ago |
| CVE-2026-11211 | 8.8 | — | — | — | google / chrome | Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code | 93d ago |
| CVE-2026-11202 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote att | 93d ago |
| CVE-2026-11201 | 8.8 | — | — | — | google / chrome | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user t | 93d ago |
| CVE-2026-11191 | 8.8 | — | — | — | google / chrome | Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentia | 93d ago |
| CVE-2026-11188 | 8.8 | — | — | — | google / chrome | Use after free in USB in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially | 93d ago |
| CVE-2026-11179 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass si | 93d ago |
| CVE-2026-11177 | 8.8 | — | — | — | google / chrome | Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user t | 93d ago |
| CVE-2026-11175 | 8.8 | — | — | — | google / chrome | Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to | 93d ago |
| CVE-2026-11173 | 8.8 | — | — | — | google / chrome | Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised th | 93d ago |
| CVE-2026-11172 | 8.8 | — | — | — | google / chrome | Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attack | 93d ago |
| CVE-2026-11171 | 8.8 | — | — | — | google / chrome | Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary c | 93d ago |
| CVE-2026-11164 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary cod | 93d ago |