| CVE-2026-10943 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-10941 | 8.8 | — | — | — | google / chrome | Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute a | 93d ago |
| CVE-2026-10939 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-10936 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code i | 93d ago |
| CVE-2026-10935 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code i | 93d ago |
| CVE-2026-10932 | 8.8 | — | — | — | google / chrome | Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially e | 93d ago |
| CVE-2026-10928 | 8.8 | — | — | — | google / chrome | Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar | 93d ago |
| CVE-2026-10926 | 8.8 | — | — | — | google / chrome | Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to | 93d ago |
| CVE-2026-10923 | 8.8 | — | — | — | google / chrome | Use after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to ex | 93d ago |
| CVE-2026-10922 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote at | 93d ago |
| CVE-2026-10914 | 8.8 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute ar | 93d ago |
| CVE-2026-10913 | 8.8 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute ar | 93d ago |
| CVE-2026-10910 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code i | 93d ago |
| CVE-2026-10907 | 8.8 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially expl | 93d ago |
| CVE-2026-10904 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute ar | 93d ago |
| CVE-2026-10903 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary co | 93d ago |
| CVE-2026-10902 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary cod | 93d ago |
| CVE-2026-10897 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potential | 93d ago |
| CVE-2026-10896 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execu | 93d ago |
| CVE-2026-10895 | 8.8 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary cod | 93d ago |
| CVE-2026-10893 | 8.8 | — | — | — | google / chrome | Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar | 93d ago |
| CVE-2026-10891 | 8.8 | — | — | — | google / chrome | Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially ex | 93d ago |
| CVE-2026-10890 | 8.8 | — | — | — | google / chrome | Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to | 93d ago |
| CVE-2026-10888 | 8.8 | — | — | — | google / chrome | Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network | 93d ago |
| CVE-2026-10885 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execu | 93d ago |
| CVE-2026-10883 | 8.8 | — | — | — | google / chrome | Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit h | 93d ago |
| CVE-2026-10882 | 8.8 | — | — | — | google / chrome | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary c | 93d ago |
| CVE-2026-41236 | 8.8 | — | — | — | — | Froxlor is open source server administration software. | 93d ago |
| CVE-2026-5228 | 8.8 | — | — | — | — | Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Acce | 94d ago |
| CVE-2026-43985 | 8.8 | — | — | — | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. | 94d ago |
| CVE-2026-49194 | 8.8 | — | — | — | acer / connect m6e 5g firmware | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely an | 94d ago |
| CVE-2026-49190 | 8.8 | — | — | — | acer / connect m6e 5g firmware | The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permittin | 94d ago |
| CVE-2026-41860 | 8.8 | — | — | — | — | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. | 94d ago |
| CVE-2026-22055 | 8.8 | — | — | — | netapp / active iq onecollect | Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with | 94d ago |
| CVE-2026-22054 | 8.8 | — | — | — | netapp / active iq config advisor | Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker | 94d ago |
| CVE-2026-46264 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of | 95d ago |
| CVE-2026-36608 | 8.8 | — | — | — | — | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external por | 95d ago |
| CVE-2026-36607 | 8.8 | — | — | — | — | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the | 95d ago |
| CVE-2026-6657 | 8.8 | — | — | — | jupyter / jupyter server | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validatio | 95d ago |
| CVE-2026-35085 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system | 95d ago |
| CVE-2026-35084 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system a | 95d ago |
| CVE-2026-35083 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. | 95d ago |
| CVE-2026-35082 | 8.8 | — | — | — | mbs-solutions / universal gateway firmware | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insuff | 95d ago |
| CVE-2025-15656 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. | 95d ago |
| CVE-2025-14772 | 8.8 | — | — | — | abb / t-mac plus | Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. | 95d ago |
| CVE-2026-49443 | 8.8 | — | — | — | goauthentik / authentik | authentik is an open-source identity provider. | 95d ago |
| CVE-2026-49143 | 8.8 | — | — | — | — | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that al | 95d ago |
| CVE-2026-1829 | 8.8 | — | — | — | — | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions | 95d ago |
| CVE-2026-30652 | 8.8 | — | — | — | vivotek / fd8136 firmware | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vi | 96d ago |
| CVE-2026-30650 | 8.8 | — | — | — | vivotek / fd8136 firmware | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of | 96d ago |
| CVE-2026-10591 | 8.8 | — | — | — | amazon / kiro ide | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow | 96d ago |
| CVE-2026-7201 | 8.8 | — | — | — | progress / sitefinity | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2 | 96d ago |
| CVE-2026-7195 | 8.8 | — | — | — | progress / sitefinity | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4. | 96d ago |
| CVE-2025-53345 | 8.8 | — | — | — | — | Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in Thim | 96d ago |
| CVE-2026-1784 | 8.8 | — | — | — | redhat / openshift container platform | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. | 96d ago |
| CVE-2026-25277 | 8.8 | — | — | — | qualcomm / cq8750m firmware | Memory corruption while using Strongbox due to buffer overflow. | 96d ago |
| CVE-2026-25276 | 8.8 | — | — | — | qualcomm / cq8750m firmware | Memory corruption while using Strongbox due to missing bounds check. | 96d ago |
| CVE-2026-10293 | 8.8 | — | — | — | — | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. | 96d ago |
| CVE-2026-10292 | 8.8 | — | — | — | — | A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. | 96d ago |
| CVE-2026-9614 | 8.8 | — | — | — | — | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authent | 96d ago |