| CVE-2026-80049 | 8.8 | high | — | Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. | 11d ago |
| CVE-2026-55585 | 8.8 | high | — | QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code | 11d ago |
| CVE-2026-24170 | 8.8 | high | — | NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticate | 11d ago |
| CVE-2026-79784 | 8.8 | high | — | Vocos instantiates a class named by a configuration file without restricting which class may be named. | 11d ago |
| CVE-2026-57863 | 8.8 | high | — | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authentica | 11d ago |
| CVE-2026-79665 | 8.8 | high | — | Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in Req | 11d ago |
| CVE-2026-19949 | 8.8 | high | — | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore fun | 11d ago |
| CVE-2026-49050 | 8.8 | high | — | General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3. | 11d ago |
| CVE-2026-12878 | 8.8 | high | octopus / codefresh | In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Adm | 11d ago |
| CVE-2026-16601 | 8.8 | high | — | The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Li | 11d ago |
| CVE-2026-19892 | 8.8 | high | — | The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions | 12d ago |
| CVE-2026-78685 | 8.8 | high | — | Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. | 12d ago |
| CVE-2026-75574 | 8.8 | high | — | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action paramet | 12d ago |
| CVE-2026-56702 | 8.8 | high | — | Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin th | 12d ago |
| CVE-2026-32561 | 8.8 | high | — | Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | 12d ago |
| CVE-2026-32560 | 8.8 | high | — | Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 | 12d ago |
| CVE-2026-76836 | 8.8 | high | — | AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permiss | 12d ago |
| CVE-2026-76073 | 8.8 | high | — | Label Studio does not scope the annotation detail endpoint to the requesting user's organization. | 12d ago |
| CVE-2025-36940 | 8.8 | high | — | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation | 12d ago |
| CVE-2026-13212 | 8.8 | high | — | The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the use | 12d ago |
| CVE-2026-78376 | 8.8 | high | — | A flaw was found in WebKitGTK. | 12d ago |
| CVE-2026-76847 | 8.8 | high | — | act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-ar | 12d ago |
| CVE-2026-76841 | 8.8 | high | — | Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 | 12d ago |
| CVE-2026-59567 | 8.8 | high | — | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving | 12d ago |
| CVE-2026-59565 | 8.8 | high | — | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versi | 12d ago |
| CVE-2026-78317 | 8.8 | high | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 12d ago |
| CVE-2026-78316 | 8.8 | high | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 12d ago |
| CVE-2026-78315 | 8.8 | high | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 12d ago |
| CVE-2026-78314 | 8.8 | high | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 12d ago |
| CVE-2026-78170 | 8.8 | high | — | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. | 13d ago |
| CVE-2026-16149 | 8.8 | high | — | The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu | 14d ago |
| CVE-2026-0551 | 8.8 | high | — | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, | 14d ago |
| CVE-2026-74702 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpo | 14d ago |
| CVE-2026-74691 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before s | 14d ago |
| CVE-2026-74655 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: fix TX DMA buffer flush Whe | 14d ago |
| CVE-2026-74649 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix missing shared-key aut | 14d ago |
| CVE-2026-74629 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr | 14d ago |
| CVE-2026-74615 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: do not arm the ageing timer on a device | 14d ago |
| CVE-2026-74607 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Serialize accesses to the owner and | 14d ago |
| CVE-2026-71513 | 8.8 | high | — | NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pi | 14d ago |
| CVE-2026-59808 | 8.8 | high | — | AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() | 14d ago |
| CVE-2026-76789 | 8.8 | high | — | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and non | 14d ago |
| CVE-2026-19883 | 8.8 | high | — | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can le | 15d ago |
| CVE-2026-53528 | 8.8 | high | — | LeafWiki is a self-hosted wiki. | 15d ago |
| CVE-2026-53527 | 8.8 | high | — | LeafWiki is a self-hosted wiki. | 15d ago |
| CVE-2026-33240 | 8.8 | high | — | Combodo iTop is a web based IT service management tool. | 15d ago |
| CVE-2026-31936 | 8.8 | high | — | Combodo iTop is a web based IT service management tool. | 15d ago |
| CVE-2026-62316 | 8.8 | high | — | Microsoft UFO open-source framework for intelligent automation across devices and platforms. | 15d ago |
| CVE-2026-50538 | 8.8 | high | — | LibVNCClient is a library for easy implementation of a VNC client. | 15d ago |
| CVE-2026-77234 | 8.8 | high | amazon / freertos | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports t | 15d ago |
| CVE-2026-62677 | 8.8 | high | — | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. | 15d ago |
| CVE-2026-62675 | 8.8 | high | — | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. | 15d ago |
| CVE-2026-74580 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring | 15d ago |
| CVE-2026-63046 | 8.8 | high | apache / inlong | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. | 15d ago |
| CVE-2026-61400 | 8.8 | high | apache / cloudstack | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudS | 15d ago |
| CVE-2026-59799 | 8.8 | high | apache / cloudstack | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypas | 15d ago |
| CVE-2026-50112 | 8.8 | high | apache / cloudstack | SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-c | 15d ago |
| CVE-2026-47359 | 8.8 | high | apache / cloudstack | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache | 15d ago |
| CVE-2026-19449 | 8.8 | high | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local u | 16d ago |
| CVE-2026-18832 | 8.8 | high | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea | 16d ago |