| CVE-2026-79188 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec | 11d ago |
| CVE-2026-79150 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arb | 11d ago |
| CVE-2026-79149 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary cod | 11d ago |
| CVE-2026-79140 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arb | 11d ago |
| CVE-2026-79138 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to po | 11d ago |
| CVE-2026-79131 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrar | 11d ago |
| CVE-2026-79130 | 9.6 | — | — | — | google / chrome | Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary co | 11d ago |
| CVE-2026-79129 | 9.6 | — | — | — | google / chrome | Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leverag | 11d ago |
| CVE-2026-79128 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arb | 11d ago |
| CVE-2026-79111 | 9.6 | — | — | — | google / chrome | Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially | 11d ago |
| CVE-2026-79091 | 9.6 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging | 11d ago |
| CVE-2026-79078 | 9.6 | — | — | — | google / chrome | Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engine | 11d ago |
| CVE-2026-79064 | 9.6 | — | — | — | google / chrome | Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging s | 11d ago |
| CVE-2026-79056 | 9.6 | — | — | — | google / chrome | Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially e | 11d ago |
| CVE-2026-79052 | 9.6 | — | — | — | google / chrome | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code | 11d ago |
| CVE-2026-79047 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engine | 11d ago |
| CVE-2026-79043 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec | 11d ago |
| CVE-2026-79026 | 9.6 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social e | 11d ago |
| CVE-2026-79019 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to po | 11d ago |
| CVE-2026-79012 | 9.6 | — | — | — | google / chrome | Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leverag | 11d ago |
| CVE-2026-78989 | 9.6 | — | — | — | google / chrome | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to pot | 11d ago |
| CVE-2026-78985 | 9.6 | — | — | — | google / chrome | Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker lev | 11d ago |
| CVE-2026-78964 | 9.6 | — | — | — | google / chrome | Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially | 11d ago |
| CVE-2026-78951 | 9.6 | — | — | — | google / chrome | Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbit | 11d ago |
| CVE-2026-78948 | 9.6 | — | — | — | google / chrome | Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary co | 11d ago |
| CVE-2026-78945 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engine | 11d ago |
| CVE-2026-78939 | 9.6 | — | — | — | google / chrome | Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised | 11d ago |
| CVE-2026-78937 | 9.6 | — | — | — | google / chrome | Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveragin | 11d ago |
| CVE-2026-78935 | 9.6 | — | — | — | google / chrome | Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacke | 11d ago |
| CVE-2026-78909 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engine | 11d ago |
| CVE-2026-78904 | 9.6 | — | — | — | google / chrome | Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute a | 11d ago |
| CVE-2026-78900 | 9.6 | — | — | — | google / chrome | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall | 11d ago |
| CVE-2026-78683 | 9.6 | — | — | — | nltk / nltk | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Tran | 12d ago |
| CVE-2026-76840 | 9.6 | — | — | — | — | RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an | 13d ago |
| CVE-2026-77087 | 9.6 | — | — | — | — | Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute | 16d ago |
| CVE-2026-69400 | 9.6 | — | — | — | microsoft / azure logic apps | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unaut | 16d ago |
| CVE-2026-28164 | 9.6 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forg | 17d ago |
| CVE-2026-11861 | 9.6 | — | — | — | freeipa / freeipa | A flaw was found in FreeIPA. | 17d ago |
| CVE-2026-53548 | 9.6 | — | — | — | — | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 17d ago |
| CVE-2026-53546 | 9.6 | — | — | — | — | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 17d ago |
| CVE-2026-55085 | 9.6 | — | — | — | — | Etherpad is a real-time collaborative editor. | 17d ago |
| CVE-2026-16903 | 9.6 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a d | 17d ago |
| CVE-2026-16835 | 9.6 | — | — | — | ibm / power system e1080 \(9080-hex\) firmware | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 throu | 17d ago |
| CVE-2026-16687 | 9.6 | — | — | — | ibm / power system e1180 \(9080-heu\) firmware | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 throu | 17d ago |
| CVE-2026-20318 | 9.6 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload enginee | 17d ago |
| CVE-2026-76036 | 9.6 | — | — | — | google / chrome | Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execut | 18d ago |
| CVE-2026-76035 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker | 18d ago |
| CVE-2026-71064 | 9.6 | — | — | — | oracle / database server | Vulnerability in the Portable Clusterware component of Oracle Database Server. | 18d ago |
| CVE-2026-71063 | 9.6 | — | — | — | oracle / database server | Vulnerability in the Portable Clusterware component of Oracle Database Server. | 18d ago |
| CVE-2026-70958 | 9.6 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 18d ago |
| CVE-2026-70846 | 9.6 | — | — | — | — | Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). | 18d ago |
| CVE-2026-70670 | 9.6 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62582 | 9.6 | — | — | — | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-62463 | 9.6 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Ma | 18d ago |
| CVE-2026-61001 | 9.6 | — | — | — | oracle / web services manager | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Secu | 18d ago |
| CVE-2026-60905 | 9.6 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 18d ago |
| CVE-2026-60861 | 9.6 | — | — | — | oracle / service delivery platform | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | 18d ago |
| CVE-2026-12564 | 9.6 | — | — | — | — | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. | 18d ago |
| CVE-2026-28192 | 9.6 | — | — | — | — | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | 19d ago |
| CVE-2026-75783 | 9.6 | — | — | — | — | A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. | 19d ago |