| CVE-2026-62948 | 9.6 | — | — | — | openwrt / openwrt | OpenWrt is a Linux operating system targeting embedded devices. | 52d ago |
| CVE-2026-53513 | 9.6 | — | — | — | better-auth / better-auth\/sso | Better Auth is an authentication and authorization library for TypeScript. | 52d ago |
| CVE-2026-61451 | 9.6 | — | — | — | — | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_ | 53d ago |
| CVE-2026-48284 | 9.6 | — | — | — | adobe / coldfusion | ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution | 53d ago |
| CVE-2026-15773 | 9.6 | — | — | — | google / chrome | Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentiall | 53d ago |
| CVE-2026-48359 | 9.6 | — | — | — | adobe / experience manager | Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabi | 53d ago |
| CVE-2026-48259 | 9.6 | — | — | — | adobe / experience manager | Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in ar | 53d ago |
| CVE-2026-47428 | 9.6 | — | — | — | — | Vitest is a testing framework powered by Vite. | 53d ago |
| CVE-2026-50380 | 9.6 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-59891 | 9.6 | — | — | — | — | sigstore-js provides JavaScript libraries for interacting with Sigstore services. | 53d ago |
| CVE-2026-55008 | 9.6 | — | — | — | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 53d ago |
| CVE-2026-48561 | 9.6 | — | — | — | microsoft / 365 copilot | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edg | 53d ago |
| CVE-2026-11563 | 9.6 | — | — | — | — | The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before d | 54d ago |
| CVE-2026-14453 | 9.6 | — | — | — | — | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module | 55d ago |
| CVE-2026-59151 | 9.6 | — | — | — | prowler / prowler | Prowler is a cloud security platform. | 57d ago |
| CVE-2026-59792 | 9.6 | — | — | — | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handl | 57d ago |
| CVE-2026-13461 | 9.6 | — | — | — | — | When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version | 58d ago |
| CVE-2026-15113 | 9.6 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potent | 59d ago |
| CVE-2026-15062 | 9.6 | — | — | — | — | SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 coul | 59d ago |
| CVE-2026-57571 | 9.6 | — | — | — | kidocode / crawl4ai | Crawl4AI is an open-source LLM-friendly web crawler and scraper. | 61d ago |
| CVE-2026-58426 | 9.6 | — | — | — | — | Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-s | 64d ago |
| CVE-2026-22874 | 9.6 | — | — | — | — | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filt | 64d ago |
| CVE-2026-57625 | 9.6 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. | 66d ago |
| CVE-2026-14425 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a | 66d ago |
| CVE-2026-14424 | 9.6 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially per | 66d ago |
| CVE-2026-14423 | 9.6 | — | — | — | google / chrome | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a | 66d ago |
| CVE-2026-14420 | 9.6 | — | — | — | google / chrome | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia | 66d ago |
| CVE-2026-14419 | 9.6 | — | — | — | google / chrome | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a | 66d ago |
| CVE-2026-14417 | 9.6 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a | 66d ago |
| CVE-2026-14416 | 9.6 | — | — | — | google / chrome | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perfor | 66d ago |
| CVE-2026-14411 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attac | 66d ago |
| CVE-2026-14405 | 9.6 | — | — | — | google / chrome | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary cod | 66d ago |
| CVE-2026-14398 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a | 66d ago |
| CVE-2026-14397 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potential | 66d ago |
| CVE-2026-14392 | 9.6 | — | — | — | google / chrome | Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perfo | 66d ago |
| CVE-2026-14390 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a | 66d ago |
| CVE-2026-14387 | 9.6 | — | — | — | google / chrome | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform | 66d ago |
| CVE-2026-14382 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attac | 66d ago |
| CVE-2026-53492 | 9.6 | — | — | — | linuxfoundation / containerd | containerd is an open-source container runtime. | 66d ago |
| CVE-2026-14152 | 9.6 | — | — | — | google / chrome | Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had co | 67d ago |
| CVE-2026-14120 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had | 67d ago |
| CVE-2026-14113 | 9.6 | — | — | — | google / chrome | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had com | 67d ago |
| CVE-2026-14109 | 9.6 | — | — | — | google / chrome | Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had | 67d ago |
| CVE-2026-14106 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a re | 67d ago |
| CVE-2026-14101 | 9.6 | — | — | — | google / chrome | Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacke | 67d ago |
| CVE-2026-14097 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote att | 67d ago |
| CVE-2026-14095 | 9.6 | — | — | — | google / chrome | Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who h | 67d ago |
| CVE-2026-14093 | 9.6 | — | — | — | google / chrome | Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the r | 67d ago |
| CVE-2026-14056 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attac | 67d ago |
| CVE-2026-14055 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allo | 67d ago |
| CVE-2026-14044 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the | 67d ago |
| CVE-2026-14043 | 9.6 | — | — | — | google / chrome | Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromis | 67d ago |
| CVE-2026-14037 | 9.6 | — | — | — | google / chrome | Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had c | 67d ago |
| CVE-2026-14017 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who h | 67d ago |
| CVE-2026-13934 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a re | 67d ago |
| CVE-2026-13920 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a r | 67d ago |
| CVE-2026-13909 | 9.6 | — | — | — | google / chrome | Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who | 67d ago |
| CVE-2026-13901 | 9.6 | — | — | — | google / chrome | Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who ha | 67d ago |
| CVE-2026-13883 | 9.6 | — | — | — | google / chrome | Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a | 67d ago |
| CVE-2026-13882 | 9.6 | — | — | — | google / chrome | Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer pro | 67d ago |