| CVE-2026-13880 | 9.6 | — | — | — | google / chrome | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised | 67d ago |
| CVE-2026-13878 | 9.6 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compr | 67d ago |
| CVE-2026-13869 | 9.6 | — | — | — | google / chrome | Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had comp | 67d ago |
| CVE-2026-13861 | 9.6 | — | — | — | google / chrome | Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the r | 67d ago |
| CVE-2026-13859 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potenti | 67d ago |
| CVE-2026-13854 | 9.6 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had comprom | 67d ago |
| CVE-2026-13853 | 9.6 | — | — | — | google / chrome | Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised t | 67d ago |
| CVE-2026-13846 | 9.6 | — | — | — | google / chrome | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised | 67d ago |
| CVE-2026-13843 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe | 67d ago |
| CVE-2026-13798 | 9.6 | — | — | — | google / chrome | Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compr | 67d ago |
| CVE-2026-13797 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote | 67d ago |
| CVE-2026-13796 | 9.6 | — | — | — | google / chrome | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromis | 67d ago |
| CVE-2026-13792 | 9.6 | — | — | — | google / chrome | Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially | 67d ago |
| CVE-2026-13789 | 9.6 | — | — | — | google / chrome | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the re | 67d ago |
| CVE-2026-13785 | 9.6 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced | 67d ago |
| CVE-2026-13781 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attack | 67d ago |
| CVE-2026-13780 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attac | 67d ago |
| CVE-2026-10140 | 9.6 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API | 67d ago |
| CVE-2026-57498 | 9.6 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 68d ago |
| CVE-2026-54352 | 9.6 | — | — | — | budibase / budibase | Budibase is an open-source low-code platform. | 71d ago |
| CVE-2026-52780 | 9.6 | — | — | — | — | OpenProject is open-source, web-based project management software. | 71d ago |
| CVE-2026-33646 | 9.6 | — | — | — | — | mise manages dev tools like node, python, cmake, and terraform. | 71d ago |
| CVE-2025-11919 | 9.6 | — | — | — | — | The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users | 71d ago |
| CVE-2026-53943 | 9.6 | — | — | — | — | Ghost is a Node.js content management system. | 73d ago |
| CVE-2026-13032 | 9.6 | — | — | — | google / chrome | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potential | 73d ago |
| CVE-2026-13028 | 9.6 | — | — | — | google / chrome | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potential | 73d ago |
| CVE-2026-54588 | 9.6 | — | — | — | — | Poweradmin is a web-based DNS administration tool for PowerDNS server. | 74d ago |
| CVE-2026-11807 | 9.6 | — | — | — | — | A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. | 74d ago |
| CVE-2026-53662 | 9.6 | — | — | — | — | immich is a high performance self-hosted photo and video management solution. | 74d ago |
| CVE-2026-55447 | 9.6 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-54307 | 9.6 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-48519 | 9.6 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-10789 | 9.6 | — | — | — | autodesk / fusion | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension e | 75d ago |
| CVE-2026-28381 | 9.6 | — | — | — | grafana / snowflake | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against | 76d ago |
| CVE-2026-56397 | 9.6 | — | — | — | — | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing mal | 77d ago |
| CVE-2026-56395 | 9.6 | — | — | — | — | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing mal | 77d ago |
| CVE-2026-48582 | 9.6 | — | — | — | microsoft / exchange online | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a netw | 78d ago |
| CVE-2026-55742 | 9.6 | — | — | — | — | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration r | 80d ago |
| CVE-2026-55743 | 9.6 | — | — | — | — | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervis | 80d ago |
| CVE-2026-12440 | 9.6 | — | — | — | google / chrome | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker | 81d ago |
| CVE-2026-46911 | 9.6 | — | — | — | oracle / jd edwards enterpriseone job cost | Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Oracle JD Edwards (component: Job Costing | 81d ago |
| CVE-2026-46906 | 9.6 | — | — | — | oracle / jd edwards enterpriseone tools | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastruc | 81d ago |
| CVE-2026-46899 | 9.6 | — | — | — | oracle / enterprise command center framework | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Cor | 81d ago |
| CVE-2026-46861 | 9.6 | — | — | — | oracle / mysql ndb cluster | Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cluster: NDB Operator). | 81d ago |
| CVE-2026-46856 | 9.6 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Meta | 81d ago |
| CVE-2026-46853 | 9.6 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Meta | 81d ago |
| CVE-2026-46789 | 9.6 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-46786 | 9.6 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-12297 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape due to incorrect boundary conditions in the Networking component. | 82d ago |
| CVE-2026-12296 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape in the Security: Process Sandboxing component. | 82d ago |
| CVE-2026-12295 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape in the DOM: Navigation component. | 82d ago |
| CVE-2026-12294 | 9.6 | — | — | — | mozilla / firefox | Sandbox escape in the DOM: Workers component. | 82d ago |
| CVE-2026-52703 | 9.6 | — | — | — | — | Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. | 82d ago |
| CVE-2026-50883 | 9.6 | — | — | — | — | An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to ex | 82d ago |
| CVE-2026-50084 | 9.6 | — | — | — | aqara / cloud production api | The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for acc | 85d ago |
| CVE-2026-12027 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who ha | 86d ago |
| CVE-2026-46703 | 9.6 | — | — | — | — | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI conta | 87d ago |
| CVE-2026-53476 | 9.6 | — | — | — | kubev2v / assisted migration agent | A flaw was found in assisted-migration-agent. | 87d ago |
| CVE-2026-53474 | 9.6 | — | — | — | kebev2v / migration assessment | A flaw was found in migration-planner. | 87d ago |
| CVE-2026-53471 | 9.6 | — | — | — | kebev2v / migration assessment | A flaw was found in migration-planner. | 87d ago |