| CVE-2026-85610 | 8.8 | — | — | — | — | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project member | 35d ago |
| CVE-2026-85604 | 8.8 | — | — | — | — | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort f | 35d ago |
| CVE-2026-85540 | 8.8 | — | — | — | — | DreamMaker developed by Interinfo has a SQL Injection vulnerability. | 36d ago |
| CVE-2026-85094 | 8.8 | — | — | — | — | The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a priv | 36d ago |
| CVE-2026-85452 | 8.8 | — | — | — | — | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where | 36d ago |
| CVE-2026-85053 | 8.8 | — | — | — | — | Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to ex | 36d ago |
| CVE-2026-85051 | 8.8 | — | — | — | — | Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitra | 36d ago |
| CVE-2026-85049 | 8.8 | — | — | — | — | Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code | 36d ago |
| CVE-2026-85046zero day | 8.8 | 48.9% | 3/3 | same day | google / chrome | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code i | 36d ago |
| CVE-2026-84752 | 8.8 | — | — | — | — | Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. | 36d ago |
| CVE-2026-71963 | 8.8 | — | — | — | — | Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that a | 36d ago |
| CVE-2026-85176 | 8.8 | — | — | — | — | DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and writ | 36d ago |
| CVE-2026-85110 | 8.8 | — | — | — | — | A vulnerability was identified in Tenda HG10 300001138. | 36d ago |
| CVE-2026-85175 | 8.8 | — | — | — | — | SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (k | 36d ago |
| CVE-2026-85174 | 8.8 | — | — | — | — | SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text s | 36d ago |
| CVE-2026-80734 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: initialize inode mapping flags for cach | 36d ago |
| CVE-2026-20280 | 8.8 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software en | 37d ago |
| CVE-2026-20278 | 8.8 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software enginee | 37d ago |
| CVE-2026-20275 | 8.8 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software enginee | 37d ago |
| CVE-2026-84673 | 8.8 | — | — | — | — | Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance con | 37d ago |
| CVE-2026-84672 | 8.8 | — | — | — | — | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissi | 37d ago |
| CVE-2026-84671 | 8.8 | — | — | — | — | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the J | 37d ago |
| CVE-2026-84670 | 8.8 | — | — | — | — | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated | 37d ago |
| CVE-2026-84669 | 8.8 | — | — | — | — | A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permiss | 37d ago |
| CVE-2026-84668 | 8.8 | — | — | — | — | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file | 37d ago |
| CVE-2026-84650 | 8.8 | — | — | — | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, a | 37d ago |
| CVE-2026-84649 | 8.8 | — | — | — | — | In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, in | 37d ago |
| CVE-2026-84648 | 8.8 | — | — | — | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata ( | 37d ago |
| CVE-2026-84647 | 8.8 | — | — | — | — | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier | 37d ago |
| CVE-2026-84645 | 8.8 | — | — | — | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in i | 37d ago |
| CVE-2026-66842 | 8.8 | — | — | — | — | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accou | 37d ago |
| CVE-2026-84801 | 8.8 | — | — | — | — | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowin | 37d ago |
| CVE-2026-84796 | 8.8 | — | — | — | — | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers th | 37d ago |
| CVE-2026-84770 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | 37d ago |
| CVE-2026-84764 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | 37d ago |
| CVE-2026-81772 | 8.8 | — | — | — | — | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | 37d ago |
| CVE-2026-81769 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. | 37d ago |
| CVE-2026-81283 | 8.8 | — | — | — | — | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | 37d ago |
| CVE-2026-14828 | 8.8 | — | — | — | — | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager | 38d ago |
| CVE-2026-81807 | 8.8 | — | — | — | — | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, al | 38d ago |
| CVE-2026-81737 | 8.8 | — | — | — | — | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated | 38d ago |
| CVE-2026-19116 | 8.8 | — | — | — | — | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserializ | 38d ago |
| CVE-2026-14357 | 8.8 | — | — | — | — | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0 | 38d ago |
| CVE-2026-84715 | 8.8 | — | — | — | — | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, | 38d ago |
| CVE-2026-84694 | 8.8 | — | — | — | — | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH | 38d ago |
| CVE-2026-84350 | 8.8 | — | — | — | google / chrome | Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social eng | 38d ago |
| CVE-2026-84347 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary co | 38d ago |
| CVE-2026-84326 | 8.8 | — | — | — | google / chrome | Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrar | 38d ago |
| CVE-2026-84482 | 8.8 | — | — | — | — | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and is | 38d ago |
| CVE-2026-73782 | 8.8 | — | — | — | hpe / arubaos-cx | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated re | 38d ago |
| CVE-2026-73753 | 8.8 | — | — | — | — | Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute | 38d ago |
| CVE-2026-73752 | 8.8 | — | — | — | hpe / arubaos-cx | An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. | 38d ago |
| CVE-2026-73751 | 8.8 | — | — | — | — | An authenticated user with low-privileged access could submit crafted input through the web-based management inter | 38d ago |
| CVE-2026-73750 | 8.8 | — | — | — | — | Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. | 38d ago |
| CVE-2026-71981 | 8.8 | — | — | — | — | Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute a | 38d ago |
| CVE-2026-73705 | 8.8 | — | — | — | arubanetworks / fabric composer | An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated lo | 38d ago |
| CVE-2026-73704 | 8.8 | — | — | — | arubanetworks / fabric composer | A command sanitization bypass exists in the API of HPE Networking Fabric Composer. | 38d ago |
| CVE-2026-73703 | 8.8 | — | — | — | arubanetworks / fabric composer | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthentic | 38d ago |
| CVE-2026-73702 | 8.8 | — | — | — | arubanetworks / fabric composer | A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. | 38d ago |
| CVE-2026-72649 | 8.8 | — | — | — | elastic / elasticsearch | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote cod | 38d ago |