| CVE-2026-51974 | 8.8 | — | — | — | — | An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 | 38d ago |
| CVE-2026-19591 | 8.8 | — | — | — | — | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain Power | 38d ago |
| CVE-2026-58566 | 8.8 | — | — | — | — | Dell PowerStore, an Incorrect Authorization vulnerability. | 38d ago |
| CVE-2026-84268 | 8.8 | — | — | — | — | A flaw was found in the SFTP backend in gvfs. | 38d ago |
| CVE-2026-84202 | 8.8 | — | — | — | — | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution | 38d ago |
| CVE-2026-79682 | 8.8 | — | — | — | — | Dell PowerStore contains a Command Injection vulnerability. | 38d ago |
| CVE-2026-58567 | 8.8 | — | — | — | — | Dell PowerStore contains an OS Command Injection vulnerability. | 38d ago |
| CVE-2026-10195 | 8.8 | — | — | — | — | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. | 38d ago |
| CVE-2026-79686 | 8.8 | — | — | — | — | Dell PowerStore contains a Protection Mechanism Failure vulnerability. | 38d ago |
| CVE-2026-58569 | 8.8 | — | — | — | — | Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. | 38d ago |
| CVE-2026-18630 | 8.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine | 38d ago |
| CVE-2026-79684 | 8.8 | — | — | — | — | Dell PowerStore contains a Protection Mechanism Failure vulnerability. | 38d ago |
| CVE-2026-58572 | 8.8 | — | — | — | — | Dell PowerStore contains a Code Injection vulnerability. | 38d ago |
| CVE-2026-58571 | 8.8 | — | — | — | — | Dell PowerStore contains an OS Command Injection vulnerability. | 38d ago |
| CVE-2026-84131 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation due to invalid pointer in the Graphics component. | 38d ago |
| CVE-2026-84128 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the WebDriver BiDi component. | 38d ago |
| CVE-2026-84123 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation due to use-after-free in the Graphics: WebGPU component. | 38d ago |
| CVE-2026-84117 | 8.8 | — | — | — | mozilla / firefox mobile | Privilege escalation in Firefox for Android. | 38d ago |
| CVE-2026-79683 | 8.8 | — | — | — | — | Dell PowerStore contains a Protection Mechanism Failure vulnerability. | 38d ago |
| CVE-2026-58575 | 8.8 | — | — | — | — | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. | 38d ago |
| CVE-2026-76111 | 8.8 | — | — | — | — | Dell PowerStore contains an Incorrect Authorization vulnerability. | 38d ago |
| CVE-2026-59681 | 8.8 | — | — | — | — | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configu | 39d ago |
| CVE-2026-19806 | 8.8 | — | — | — | — | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress | 39d ago |
| CVE-2026-65643 | 8.8 | — | — | — | cpanel / cpanel | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as roo | 39d ago |
| CVE-2026-82882 | 8.8 | — | — | — | — | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, a | 39d ago |
| CVE-2026-83596 | 8.8 | — | — | — | — | A flaw was found in WebKitGTK. | 39d ago |
| CVE-2026-82908 | 8.8 | — | — | — | — | A vulnerability was found in MSI Dragon Center up to 2.0.155.0. | 39d ago |
| CVE-2026-83497 | 8.8 | — | — | — | — | Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin all | 39d ago |
| CVE-2026-79744 | 8.8 | — | — | — | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 39d ago |
| CVE-2026-82807 | 8.8 | — | — | — | — | A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. | 39d ago |
| CVE-2026-77966 | 8.8 | — | — | — | — | The affected Ebyte product does not provide separation between limited and administrative management functions. | 39d ago |
| CVE-2026-82217 | 8.8 | — | — | — | — | In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileC | 39d ago |
| CVE-2026-5956 | 8.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hostin | 39d ago |
| CVE-2026-12894 | 8.8 | — | — | — | — | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages | 39d ago |
| CVE-2026-82680 | 8.8 | — | — | — | — | A weakness has been identified in D-Link DSM-G600 1.01. | 40d ago |
| CVE-2026-82628 | 8.8 | — | — | — | — | A vulnerability was found in Colorful iGameCenter 2.0.0.81. | 40d ago |
| CVE-2026-82642 | 8.8 | — | — | — | — | Readest is an open-source e-book reader built on Tauri. | 40d ago |
| CVE-2026-82635 | 8.8 | — | — | — | faberon / pake | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Down | 40d ago |
| CVE-2026-81660 | 8.8 | — | — | — | — | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or es | 41d ago |
| CVE-2026-76585 | 8.8 | — | — | — | — | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of c | 41d ago |
| CVE-2026-82450 | 8.8 | — | — | — | — | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality t | 41d ago |
| CVE-2026-82447 | 8.8 | — | — | — | — | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first | 41d ago |
| CVE-2026-81532 | 8.8 | — | — | — | — | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a posit | 42d ago |
| CVE-2026-18729 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to | 42d ago |
| CVE-2026-82278 | 8.8 | — | — | — | — | BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows | 42d ago |
| CVE-2026-81849 | 8.8 | — | — | — | — | Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent | 42d ago |
| CVE-2026-72984 | 8.8 | — | — | — | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 42d ago |
| CVE-2026-55521 | 8.8 | — | — | — | — | Yamcs is a mission control framework. | 42d ago |
| CVE-2026-55485 | 8.8 | — | — | — | — | Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. | 42d ago |
| CVE-2026-80724 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from | 43d ago |
| CVE-2026-80722 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params | 43d ago |
| CVE-2026-80721 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon refere | 43d ago |
| CVE-2026-80692 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_ | 43d ago |
| CVE-2026-80683 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: give the socket its own sco_co | 43d ago |
| CVE-2026-80672 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix u16 truncation of restart-area lengt | 43d ago |
| CVE-2026-80638 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_remove | 43d ago |
| CVE-2026-80635 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from short trigger | 43d ago |
| CVE-2026-80633 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iommufd: Take dma_resv lock before dma_buf_unp | 43d ago |
| CVE-2026-80608 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix iommu domain lifetime race | 43d ago |
| CVE-2026-80604 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix OOB read in hid_get_report for | 43d ago |