| CVE-2026-80601 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: gw: acquire ethernet header only a | 43d ago |
| CVE-2026-82072 | 8.8 | — | — | — | google / chrome | Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 43d ago |
| CVE-2026-78037 | 8.8 | — | — | — | — | Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. | 43d ago |
| CVE-2026-76060 | 8.8 | — | — | — | — | An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. | 43d ago |
| CVE-2026-75814 | 8.8 | — | — | — | — | The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management | 43d ago |
| CVE-2026-75419 | 8.8 | — | — | — | — | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. | 43d ago |
| CVE-2026-75339 | 8.8 | — | — | — | — | The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. | 43d ago |
| CVE-2026-39944 | 8.8 | — | — | — | — | Ceph is an open-source distributed storage platform providing object, block, and file storage. | 43d ago |
| CVE-2026-18965 | 8.8 | — | — | — | — | PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device | 43d ago |
| CVE-2026-76639 | 8.8 | — | — | — | — | Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows | 43d ago |
| CVE-2026-54721 | 8.8 | — | — | — | — | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. | 43d ago |
| CVE-2026-10036 | 8.8 | — | — | — | — | SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbit | 43d ago |
| CVE-2026-26899 | 8.8 | — | — | — | — | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). | 43d ago |
| CVE-2026-81625 | 8.8 | — | — | — | — | A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affe | 44d ago |
| CVE-2026-81581 | 8.8 | — | — | — | — | Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an | 44d ago |
| CVE-2026-81579 | 8.8 | — | — | — | — | In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver | 44d ago |
| CVE-2026-81271 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | 44d ago |
| CVE-2026-78257 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | 44d ago |
| CVE-2026-78333 | 8.8 | — | — | — | — | The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthe | 44d ago |
| CVE-2026-77018 | 8.8 | — | — | — | — | The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor vali | 44d ago |
| CVE-2026-74770 | 8.8 | — | — | — | dell / powerprotect one | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in | 44d ago |
| CVE-2026-68861 | 8.8 | — | — | — | dell / powerprotect one | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in | 44d ago |
| CVE-2026-58474 | 8.8 | — | — | — | — | whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remot | 44d ago |
| CVE-2025-56798 | 8.8 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier a | 44d ago |
| CVE-2020-15878 | 8.8 | — | — | — | — | An issue was discovered in LibreNMS 1.65. | 44d ago |
| CVE-2020-15876 | 8.8 | — | — | — | — | An issue was discovered in LibreNMS 1.65. | 44d ago |
| CVE-2020-15874 | 8.8 | — | — | — | — | An issue was discovered in LibreNMS 1.65. | 44d ago |
| CVE-2026-80576 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring | 44d ago |
| CVE-2026-80553 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing workqueues The | 44d ago |
| CVE-2026-80552 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write reg | 44d ago |
| CVE-2026-80548 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Selectively expand io_mutex The | 44d ago |
| CVE-2026-80547 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Implement a crw lock Unlike the | 44d ago |
| CVE-2026-63041 | 8.8 | — | — | — | apache / apisix | Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. | 44d ago |
| CVE-2026-80348 | 8.8 | — | — | — | — | TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four met | 45d ago |
| CVE-2026-19042 | 8.8 | — | — | — | — | A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a r | 45d ago |
| CVE-2026-80237 | 8.8 | — | — | — | — | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. | 45d ago |
| CVE-2026-78236 | 8.8 | — | — | — | — | An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator b | 45d ago |
| CVE-2026-75977 | 8.8 | — | — | — | — | The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in | 45d ago |
| CVE-2026-58096 | 8.8 | — | — | — | — | LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum requi | 45d ago |
| CVE-2026-58095 | 8.8 | — | — | — | — | mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allo | 45d ago |
| CVE-2026-80202 | 8.8 | — | — | — | — | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permi | 45d ago |
| CVE-2026-80193 | 8.8 | — | — | — | — | Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating | 45d ago |
| CVE-2026-79266 | 8.8 | — | — | — | google / chrome | Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social eng | 45d ago |
| CVE-2026-79244 | 8.8 | — | — | — | google / chrome | Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary | 45d ago |
| CVE-2026-79240 | 8.8 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to po | 45d ago |
| CVE-2026-79236 | 8.8 | — | — | — | google / chrome | Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code i | 45d ago |
| CVE-2026-79231 | 8.8 | — | — | — | google / chrome | Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary co | 45d ago |
| CVE-2026-79230 | 8.8 | — | — | — | google / chrome | Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to | 45d ago |
| CVE-2026-79227 | 8.8 | — | — | — | google / chrome | Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social eng | 45d ago |
| CVE-2026-79226 | 8.8 | — | — | — | google / chrome | Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote at | 45d ago |
| CVE-2026-79223 | 8.8 | — | — | — | google / chrome | Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory insi | 45d ago |
| CVE-2026-79219 | 8.8 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social en | 45d ago |
| CVE-2026-79215 | 8.8 | — | — | — | google / chrome | Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute | 45d ago |
| CVE-2026-79209 | 8.8 | — | — | — | google / chrome | Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execu | 45d ago |
| CVE-2026-79202 | 8.8 | — | — | — | google / chrome | Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrar | 45d ago |
| CVE-2026-79198 | 8.8 | — | — | — | google / chrome | Use after free in Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary | 45d ago |
| CVE-2026-79197 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code i | 45d ago |
| CVE-2026-79195 | 8.8 | — | — | — | google / chrome | Use after free in Script in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary co | 45d ago |
| CVE-2026-79187 | 8.8 | — | — | — | google / chrome | Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary co | 45d ago |
| CVE-2026-79183 | 8.8 | — | — | — | google / chrome | Use after free in Accessibility in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging socia | 45d ago |