| CVE-2026-79182 | 8.8 | — | — | — | google / chrome | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall | 45d ago |
| CVE-2026-79142 | 8.8 | — | — | — | google / chrome | Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execut | 45d ago |
| CVE-2026-79127 | 8.8 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrar | 45d ago |
| CVE-2026-79119 | 8.8 | — | — | — | google / chrome | Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code | 45d ago |
| CVE-2026-79097 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code i | 45d ago |
| CVE-2026-79073 | 8.8 | — | — | — | google / chrome | Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potential | 45d ago |
| CVE-2026-79069 | 8.8 | — | — | — | google / chrome | Memory corruption in Tint in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potential | 45d ago |
| CVE-2026-79048 | 8.8 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to po | 45d ago |
| CVE-2026-79045 | 8.8 | — | — | — | google / chrome | Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri | 45d ago |
| CVE-2026-79033 | 8.8 | — | — | — | google / chrome | Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker | 45d ago |
| CVE-2026-78990 | 8.8 | — | — | — | google / chrome | Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitra | 45d ago |
| CVE-2026-78978 | 8.8 | — | — | — | google / chrome | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to pot | 45d ago |
| CVE-2026-78963 | 8.8 | — | — | — | google / chrome | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall | 45d ago |
| CVE-2026-78956 | 8.8 | — | — | — | google / chrome | Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri | 45d ago |
| CVE-2026-78950 | 8.8 | — | — | — | google / chrome | Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execut | 45d ago |
| CVE-2026-78944 | 8.8 | — | — | — | google / chrome | Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social eng | 45d ago |
| CVE-2026-78938 | 8.8 | — | — | — | google / chrome | Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code i | 45d ago |
| CVE-2026-78910 | 8.8 | — | — | — | google / chrome | Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code | 45d ago |
| CVE-2026-78905 | 8.8 | — | — | — | google / chrome | Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute a | 45d ago |
| CVE-2026-78899 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code i | 45d ago |
| CVE-2026-78891 | 8.8 | — | — | — | google / chrome | Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary c | 45d ago |
| CVE-2026-65091 | 8.8 | — | — | — | nvidia / openshell | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injec | 45d ago |
| CVE-2026-66152 | 8.8 | — | — | — | — | A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attack | 45d ago |
| CVE-2026-43670 | 8.8 | — | — | — | apple / safari | A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. | 45d ago |
| CVE-2026-80049 | 8.8 | — | — | — | — | Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. | 45d ago |
| CVE-2026-55585 | 8.8 | — | — | — | — | QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code | 45d ago |
| CVE-2026-24170 | 8.8 | — | — | — | — | NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticate | 45d ago |
| CVE-2026-79784 | 8.8 | — | — | — | — | Vocos instantiates a class named by a configuration file without restricting which class may be named. | 45d ago |
| CVE-2026-57863 | 8.8 | — | — | — | — | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authentica | 45d ago |
| CVE-2026-79665 | 8.8 | — | — | — | — | Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in Req | 46d ago |
| CVE-2026-19949 | 8.8 | — | — | — | — | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore fun | 46d ago |
| CVE-2026-49050 | 8.8 | — | — | — | — | General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3. | 46d ago |
| CVE-2026-12878 | 8.8 | — | — | — | octopus / codefresh | In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Adm | 46d ago |
| CVE-2026-16601 | 8.8 | — | — | — | — | The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Li | 46d ago |
| CVE-2026-19892 | 8.8 | — | — | — | — | The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions | 46d ago |
| CVE-2026-78685 | 8.8 | — | — | — | — | Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. | 46d ago |
| CVE-2026-75574 | 8.8 | — | — | — | — | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action paramet | 46d ago |
| CVE-2026-56702 | 8.8 | — | — | — | — | Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin th | 46d ago |
| CVE-2026-32561 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | 46d ago |
| CVE-2026-32560 | 8.8 | — | — | — | — | Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 | 46d ago |
| CVE-2026-76836 | 8.8 | — | — | — | — | AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permiss | 46d ago |
| CVE-2026-76073 | 8.8 | — | — | — | — | Label Studio does not scope the annotation detail endpoint to the requesting user's organization. | 46d ago |
| CVE-2025-36940 | 8.8 | — | — | — | — | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation | 46d ago |
| CVE-2026-13212 | 8.8 | — | — | — | — | The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the use | 46d ago |
| CVE-2026-78376 | 8.8 | — | — | — | — | A flaw was found in WebKitGTK. | 46d ago |
| CVE-2026-76847 | 8.8 | — | — | — | — | act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-ar | 46d ago |
| CVE-2026-76841 | 8.8 | — | — | — | — | Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 | 46d ago |
| CVE-2026-59567 | 8.8 | — | — | — | — | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving | 46d ago |
| CVE-2026-59565 | 8.8 | — | — | — | — | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versi | 46d ago |
| CVE-2026-78317 | 8.8 | — | — | — | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 47d ago |
| CVE-2026-78316 | 8.8 | — | — | — | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 47d ago |
| CVE-2026-78315 | 8.8 | — | — | — | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 47d ago |
| CVE-2026-78314 | 8.8 | — | — | — | — | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | 47d ago |
| CVE-2026-78170 | 8.8 | — | — | — | — | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. | 47d ago |
| CVE-2026-16149 | 8.8 | — | — | — | — | The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu | 48d ago |
| CVE-2026-0551 | 8.8 | — | — | — | — | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, | 48d ago |
| CVE-2026-74702 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpo | 48d ago |
| CVE-2026-74691 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before s | 48d ago |
| CVE-2026-74655 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: fix TX DMA buffer flush Whe | 48d ago |
| CVE-2026-74649 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix missing shared-key aut | 48d ago |