| CVE-2026-74629 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr | 48d ago |
| CVE-2026-74615 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: do not arm the ageing timer on a device | 48d ago |
| CVE-2026-74607 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Serialize accesses to the owner and | 48d ago |
| CVE-2026-71513 | 8.8 | — | — | — | — | NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pi | 48d ago |
| CVE-2026-59808 | 8.8 | — | — | — | — | AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() | 48d ago |
| CVE-2026-76789 | 8.8 | — | — | — | — | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and non | 49d ago |
| CVE-2026-19883 | 8.8 | — | — | — | — | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can le | 49d ago |
| CVE-2026-53528 | 8.8 | — | — | — | — | LeafWiki is a self-hosted wiki. | 49d ago |
| CVE-2026-53527 | 8.8 | — | — | — | — | LeafWiki is a self-hosted wiki. | 49d ago |
| CVE-2026-33240 | 8.8 | — | — | — | — | Combodo iTop is a web based IT service management tool. | 49d ago |
| CVE-2026-31936 | 8.8 | — | — | — | — | Combodo iTop is a web based IT service management tool. | 49d ago |
| CVE-2026-62316 | 8.8 | — | — | — | — | Microsoft UFO open-source framework for intelligent automation across devices and platforms. | 49d ago |
| CVE-2026-50538 | 8.8 | — | — | — | — | LibVNCClient is a library for easy implementation of a VNC client. | 49d ago |
| CVE-2026-77234 | 8.8 | — | — | — | amazon / freertos | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports t | 49d ago |
| CVE-2026-62677 | 8.8 | — | — | — | — | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. | 49d ago |
| CVE-2026-62675 | 8.8 | — | — | — | — | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. | 49d ago |
| CVE-2026-74580 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring | 49d ago |
| CVE-2026-63046 | 8.8 | — | — | — | apache / inlong | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. | 50d ago |
| CVE-2026-61400 | 8.8 | — | — | — | apache / cloudstack | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudS | 50d ago |
| CVE-2026-59799 | 8.8 | — | — | — | apache / cloudstack | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypas | 50d ago |
| CVE-2026-50112 | 8.8 | — | — | — | apache / cloudstack | SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-c | 50d ago |
| CVE-2026-47359 | 8.8 | — | — | — | apache / cloudstack | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache | 50d ago |
| CVE-2026-19449 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local u | 50d ago |
| CVE-2026-18832 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea | 50d ago |
| CVE-2026-17436 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea | 50d ago |
| CVE-2026-16996 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an int | 50d ago |
| CVE-2026-16936 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buff | 50d ago |
| CVE-2026-16934 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a he | 50d ago |
| CVE-2026-76023 | 8.8 | — | — | — | google / chrome | Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attac | 50d ago |
| CVE-2026-76022 | 8.8 | — | — | — | google / chrome | Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary | 50d ago |
| CVE-2026-76021 | 8.8 | — | — | — | google / chrome | Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code | 50d ago |
| CVE-2026-76018 | 8.8 | — | — | — | google / chrome | Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social | 50d ago |
| CVE-2026-76017 | 8.8 | — | — | — | google / chrome | Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitra | 50d ago |
| CVE-2026-73040 | 8.8 | — | — | — | — | Dockge validates a stack name only on the write path. | 50d ago |
| CVE-2026-18420 | 8.8 | — | — | — | — | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authe | 50d ago |
| CVE-2026-54449 | 8.8 | — | — | — | — | LangBot is a global IM bot platform designed for LLMs. | 50d ago |
| CVE-2026-18279 | 8.8 | — | — | — | — | Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. | 50d ago |
| CVE-2026-18264 | 8.8 | — | — | — | — | NoMachine getstat Command Injection Remote Code Execution Vulnerability. | 50d ago |
| CVE-2026-16932 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to im | 50d ago |
| CVE-2026-77084 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. | 51d ago |
| CVE-2026-77080 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerab | 51d ago |
| CVE-2026-77079 | 8.8 | — | — | — | n8n / n8n | n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) p | 51d ago |
| CVE-2026-77068 | 8.8 | — | — | — | n8n / n8n | n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk | 51d ago |
| CVE-2026-14948 | 8.8 | — | — | — | — | A low privileged remote attacker can hijack an active administrative session without needing to know the administr | 51d ago |
| CVE-2026-76832 | 8.8 | — | — | — | — | Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers | 51d ago |
| CVE-2026-76395 | 8.8 | — | — | — | splunk / ai toolkit | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code o | 51d ago |
| CVE-2026-76389 | 8.8 | — | — | — | cisco / talos intelligence for enterprise security cloud | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the | 51d ago |
| CVE-2026-76352 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 51d ago |
| CVE-2026-76351 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3 | 51d ago |
| CVE-2026-76350 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule | 51d ago |
| CVE-2026-76335 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a | 51d ago |
| CVE-2026-76319 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold t | 51d ago |
| CVE-2026-76317 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 51d ago |
| CVE-2026-76316 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the | 51d ago |
| CVE-2026-76315 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 51d ago |
| CVE-2026-76314 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 51d ago |
| CVE-2026-76313 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 51d ago |
| CVE-2026-76259 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with acce | 51d ago |
| CVE-2026-76253 | 8.8 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule | 51d ago |
| CVE-2026-53547 | 8.8 | — | — | — | — | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 51d ago |