| CVE-2026-53542 | 8.8 | — | — | — | — | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 51d ago |
| CVE-2026-12522 | 8.8 | — | — | — | — | The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_ | 51d ago |
| CVE-2026-76647 | 8.8 | — | — | — | — | Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatc | 51d ago |
| CVE-2026-68561 | 8.8 | — | — | — | — | Wekan is open source kanban built with Meteor. | 51d ago |
| CVE-2026-16911 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary cod | 51d ago |
| CVE-2026-16909 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an of | 51d ago |
| CVE-2026-16901 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an ou | 51d ago |
| CVE-2026-16877 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary cod | 51d ago |
| CVE-2026-16865 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to comma | 51d ago |
| CVE-2026-16850 | 8.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to comma | 51d ago |
| CVE-2026-16848 | 8.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 51d ago |
| CVE-2026-16847 | 8.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea | 51d ago |
| CVE-2026-16844 | 8.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 51d ago |
| CVE-2026-16842 | 8.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 51d ago |
| CVE-2026-16841 | 8.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 51d ago |
| CVE-2026-75149 | 8.8 | — | — | — | — | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows at | 51d ago |
| CVE-2026-61518 | 8.8 | — | — | — | — | ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. | 51d ago |
| CVE-2026-62666 | 8.8 | — | — | — | — | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. | 51d ago |
| CVE-2026-71961 | 8.8 | — | — | — | — | Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenti | 51d ago |
| CVE-2026-71176 | 8.8 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used | 51d ago |
| CVE-2026-58565 | 8.8 | — | — | — | dell / command update | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. | 51d ago |
| CVE-2026-49255 | 8.8 | — | — | — | — | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. | 51d ago |
| CVE-2026-44829 | 8.8 | — | — | — | — | Gotenberg is a Docker-powered stateless API for PDF files. | 51d ago |
| CVE-2026-16814 | 8.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea | 51d ago |
| CVE-2026-76224 | 8.8 | — | — | — | — | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in it | 51d ago |
| CVE-2026-76221 | 8.8 | — | — | — | gitpython project / gitpython | GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows at | 51d ago |
| CVE-2026-76220 | 8.8 | — | — | — | gitpython project / gitpython | GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be b | 51d ago |
| CVE-2026-75918 | 8.8 | — | — | — | phpmyfaq / phpmyfaq | phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is en | 51d ago |
| CVE-2026-71694 | 8.8 | — | — | — | — | An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68 | 51d ago |
| CVE-2026-54795 | 8.8 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used | 51d ago |
| CVE-2024-58376 | 8.8 | — | — | — | — | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's regis | 51d ago |
| CVE-2026-49427 | 8.8 | — | — | — | freebsd / freebsd | Pages belonging to largepage shared memory objects were not explicitly wired. | 52d ago |
| CVE-2026-49420 | 8.8 | — | — | — | freebsd / freebsd | The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether th | 52d ago |
| CVE-2026-19842 | 8.8 | — | — | — | — | The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before stor | 52d ago |
| CVE-2026-16617 | 8.8 | — | — | — | — | The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description be | 52d ago |
| CVE-2026-14334 | 8.8 | — | — | — | — | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize upload | 52d ago |
| CVE-2026-70408 | 8.8 | — | — | — | — | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that h | 52d ago |
| CVE-2026-49419 | 8.8 | — | — | — | freebsd / freebsd | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller' | 52d ago |
| CVE-2026-49418 | 8.8 | — | — | — | freebsd / freebsd | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping | 52d ago |
| CVE-2026-49415 | 8.8 | — | — | — | freebsd / freebsd | During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are u | 52d ago |
| CVE-2026-66602 | 8.8 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site | 52d ago |
| CVE-2026-52876 | 8.8 | — | — | — | — | Streambert is a cross-platform Electron Desktop App to stream and download video content. | 52d ago |
| CVE-2026-52872 | 8.8 | — | — | — | — | Streambert is a cross-platform Electron Desktop App to stream and download video content. | 52d ago |
| CVE-2026-50191 | 8.8 | — | — | — | — | 4gaBoards is a boards system for realtime project management. | 52d ago |
| CVE-2026-50186 | 8.8 | — | — | — | — | 4gaBoards is a boards system for realtime project management. | 52d ago |
| CVE-2026-15315 | 8.8 | — | — | — | tp-link / tapo c120 firmware | Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verifica | 52d ago |
| CVE-2026-76047 | 8.8 | — | — | — | google / chrome | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code | 52d ago |
| CVE-2026-76045 | 8.8 | — | — | — | google / chrome | Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary co | 52d ago |
| CVE-2026-76043 | 8.8 | — | — | — | google / chrome | Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrar | 52d ago |
| CVE-2026-76040 | 8.8 | — | — | — | google / chrome | Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging | 52d ago |
| CVE-2026-76038 | 8.8 | — | — | — | google / chrome | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code | 52d ago |
| CVE-2026-76034 | 8.8 | — | — | — | google / chrome | Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary c | 52d ago |
| CVE-2026-71150 | 8.8 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 52d ago |
| CVE-2026-71106 | 8.8 | — | — | — | oracle / hospitality opera 5 property services | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (comp | 52d ago |
| CVE-2026-71067 | 8.8 | — | — | — | oracle / agile plm mcad connector | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). | 52d ago |
| CVE-2026-71058 | 8.8 | — | — | — | oracle / bi publisher | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). | 52d ago |
| CVE-2026-71055 | 8.8 | — | — | — | oracle / business intelligence | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platf | 52d ago |
| CVE-2026-71052 | 8.8 | — | — | — | oracle / agile engineering data management | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Servi | 52d ago |
| CVE-2026-71051 | 8.8 | — | — | — | oracle / product lifecycle analytics | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Is | 52d ago |
| CVE-2026-71046 | 8.8 | — | — | — | oracle / agile product lifecycle management | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). | 52d ago |