| CVE-2026-61002 | 8.8 | — | — | — | oracle / soa suite | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). | 52d ago |
| CVE-2026-60976 | 8.8 | — | — | — | oracle / scripting | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). | 52d ago |
| CVE-2026-60967 | 8.8 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). | 52d ago |
| CVE-2026-60879 | 8.8 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Mana | 52d ago |
| CVE-2026-60767 | 8.8 | — | — | — | oracle / siebel apps - marketing | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). | 52d ago |
| CVE-2026-60751 | 8.8 | — | — | — | oracle / siebel apps - marketing | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). | 52d ago |
| CVE-2026-60731 | 8.8 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). | 52d ago |
| CVE-2026-60729 | 8.8 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). | 52d ago |
| CVE-2026-60726 | 8.8 | — | — | — | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 52d ago |
| CVE-2026-60722 | 8.8 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 52d ago |
| CVE-2026-60716 | 8.8 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 52d ago |
| CVE-2026-60715 | 8.8 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 52d ago |
| CVE-2026-67920 | 8.8 | — | — | — | — | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.Mig | 52d ago |
| CVE-2026-48508 | 8.8 | — | — | — | — | Lemur manages TLS certificate creation. | 52d ago |
| CVE-2026-61574 | 8.8 | — | — | — | — | authentik is an open-source identity provider. | 52d ago |
| CVE-2026-49228 | 8.8 | — | — | — | — | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. | 52d ago |
| CVE-2026-49221 | 8.8 | — | — | — | — | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. | 52d ago |
| CVE-2026-19501 | 8.8 | — | — | — | — | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula | 52d ago |
| CVE-2026-74012 | 8.8 | — | — | — | — | Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. | 52d ago |
| CVE-2026-66793 | 8.8 | — | — | — | — | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Ku | 52d ago |
| CVE-2026-63639 | 8.8 | — | — | — | — | Valkey is a distributed key-value database. | 52d ago |
| CVE-2026-61407 | 8.8 | — | — | — | — | Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vul | 52d ago |
| CVE-2026-50187 | 8.8 | — | — | — | — | Oh My Zsh is a community-driven framework for managing Zsh configuration. | 52d ago |
| CVE-2026-32465 | 8.8 | — | — | — | — | Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. | 53d ago |
| CVE-2026-28191 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. | 53d ago |
| CVE-2026-24301 | 8.8 | — | — | — | — | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an | 53d ago |
| CVE-2026-74969 | 8.8 | — | — | — | mozilla / firefox | Use-after-free in the Layout: Text and Fonts component. | 53d ago |
| CVE-2026-74965 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Shell Integration component. | 53d ago |
| CVE-2026-74955 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Request Handling component. | 53d ago |
| CVE-2026-74953 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Networking: Cookies component. | 53d ago |
| CVE-2026-74952 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Application Update component. | 53d ago |
| CVE-2026-74950 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Downloads API component. | 53d ago |
| CVE-2026-74949 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation due to use-after-free in the Graphics: Canvas2D component. | 53d ago |
| CVE-2026-74947 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation due to invalid pointer in the Graphics component. | 53d ago |
| CVE-2026-74946 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. | 53d ago |
| CVE-2026-74942 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Remote Settings Client component. | 53d ago |
| CVE-2026-74941 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Graphics: CanvasWebGL component. | 53d ago |
| CVE-2026-74939 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the DOM: Navigation component. | 53d ago |
| CVE-2026-74937 | 8.8 | — | — | — | mozilla / firefox | Use-after-free in the JavaScript: GC component. | 53d ago |
| CVE-2026-74935 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the DOM: Networking component. | 53d ago |
| CVE-2026-75853 | 8.8 | — | — | — | — | ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authenticat | 53d ago |
| CVE-2026-75836 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enf | 53d ago |
| CVE-2026-75827 | 8.8 | — | — | — | — | Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function vali | 53d ago |
| CVE-2026-65346 | 8.8 | — | — | — | apple / ipados | An integer overflow was addressed with improved input validation. | 53d ago |
| CVE-2026-43794 | 8.8 | — | — | — | apple / safari | A memory corruption issue was addressed with improved memory handling. | 53d ago |
| CVE-2026-75481 | 8.8 | — | — | — | — | SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating servic | 53d ago |
| CVE-2026-75103 | 8.8 | — | — | — | — | Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authen | 53d ago |
| CVE-2026-65640 | 8.8 | — | — | — | — | WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author | 53d ago |
| CVE-2026-70495 | 8.8 | — | — | — | — | A flaw was found in search-v2-operator. | 53d ago |
| CVE-2026-62982 | 8.8 | — | — | — | — | Glances is an open-source system cross-platform monitoring tool. | 53d ago |
| CVE-2026-50768 | 8.8 | — | — | — | — | File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker | 53d ago |
| CVE-2026-9771 | 8.8 | — | — | — | — | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. | 53d ago |
| CVE-2026-74997 | 8.8 | — | — | — | — | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subjec | 54d ago |
| CVE-2026-74893 | 8.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validat | 54d ago |
| CVE-2026-74883 | 8.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to res | 54d ago |
| CVE-2026-74877 | 8.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key met | 54d ago |
| CVE-2026-74845 | 8.8 | — | — | — | — | Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allow | 54d ago |
| CVE-2026-17123 | 8.8 | — | — | — | — | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, an | 55d ago |
| CVE-2026-16099 | 8.8 | — | — | — | — | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi | 55d ago |
| CVE-2026-14498 | 8.8 | — | — | — | — | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin | 55d ago |