| CVE-2026-72160 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject dinodes with non-canonical i_mod | 56d ago |
| CVE-2026-72157 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Fix frags[] overflow by boun | 56d ago |
| CVE-2026-72148 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Add spinlock to protect DO | 56d ago |
| CVE-2026-72136 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_interface: require CAP_NET_ADMIN in | 56d ago |
| CVE-2026-72124 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: can: isotp: serialize TX state transitions und | 56d ago |
| CVE-2026-72121 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking when updating filter and | 56d ago |
| CVE-2026-72111 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register bounds before narrowing re | 56d ago |
| CVE-2026-72107 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bounds memory access for no | 56d ago |
| CVE-2026-72100 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix a bug if the bio is out of l | 56d ago |
| CVE-2026-72061 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: sit: require CAP_NET_ADMIN in the device | 56d ago |
| CVE-2026-72055 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_ADMIN in the dev | 56d ago |
| CVE-2026-72054 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ip_vti: require CAP_NET_ADMIN in the devi | 56d ago |
| CVE-2026-72053 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ipip: require CAP_NET_ADMIN in the device | 56d ago |
| CVE-2026-72052 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the dev | 56d ago |
| CVE-2026-72051 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET_ADMIN in the | 56d ago |
| CVE-2026-72045 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE shari | 56d ago |
| CVE-2026-72029 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: bound device offsets in the M | 56d ago |
| CVE-2026-72003 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a sh | 56d ago |
| CVE-2026-68471 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE common info leng | 56d ago |
| CVE-2026-68470 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extension-frame layou | 56d ago |
| CVE-2026-68466 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: lpc32xx_slc: fail DMA transfer o | 56d ago |
| CVE-2026-15965 | 8.8 | — | — | — | — | The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitra | 56d ago |
| CVE-2026-15312 | 8.8 | — | — | — | — | The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in | 56d ago |
| CVE-2026-15001 | 8.8 | — | — | — | — | The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versi | 56d ago |
| CVE-2026-73680 | 8.8 | — | — | — | — | Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows auth | 56d ago |
| CVE-2026-16879 | 8.8 | — | — | — | ibm / db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions | 56d ago |
| CVE-2026-19847 | 8.8 | — | — | — | — | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 56d ago |
| CVE-2026-19846 | 8.8 | — | — | — | — | A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 56d ago |
| CVE-2026-19679 | 8.8 | — | — | — | tenable / security center | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitizatio | 56d ago |
| CVE-2026-19635 | 8.8 | — | — | — | tenable / security center | A local privilege escalation vulnerability exists in Security Center. | 56d ago |
| CVE-2026-12366 | 8.8 | — | — | — | — | Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's stora | 56d ago |
| CVE-2026-19845 | 8.8 | — | — | — | — | A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 56d ago |
| CVE-2026-19844 | 8.8 | — | — | — | — | A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 56d ago |
| CVE-2026-73673 | 8.8 | — | — | — | — | Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unaut | 57d ago |
| CVE-2026-19824 | 8.8 | — | — | — | — | A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. | 57d ago |
| CVE-2026-19823 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. | 57d ago |
| CVE-2026-72837 | 8.8 | — | — | — | — | File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication au | 57d ago |
| CVE-2026-72833 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulne | 57d ago |
| CVE-2026-72831 | 8.8 | — | — | — | — | The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability | 57d ago |
| CVE-2026-72830 | 8.8 | — | — | — | — | Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, a | 57d ago |
| CVE-2026-72829 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersControlle | 57d ago |
| CVE-2026-72827 | 8.8 | — | — | — | — | Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that all | 57d ago |
| CVE-2026-72826 | 8.8 | — | — | — | — | The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are | 57d ago |
| CVE-2026-72824 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesControlle | 57d ago |
| CVE-2026-72822 | 8.8 | — | — | — | — | The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope cap | 57d ago |
| CVE-2026-72819 | 8.8 | — | — | — | — | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validati | 57d ago |
| CVE-2026-19822 | 8.8 | — | — | — | — | A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. | 57d ago |
| CVE-2026-19821 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. | 57d ago |
| CVE-2026-19815 | 8.8 | — | — | — | — | A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 57d ago |
| CVE-2026-19814 | 8.8 | — | — | — | — | A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 57d ago |
| CVE-2026-19813 | 8.8 | — | — | — | — | A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 57d ago |
| CVE-2026-19812 | 8.8 | — | — | — | — | A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 57d ago |
| CVE-2026-19811 | 8.8 | — | — | — | — | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. | 57d ago |
| CVE-2026-19792 | 8.8 | — | — | — | — | A security flaw has been discovered in Tenda G0 up to 20260625. | 57d ago |
| CVE-2026-19791 | 8.8 | — | — | — | — | A weakness has been identified in Tenda G0 up to 20260625. | 57d ago |
| CVE-2026-19790 | 8.8 | — | — | — | — | A vulnerability was identified in Tenda G0 up to 20260625. | 57d ago |
| CVE-2026-19789 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. | 57d ago |
| CVE-2026-19788 | 8.8 | — | — | — | — | A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. | 57d ago |
| CVE-2026-73841 | 8.8 | — | — | — | — | OpenChoreo is a complete, open-source developer platform for Kubernetes. | 57d ago |
| CVE-2026-73667 | 8.8 | — | — | — | — | OpenChoreo is a complete, open-source developer platform for Kubernetes. | 57d ago |