| CVE-2026-73305 | 8.8 | — | — | — | — | Budibase is an open-source low-code platform. | 58d ago |
| CVE-2026-72840 | 8.8 | — | — | — | — | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /e | 58d ago |
| CVE-2026-18101 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management o | 58d ago |
| CVE-2026-17481 | 8.8 | — | — | — | ibm / documentation offline | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to impro | 58d ago |
| CVE-2026-72642 | 8.8 | — | — | — | elastic / elasticsearch | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model | 58d ago |
| CVE-2026-17223 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer | 58d ago |
| CVE-2026-17029 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. | 58d ago |
| CVE-2026-16987 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation o | 58d ago |
| CVE-2026-16975 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-b | 58d ago |
| CVE-2026-16722 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to | 58d ago |
| CVE-2026-16674 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untru | 58d ago |
| CVE-2026-18428 | 8.8 | — | — | — | — | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote au | 58d ago |
| CVE-2026-59109 | 8.8 | — | — | — | — | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electro | 58d ago |
| CVE-2026-73514 | 8.8 | — | — | — | — | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds w | 59d ago |
| CVE-2026-68454 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable wit | 59d ago |
| CVE-2026-19293 | 8.8 | — | — | — | — | SMP security request (from peripheral) does not include the maximum encryption key size supported. | 59d ago |
| CVE-2026-19292 | 8.8 | — | — | — | — | Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easi | 59d ago |
| CVE-2026-19291 | 8.8 | — | — | — | — | Bluetooth re-pairing with an existing device can use a lower security level. | 59d ago |
| CVE-2026-16101 | 8.8 | — | — | — | — | Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. | 59d ago |
| CVE-2026-28176 | 8.8 | — | — | — | — | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | 59d ago |
| CVE-2026-28161 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | 59d ago |
| CVE-2026-19385 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute ar | 59d ago |
| CVE-2026-18408 | 8.8 | — | — | — | postgresql / postgresql | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbi | 59d ago |
| CVE-2026-16239 | 8.8 | — | — | — | postgresql / postgresql | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating sy | 59d ago |
| CVE-2026-16238 | 8.8 | — | — | — | postgresql / postgresql | Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as th | 59d ago |
| CVE-2026-15742 | 8.8 | — | — | — | postgresql / postgresql | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, execut | 59d ago |
| CVE-2026-15741 | 8.8 | — | — | — | postgresql / postgresql | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a | 59d ago |
| CVE-2026-14680 | 8.8 | — | — | — | postgresql / postgresql | Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the ope | 59d ago |
| CVE-2026-14677 | 8.8 | — | — | — | postgresql / postgresql | Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to | 59d ago |
| CVE-2026-14676 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the ope | 59d ago |
| CVE-2026-14671 | 8.8 | — | — | — | postgresql / postgresql | Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating s | 59d ago |
| CVE-2026-14670 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary cod | 59d ago |
| CVE-2026-14669 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrar | 59d ago |
| CVE-2026-14664 | 8.8 | — | — | — | postgresql / postgresql | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating syste | 59d ago |
| CVE-2026-14662 | 8.8 | — | — | — | postgresql / postgresql | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to | 59d ago |
| CVE-2026-73625 | 8.8 | — | — | — | gitpython project / gitpython | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard t | 59d ago |
| CVE-2026-73615 | 8.8 | — | — | — | — | Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates ra | 59d ago |
| CVE-2026-73614 | 8.8 | — | — | — | — | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatt | 59d ago |
| CVE-2026-73601 | 8.8 | — | — | — | flowiseai / flowise | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP | 59d ago |
| CVE-2026-73486 | 8.8 | — | — | — | flowiseai / flowise | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that | 59d ago |
| CVE-2026-73485 | 8.8 | — | — | — | flowiseai / flowise | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticate | 59d ago |
| CVE-2026-73483 | 8.8 | — | — | — | flowiseai / flowise | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowis | 59d ago |
| CVE-2026-12263 | 8.8 | — | — | — | — | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to | 59d ago |
| CVE-2026-11840 | 8.8 | — | — | — | — | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are | 59d ago |
| CVE-2026-49473 | 8.8 | — | — | — | — | @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorizat | 59d ago |
| CVE-2026-13622 | 8.8 | — | — | — | — | A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. | 59d ago |
| CVE-2026-13105 | 8.8 | — | — | — | ibm / i access client solutions | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when impor | 59d ago |
| CVE-2026-17642 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr | 59d ago |
| CVE-2026-17417 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr | 59d ago |
| CVE-2026-17082 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improp | 59d ago |
| CVE-2026-13361 | 8.8 | — | — | — | ibm / informix dynamic server | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | 59d ago |
| CVE-2026-69106 | 8.8 | — | — | — | — | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers | 59d ago |
| CVE-2026-49467 | 8.8 | — | — | — | — | Pingvin Share X is a secure and easy self-hosted file sharing platform. | 59d ago |
| CVE-2026-44741 | 8.8 | — | — | — | — | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. | 59d ago |
| CVE-2026-18713 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. | 59d ago |
| CVE-2026-18669 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vuln | 59d ago |
| CVE-2026-17110 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain | 59d ago |
| CVE-2026-16906 | 8.8 | — | — | — | ibm / i | IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privile | 59d ago |
| CVE-2026-16856 | 8.8 | — | — | — | ibm / i | IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of spec | 59d ago |
| CVE-2026-18847 | 8.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing | 59d ago |