| CVE-2026-28191 | 8.8 | high | — | Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. | 18d ago |
| CVE-2026-24301 | 8.8 | high | — | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an | 18d ago |
| CVE-2026-74969 | 8.8 | high | mozilla / firefox | Use-after-free in the Layout: Text and Fonts component. | 18d ago |
| CVE-2026-74965 | 8.8 | high | mozilla / firefox | Privilege escalation in the Shell Integration component. | 18d ago |
| CVE-2026-74955 | 8.8 | high | mozilla / firefox | Privilege escalation in the Request Handling component. | 18d ago |
| CVE-2026-74953 | 8.8 | high | mozilla / firefox | Privilege escalation in the Networking: Cookies component. | 18d ago |
| CVE-2026-74952 | 8.8 | high | mozilla / firefox | Privilege escalation in the Application Update component. | 18d ago |
| CVE-2026-74950 | 8.8 | high | mozilla / firefox | Privilege escalation in the Downloads API component. | 18d ago |
| CVE-2026-74949 | 8.8 | high | mozilla / firefox | Privilege escalation due to use-after-free in the Graphics: Canvas2D component. | 18d ago |
| CVE-2026-74947 | 8.8 | high | mozilla / firefox | Privilege escalation due to invalid pointer in the Graphics component. | 18d ago |
| CVE-2026-74946 | 8.8 | high | mozilla / firefox | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. | 18d ago |
| CVE-2026-74942 | 8.8 | high | mozilla / firefox | Privilege escalation in the Remote Settings Client component. | 18d ago |
| CVE-2026-74941 | 8.8 | high | mozilla / firefox | Privilege escalation in the Graphics: CanvasWebGL component. | 18d ago |
| CVE-2026-74939 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Navigation component. | 18d ago |
| CVE-2026-74937 | 8.8 | high | mozilla / firefox | Use-after-free in the JavaScript: GC component. | 18d ago |
| CVE-2026-74935 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Networking component. | 18d ago |
| CVE-2026-75853 | 8.8 | high | — | ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authenticat | 18d ago |
| CVE-2026-75836 | 8.8 | high | — | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enf | 18d ago |
| CVE-2026-75827 | 8.8 | high | — | Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function vali | 18d ago |
| CVE-2026-65346 | 8.8 | high | apple / ipados | An integer overflow was addressed with improved input validation. | 19d ago |
| CVE-2026-43794 | 8.8 | high | apple / safari | A memory corruption issue was addressed with improved memory handling. | 19d ago |
| CVE-2026-75481 | 8.8 | high | — | SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating servic | 19d ago |
| CVE-2026-75103 | 8.8 | high | — | Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authen | 19d ago |
| CVE-2026-65640 | 8.8 | high | — | WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author | 19d ago |
| CVE-2026-70495 | 8.8 | high | — | A flaw was found in search-v2-operator. | 19d ago |
| CVE-2026-62982 | 8.8 | high | — | Glances is an open-source system cross-platform monitoring tool. | 19d ago |
| CVE-2026-50768 | 8.8 | high | — | File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker | 19d ago |
| CVE-2026-9771 | 8.8 | high | — | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. | 19d ago |
| CVE-2026-74997 | 8.8 | high | — | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subjec | 19d ago |
| CVE-2026-74893 | 8.8 | high | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validat | 19d ago |
| CVE-2026-74883 | 8.8 | high | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to res | 19d ago |
| CVE-2026-74877 | 8.8 | high | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key met | 19d ago |
| CVE-2026-74845 | 8.8 | high | — | Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allow | 19d ago |
| CVE-2026-17123 | 8.8 | high | — | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, an | 21d ago |
| CVE-2026-16099 | 8.8 | high | — | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi | 21d ago |
| CVE-2026-14498 | 8.8 | high | — | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin | 21d ago |
| CVE-2026-74575 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain delayed work use- | 21d ago |
| CVE-2026-74562 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: nexthop: take nh->lock for f6i_list walks in r | 21d ago |
| CVE-2026-74561 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: nexthop: avoid unlocked f6i_list walk in nh_rt | 21d ago |
| CVE-2026-74554 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bounds clear_bit in a | 21d ago |
| CVE-2026-74541 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: clear iso_data always when det | 21d ago |
| CVE-2026-74540 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_ | 21d ago |
| CVE-2026-74538 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_connect_ind Acc | 21d ago |
| CVE-2026-74537 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: hold sk properly in iso_conn_r | 21d ago |
| CVE-2026-74535 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks in iso_sock_ti | 21d ago |
| CVE-2026-74534 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting of iso_conn is | 21d ago |
| CVE-2026-74533 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix race of kfree vs kref_get_ | 21d ago |
| CVE-2026-74531 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn reference in ab | 21d ago |
| CVE-2026-74530 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_ | 21d ago |
| CVE-2026-74527 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Block VFs from clobbering specia | 21d ago |
| CVE-2026-74522 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __close_file_tabl | 21d ago |
| CVE-2026-74520 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix IOPF group ownership UAF io | 21d ago |
| CVE-2026-74515 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Reject adapter interrupt forwa | 21d ago |
| CVE-2026-74509 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix advertising data UAFs | 21d ago |
| CVE-2026-74508 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames without a trans | 21d ago |
| CVE-2026-74490 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: tipc: avoid use-after-free in poll trace queue | 21d ago |
| CVE-2026-74489 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix tid_tx use-after-free on B | 21d ago |
| CVE-2026-74488 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: use the subframe length when pa | 21d ago |
| CVE-2026-74469 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sc | 21d ago |
| CVE-2026-74443 | 8.8 | high | — | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command body size agains | 21d ago |