| CVE-2026-62784 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to | 60d ago |
| CVE-2026-59133 | 8.8 | — | — | — | microsoft / windows app | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized atta | 60d ago |
| CVE-2026-59113 | 8.8 | — | — | — | microsoft / visual studio code | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 60d ago |
| CVE-2026-57104 | 8.8 | — | — | — | microsoft / azure storage explorer | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer all | 60d ago |
| CVE-2026-49179 | 8.8 | — | — | — | microsoft / windows 10 1607 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory al | 60d ago |
| CVE-2026-20749 | 8.8 | — | — | — | intel / proset\/wireless wifi | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow an esca | 60d ago |
| CVE-2026-56721 | 8.8 | — | — | — | — | CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object ref | 60d ago |
| CVE-2026-19546 | 8.8 | — | — | — | — | A flaw was found in DBI. | 60d ago |
| CVE-2026-72781 | 8.8 | — | — | — | — | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulne | 60d ago |
| CVE-2026-72778 | 8.8 | — | — | — | — | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote c | 60d ago |
| CVE-2026-72775 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which | 60d ago |
| CVE-2026-72750 | 8.8 | — | — | — | n8n / n8n | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Que | 60d ago |
| CVE-2026-72562 | 8.8 | — | — | — | — | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend | 60d ago |
| CVE-2026-72561 | 8.8 | — | — | — | — | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated | 60d ago |
| CVE-2026-72558 | 8.8 | — | — | — | — | An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire databa | 60d ago |
| CVE-2026-72557 | 8.8 | — | — | — | — | An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any e | 60d ago |
| CVE-2026-72556 | 8.8 | — | — | — | — | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands b | 60d ago |
| CVE-2026-72551 | 8.8 | — | — | — | — | A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to e | 60d ago |
| CVE-2026-72538 | 8.8 | — | — | — | — | An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remot | 60d ago |
| CVE-2026-72537 | 8.8 | — | — | — | — | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a so | 60d ago |
| CVE-2026-72534 | 8.8 | — | — | — | — | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a so | 60d ago |
| CVE-2026-72533 | 8.8 | — | — | — | — | An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to | 60d ago |
| CVE-2026-15555 | 8.8 | — | — | — | — | A flaw was found in JBoss marshalling. | 60d ago |
| CVE-2026-58243 | 8.8 | — | — | — | — | SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an | 60d ago |
| CVE-2026-18982 | 8.8 | — | — | — | — | A flaw was found in the RHOAI training-operator. | 60d ago |
| CVE-2026-18951 | 8.8 | — | — | — | — | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. | 60d ago |
| CVE-2026-18950 | 8.8 | — | — | — | — | A flaw was found in odh-dashboard. | 60d ago |
| CVE-2026-18949 | 8.8 | — | — | — | — | A flaw was found in odh-dashboard. | 60d ago |
| CVE-2026-18617 | 8.8 | — | — | — | — | A flaw was found in the Data Science Pipelines Operator (DSPO). | 60d ago |
| CVE-2026-13717 | 8.8 | — | — | — | — | A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. | 60d ago |
| CVE-2026-72883 | 8.8 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 60d ago |
| CVE-2026-72875 | 8.8 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 60d ago |
| CVE-2026-71966 | 8.8 | — | — | — | — | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote | 60d ago |
| CVE-2026-71965 | 8.8 | — | — | — | — | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the re | 60d ago |
| CVE-2026-69118 | 8.8 | — | — | — | — | Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that a | 60d ago |
| CVE-2026-72866 | 8.8 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 60d ago |
| CVE-2026-66738 | 8.8 | — | — | — | — | SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. | 61d ago |
| CVE-2026-68409 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu fre | 61d ago |
| CVE-2026-68397 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found | 61d ago |
| CVE-2026-68393 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: extend conn_hash lookup c | 61d ago |
| CVE-2026-68390 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold hdev->lock for hci_c | 61d ago |
| CVE-2026-68389 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: Clear memdump state on inv | 61d ago |
| CVE-2026-68354 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassem | 61d ago |
| CVE-2026-68341 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ovpn: fix use after free in unlock_ovpn() unlo | 61d ago |
| CVE-2026-68329 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of retu | 61d ago |
| CVE-2026-68326 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound uAP association event IEs | 61d ago |
| CVE-2026-68294 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: restrict socket creation to the ini | 61d ago |
| CVE-2026-68283 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free freeing trigger pr | 61d ago |
| CVE-2026-68240 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: publish dpagemap early to avoid de | 61d ago |
| CVE-2026-68199 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADD | 61d ago |
| CVE-2026-68198 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset | 61d ago |
| CVE-2026-68192 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers id | 61d ago |
| CVE-2026-68142 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device ne | 61d ago |
| CVE-2026-68140 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv | 61d ago |
| CVE-2026-68128 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_p | 61d ago |
| CVE-2026-68125 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than t | 61d ago |
| CVE-2026-68108 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image | 61d ago |
| CVE-2026-68107 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param leng | 61d ago |
| CVE-2026-68098 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs se | 61d ago |
| CVE-2026-68097 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-autho | 61d ago |