| CVE-2026-68091 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start pro | 61d ago |
| CVE-2026-72578 | 8.8 | — | — | — | — | A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attac | 61d ago |
| CVE-2026-72573 | 8.8 | — | — | — | — | An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to | 61d ago |
| CVE-2026-66405 | 8.8 | — | — | — | — | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. | 61d ago |
| CVE-2026-18786 | 8.8 | — | — | — | — | The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes | 61d ago |
| CVE-2026-17540 | 8.8 | — | — | — | — | The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing | 61d ago |
| CVE-2026-16985 | 8.8 | — | — | — | — | The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data | 61d ago |
| CVE-2026-14293 | 8.8 | — | — | — | — | The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling o | 61d ago |
| CVE-2026-19346 | 8.8 | — | — | — | — | A vulnerability was determined in Tenda CH22 1.0.0.1. | 62d ago |
| CVE-2026-19341 | 8.8 | — | — | — | — | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. | 62d ago |
| CVE-2026-48169 | 8.8 | — | — | — | — | PraisonAI is a multi-agent teams system. | 63d ago |
| CVE-2026-9169 | 8.8 | — | — | — | — | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute a | 64d ago |
| CVE-2026-16263 | 8.8 | — | — | — | — | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does | 64d ago |
| CVE-2026-15215 | 8.8 | — | — | — | — | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before insta | 64d ago |
| CVE-2026-65668 | 8.8 | — | — | — | microsoft / purview ediscovery | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a | 64d ago |
| CVE-2026-49163 | 8.8 | — | — | — | microsoft / application insights profiler | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler al | 64d ago |
| CVE-2026-67687 | 8.8 | — | — | — | — | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /syst | 64d ago |
| CVE-2026-48054 | 8.8 | — | — | — | — | OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZep | 64d ago |
| CVE-2026-19174 | 8.8 | — | — | — | google / chrome | Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary cod | 64d ago |
| CVE-2026-19169 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a | 64d ago |
| CVE-2026-19168 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute a | 64d ago |
| CVE-2026-19162 | 8.8 | — | — | — | google / chrome | Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary | 64d ago |
| CVE-2026-19151 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code | 64d ago |
| CVE-2026-19150 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute a | 64d ago |
| CVE-2026-19145 | 8.8 | — | — | — | google / chrome | Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrar | 64d ago |
| CVE-2026-19144 | 8.8 | — | — | — | google / chrome | Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit h | 64d ago |
| CVE-2024-39024 | 8.8 | — | — | — | — | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. | 64d ago |
| CVE-2026-18258 | 8.8 | — | — | — | escriptorium / escriptorium | Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/e | 65d ago |
| CVE-2026-65542 | 8.8 | — | — | — | — | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | 65d ago |
| CVE-2026-28111 | 8.8 | — | — | — | — | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | 65d ago |
| CVE-2026-64598 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_al | 65d ago |
| CVE-2026-64586 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device | 65d ago |
| CVE-2026-15991 | 8.8 | — | — | — | — | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid | 65d ago |
| CVE-2026-68746 | 8.8 | — | — | — | livebook / livebook | Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network cli | 65d ago |
| CVE-2026-66298 | 8.8 | — | — | — | livebook / livebook | Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trig | 65d ago |
| CVE-2026-9201 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryp | 65d ago |
| CVE-2026-8478 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to | 65d ago |
| CVE-2026-8182 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the s | 65d ago |
| CVE-2026-17632 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to | 65d ago |
| CVE-2026-70432 | 8.8 | — | — | — | — | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allow | 65d ago |
| CVE-2026-70431 | 8.8 | — | — | — | — | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate w | 65d ago |
| CVE-2026-20312 | 8.8 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN enginee | 66d ago |
| CVE-2026-20200 | 8.8 | — | — | — | cisco / unified computing system | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker w | 66d ago |
| CVE-2026-17626 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose se | 66d ago |
| CVE-2026-17623 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands du | 66d ago |
| CVE-2026-15572 | 8.8 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. | 66d ago |
| CVE-2026-67623 | 8.8 | — | — | — | — | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitra | 66d ago |
| CVE-2026-71291 | 8.8 | — | — | — | — | Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension r | 66d ago |
| CVE-2026-71288 | 8.8 | — | — | — | — | Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamicall | 66d ago |
| CVE-2026-71287 | 8.8 | — | — | — | — | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . | 66d ago |
| CVE-2026-71281 | 8.8 | — | — | — | — | Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, a | 66d ago |
| CVE-2026-71243 | 8.8 | — | — | — | — | The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source | 66d ago |
| CVE-2026-71235 | 8.8 | — | — | — | — | Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed serv | 66d ago |
| CVE-2026-60009 | 8.8 | — | — | — | eclipse / theia | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in | 66d ago |
| CVE-2026-6147 | 8.8 | — | — | — | — | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation | 66d ago |
| CVE-2026-55997 | 8.8 | — | — | — | — | Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. | 66d ago |
| CVE-2026-70375 | 8.8 | — | — | — | — | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. | 66d ago |
| CVE-2026-70374 | 8.8 | — | — | — | — | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail | 66d ago |
| CVE-2026-8761 | 8.8 | — | — | — | — | The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. | 66d ago |
| CVE-2026-18322exploited | 8.8 | 0.59% | 1/3 | +50d | — | The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and | 66d ago |