| CVE-2026-18898 | 8.8 | — | — | — | — | A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. | 66d ago |
| CVE-2026-18897 | 8.8 | — | — | — | — | A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. | 66d ago |
| CVE-2026-18895 | 8.8 | — | — | — | — | A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. | 66d ago |
| CVE-2026-70619 | 8.8 | — | — | — | — | Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin | 66d ago |
| CVE-2026-16793 | 8.8 | — | — | — | — | An improper neutralization of special elements used in an operating system command vulnerability was reported in L | 66d ago |
| CVE-2026-18787 | 8.8 | — | — | — | — | A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. | 67d ago |
| CVE-2026-15307 | 8.8 | — | — | — | djangoproject / django | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. | 67d ago |
| CVE-2026-69100 | 8.8 | — | — | — | — | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerabi | 67d ago |
| CVE-2026-67195 | 8.8 | — | — | — | — | Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute | 67d ago |
| CVE-2026-18650 | 8.8 | — | — | — | — | Missing Authorization vulnerability in HAVELSAN Inc. | 67d ago |
| CVE-2026-17070 | 8.8 | — | — | — | — | Missing Authorization vulnerability in HAVELSAN Inc. | 67d ago |
| CVE-2026-70373 | 8.8 | — | — | — | — | Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate b | 67d ago |
| CVE-2026-70372 | 8.8 | — | — | — | — | Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled requ | 67d ago |
| CVE-2026-70371 | 8.8 | — | — | — | — | Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled re | 67d ago |
| CVE-2026-70370 | 8.8 | — | — | — | — | Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line an | 67d ago |
| CVE-2026-70369 | 8.8 | — | — | — | — | Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the us | 67d ago |
| CVE-2026-64562 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEA | 67d ago |
| CVE-2026-64561 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *aft | 67d ago |
| CVE-2026-62870 | 8.8 | — | — | — | microsoft / 365 apps | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | 67d ago |
| CVE-2026-18733 | 8.8 | — | — | — | — | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote | 67d ago |
| CVE-2026-41453 | 8.8 | — | — | — | — | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticat | 68d ago |
| CVE-2026-18607 | 8.8 | — | — | — | — | A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. | 68d ago |
| CVE-2026-69096 | 8.8 | — | — | — | — | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend | 68d ago |
| CVE-2026-18600 | 8.8 | — | — | — | — | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. | 68d ago |
| CVE-2026-18598 | 8.8 | — | — | — | — | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. | 68d ago |
| CVE-2026-67356 | 8.8 | — | — | — | — | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, a | 69d ago |
| CVE-2026-67343 | 8.8 | — | — | — | — | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allo | 70d ago |
| CVE-2026-67325 | 8.8 | — | — | — | gitpython project / gitpython | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-op | 70d ago |
| CVE-2026-16635 | 8.8 | — | — | — | — | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, | 70d ago |
| CVE-2026-15988 | 8.8 | — | — | — | — | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Req | 70d ago |
| CVE-2026-14596 | 8.8 | — | — | — | — | The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used | 70d ago |
| CVE-2026-15414 | 8.8 | — | — | — | — | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, an | 70d ago |
| CVE-2026-50986 | 8.8 | — | — | — | — | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). | 70d ago |
| CVE-2026-17346 | 8.8 | — | — | — | pgadmin / pgadmin 4 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pg | 71d ago |
| CVE-2026-16236 | 8.8 | — | — | — | — | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and includ | 71d ago |
| CVE-2026-13609 | 8.8 | — | — | — | — | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field va | 71d ago |
| CVE-2026-66420 | 8.8 | — | — | — | — | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthent | 71d ago |
| CVE-2026-65423 | 8.8 | — | — | — | — | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker | 71d ago |
| CVE-2026-12562 | 8.8 | — | — | — | — | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting | 71d ago |
| CVE-2026-67207 | 8.8 | — | — | — | — | Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows aut | 71d ago |
| CVE-2026-67206 | 8.8 | — | — | — | — | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authe | 71d ago |
| CVE-2026-66416 | 8.8 | — | — | — | — | Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perfor | 71d ago |
| CVE-2026-58222 | 8.8 | — | — | — | — | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Direct | 72d ago |
| CVE-2026-28813 | 8.8 | — | — | — | apache / jspwiki | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. | 72d ago |
| CVE-2026-14522 | 8.8 | — | — | — | ibm / app connect enterprise | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacke | 72d ago |
| CVE-2026-67351 | 8.8 | — | — | — | — | Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and | 72d ago |
| CVE-2026-54368 | 8.8 | — | — | — | — | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that | 72d ago |
| CVE-2026-22622 | 8.8 | — | — | — | — | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware co | 72d ago |
| CVE-2026-16526 | 8.8 | — | — | — | — | A flaw in the PCP linux_sockets module exposes an unsecured internal connection. | 72d ago |
| CVE-2026-67248 | 8.8 | — | — | — | asustor / data master | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. | 72d ago |
| CVE-2026-14356 | 8.8 | — | — | — | — | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, | 72d ago |
| CVE-2026-18017 | 8.8 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code | 72d ago |
| CVE-2026-18012 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 72d ago |
| CVE-2026-17989 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 72d ago |
| CVE-2026-17971 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti | 72d ago |
| CVE-2026-17969 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exe | 72d ago |
| CVE-2026-17967 | 8.8 | — | — | — | google / chrome | Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to poten | 72d ago |
| CVE-2026-17956 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex | 72d ago |
| CVE-2026-17951 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out | 72d ago |
| CVE-2026-17950 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attac | 72d ago |