| CVE-2026-17935 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitr | 72d ago |
| CVE-2026-17922 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex | 72d ago |
| CVE-2026-17920 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a | 72d ago |
| CVE-2026-17918 | 8.8 | — | — | — | google / chrome | Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code | 72d ago |
| CVE-2026-17899 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convin | 72d ago |
| CVE-2026-17894 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially | 72d ago |
| CVE-2026-17886 | 8.8 | — | — | — | google / chrome | Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially expl | 72d ago |
| CVE-2026-17884 | 8.8 | — | — | — | google / chrome | Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially | 72d ago |
| CVE-2026-17881 | 8.8 | — | — | — | google / chrome | Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary c | 72d ago |
| CVE-2026-17875 | 8.8 | — | — | — | google / chrome | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 72d ago |
| CVE-2026-17868 | 8.8 | — | — | — | google / chrome | Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perfor | 72d ago |
| CVE-2026-17836 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 72d ago |
| CVE-2026-17807 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 72d ago |
| CVE-2026-17786 | 8.8 | — | — | — | google / chrome | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker | 72d ago |
| CVE-2026-17784 | 8.8 | — | — | — | google / chrome | Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromis | 72d ago |
| CVE-2026-17778 | 8.8 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrar | 72d ago |
| CVE-2026-17752 | 8.8 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially ex | 72d ago |
| CVE-2026-17751 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exec | 72d ago |
| CVE-2026-17729 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the ren | 72d ago |
| CVE-2026-17725 | 8.8 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 72d ago |
| CVE-2026-17719 | 8.8 | — | — | — | google / chrome | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary cod | 72d ago |
| CVE-2026-17712 | 8.8 | — | — | — | google / chrome | Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code in | 72d ago |
| CVE-2026-17705 | 8.8 | — | — | — | google / chrome | Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary | 72d ago |
| CVE-2026-17694 | 8.8 | — | — | — | google / chrome | Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code | 72d ago |
| CVE-2026-17685 | 8.8 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary | 72d ago |
| CVE-2026-17678 | 8.8 | — | — | — | google / chrome | Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised | 72d ago |
| CVE-2026-17677 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker | 72d ago |
| CVE-2026-17665 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 72d ago |
| CVE-2026-17661 | 8.8 | — | — | — | google / chrome | Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co | 72d ago |
| CVE-2026-17658 | 8.8 | — | — | — | google / chrome | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i | 72d ago |
| CVE-2026-5490 | 8.8 | — | — | — | — | DriveLock SQL Injection Privilege Escalation Vulnerability. | 72d ago |
| CVE-2026-18022 | 8.8 | — | — | — | pgvector project / pgvector | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bou | 72d ago |
| CVE-2026-65944 | 8.8 | — | — | — | rolandd / ro csvi | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | 73d ago |
| CVE-2026-65885zero day | 8.8 | 0.52% | 1/3 | same day | balbooa / gridbox | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods all | 73d ago |
| CVE-2026-14270 | 8.8 | — | — | — | — | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vul | 73d ago |
| CVE-2026-50622 | 8.8 | — | — | — | apache / atlas | Description: Missing Authorization in Apache Atlas. | 73d ago |
| CVE-2026-64557 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_ | 73d ago |
| CVE-2026-12144 | 8.8 | — | — | — | — | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an | 73d ago |
| CVE-2026-54653 | 8.8 | — | — | — | koxudaxi / datamodel-code-generator | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JS | 73d ago |
| CVE-2026-57510 | 8.8 | — | — | — | — | SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC hand | 73d ago |
| CVE-2026-16347 | 8.8 | — | — | — | — | MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against e | 73d ago |
| CVE-2026-49258 | 8.8 | — | — | — | — | Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. | 73d ago |
| CVE-2026-16771 | 8.8 | — | — | — | — | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authenticati | 73d ago |
| CVE-2026-15992 | 8.8 | — | — | — | — | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and includ | 73d ago |
| CVE-2026-66748 | 8.8 | — | — | — | — | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allow | 74d ago |
| CVE-2026-63727 | 8.8 | — | — | — | — | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability | 74d ago |
| CVE-2026-7187 | 8.8 | — | — | — | — | Missing authentication for critical function vulnerability in Universal Software Inc. | 74d ago |
| CVE-2026-62427 | 8.8 | — | — | — | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond | 74d ago |
| CVE-2026-62426 | 8.8 | — | — | — | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond | 74d ago |
| CVE-2026-14328 | 8.8 | — | — | — | — | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to | 74d ago |
| CVE-2026-14168 | 8.8 | — | — | — | — | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path | 74d ago |
| CVE-2026-14167 | 8.8 | — | — | — | — | A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level | 74d ago |
| CVE-2021-32087 | 8.8 | — | — | — | quest / kace systems management appliance | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. | 74d ago |
| CVE-2021-32085 | 8.8 | — | — | — | quest / kace systems management appliance | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. | 74d ago |
| CVE-2026-64783 | 8.8 | — | — | — | apple / safari | A use-after-free issue was addressed with improved memory management. | 74d ago |
| CVE-2026-64757 | 8.8 | — | — | — | apple / safari | A memory corruption issue was addressed with improved state management. | 74d ago |
| CVE-2026-64739 | 8.8 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved bounds checking. | 74d ago |
| CVE-2026-64555 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hy | 74d ago |
| CVE-2026-64554 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale prevhdr pointer i | 74d ago |
| CVE-2026-43818 | 8.8 | — | — | — | apple / ipados | An integer overflow was addressed with improved input validation. | 74d ago |