| CVE-2026-28931 | 8.8 | — | — | — | apple / ipados | A buffer overflow was addressed with improved bounds checking. | 74d ago |
| CVE-2026-66014 | 8.8 | — | — | — | jfrog / artifactory | JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific | 74d ago |
| CVE-2026-65921 | 8.8 | — | — | — | jfrog / artifactory | A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be writ | 74d ago |
| CVE-2026-65617 | 8.8 | — | — | — | jfrog / artifactory | A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confi | 74d ago |
| CVE-2026-65616 | 8.8 | — | — | — | jfrog / artifactory | Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog admi | 74d ago |
| CVE-2026-56748 | 8.8 | — | — | — | cribl / cribl stream | Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote | 74d ago |
| CVE-2026-56747 | 8.8 | — | — | — | cribl / cribl stream | Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allo | 74d ago |
| CVE-2026-42017 | 8.8 | — | — | — | jfrog / artifactory | An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileg | 74d ago |
| CVE-2026-55578 | 8.8 | — | — | — | — | Pheditor is a single-file editor and file manager written in PHP. | 75d ago |
| CVE-2026-54540 | 8.8 | — | — | — | — | Pheditor is a single-file editor and file manager written in PHP. | 75d ago |
| CVE-2026-17568 | 8.8 | — | — | — | devolutions / devolutions server | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated n | 75d ago |
| CVE-2026-15962 | 8.8 | — | — | — | — | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, | 76d ago |
| CVE-2026-64522 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix eswitch mode block underflow on | 77d ago |
| CVE-2026-64516 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce1: Fix VCE 1 firmware size and o | 77d ago |
| CVE-2026-64475 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Release the VGA arbiter client on re | 77d ago |
| CVE-2026-64467 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64 stride when cleaning up | 77d ago |
| CVE-2026-64445 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow a | 77d ago |
| CVE-2026-64441 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_s | 77d ago |
| CVE-2026-64438 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in | 77d ago |
| CVE-2026-64437 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_l | 77d ago |
| CVE-2026-64434 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout b | 77d ago |
| CVE-2026-64408 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during n | 77d ago |
| CVE-2026-64396 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOC | 77d ago |
| CVE-2026-64394 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SM | 77d ago |
| CVE-2026-64390 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: track the connection owning a byte-rang | 77d ago |
| CVE-2026-64382 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() re | 77d ago |
| CVE-2026-64366 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix slab-out-of-bounds write in wa | 77d ago |
| CVE-2026-64364 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access | 77d ago |
| CVE-2026-64313 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multip | 77d ago |
| CVE-2026-64280 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in | 77d ago |
| CVE-2026-61892 | 8.8 | — | — | — | — | Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. | 77d ago |
| CVE-2026-60134 | 8.8 | — | — | — | — | Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. | 77d ago |
| CVE-2026-66041 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_qui | 77d ago |
| CVE-2026-66040 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG | 77d ago |
| CVE-2026-66039 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio | 77d ago |
| CVE-2026-66036 | 8.8 | — | — | — | ffmpeg / ffmpeg | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d | 77d ago |
| CVE-2026-66032 | 8.8 | — | — | — | libssh2 / libssh2 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function | 78d ago |
| CVE-2026-64255 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before f | 78d ago |
| CVE-2026-16801 | 8.8 | — | — | — | devolutions / powershell universal | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Unive | 78d ago |
| CVE-2026-16800 | 8.8 | — | — | — | devolutions / powershell universal | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Univer | 78d ago |
| CVE-2026-45813 | 8.8 | — | — | — | apache / nimble | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. | 78d ago |
| CVE-2026-16870 | 8.8 | — | — | — | — | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code | 78d ago |
| CVE-2026-16807 | 8.8 | — | — | — | google / chrome | Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially pe | 78d ago |
| CVE-2026-16806 | 8.8 | — | — | — | google / chrome | Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary c | 78d ago |
| CVE-2026-16805 | 8.8 | — | — | — | google / chrome | Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary co | 78d ago |
| CVE-2026-15212 | 8.8 | — | — | — | — | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi | 78d ago |
| CVE-2026-65917 | 8.8 | — | — | — | — | CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerabili | 79d ago |
| CVE-2026-65690 | 8.8 | — | — | — | syncfusion / standalone report designer | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its | 79d ago |
| CVE-2026-65906 | 8.8 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | 79d ago |
| CVE-2026-65897 | 8.8 | — | — | — | — | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allow | 79d ago |
| CVE-2026-65608 | 8.8 | — | — | — | — | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. | 79d ago |
| CVE-2026-59541 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | 79d ago |
| CVE-2026-57785 | 8.8 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | 79d ago |
| CVE-2026-16745 | 8.8 | — | — | — | — | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). | 79d ago |
| CVE-2026-64876 | 8.8 | — | — | — | — | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Databa | 79d ago |
| CVE-2026-15017 | 8.8 | — | — | — | — | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in | 79d ago |
| CVE-2026-61246 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 79d ago |
| CVE-2026-60455 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 79d ago |
| CVE-2026-60439 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 79d ago |
| CVE-2026-60373 | 8.8 | — | — | — | oracle / platform security for java | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized | 79d ago |