| CVE-2026-63946 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix UAF in iso_recv_frame iso_ | 83d ago |
| CVE-2026-63944 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix UAF in hci_le_create_ | 83d ago |
| CVE-2026-63941 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly cap ZCR_EL2 provided by | 83d ago |
| CVE-2026-63937 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Use READ_ONCE() when reading entries | 83d ago |
| CVE-2026-63923 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: validate body pcifunc in rvu_mbo | 83d ago |
| CVE-2026-63921 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevpriva | 83d ago |
| CVE-2026-63919 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transp | 83d ago |
| CVE-2026-63917 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink() | 83d ago |
| CVE-2026-63916 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: Fix OOB write in wacom_hid_set_dev | 83d ago |
| CVE-2026-63915 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nfc: hci: fix out-of-bounds read in HCP header | 83d ago |
| CVE-2026-63885 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/gem: fix race between change_handle and ha | 83d ago |
| CVE-2026-63866 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Clear wcid pointer in mt79 | 83d ago |
| CVE-2026-63865 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Drop task_to_inode and inet_conn_establis | 83d ago |
| CVE-2026-63863 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: Fix unbalanced unlock in drm_gpusv | 83d ago |
| CVE-2026-63832 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: add wcid publish check in mt76_sta | 83d ago |
| CVE-2026-63831 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: add skb_cow_data() before in | 83d ago |
| CVE-2026-63829 | 8.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ip_gre: require CAP_NET_ADMIN in the devi | 83d ago |
| CVE-2026-63807 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot be | 83d ago |
| CVE-2026-63801 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aea | 83d ago |
| CVE-2026-63796 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descripto | 83d ago |
| CVE-2026-53375 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patche | 83d ago |
| CVE-2026-53374 | 8.8 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allo | 83d ago |
| CVE-2026-11826 | 8.8 | — | — | — | — | OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. | 84d ago |
| CVE-2025-71390 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames | 84d ago |
| CVE-2024-58362 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup o | 84d ago |
| CVE-2023-54366 | 8.8 | — | — | — | surrealdb / surrealdb | SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, an | 84d ago |
| CVE-2026-16097 | 8.8 | — | — | — | — | A vulnerability was found in Shibby Tomato 1.28. | 84d ago |
| CVE-2026-16096 | 8.8 | — | — | — | — | A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. | 84d ago |
| CVE-2026-16095 | 8.8 | — | — | — | — | A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. | 84d ago |
| CVE-2026-47871 | 8.8 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a directory traversal vulnerability. | 84d ago |
| CVE-2026-8056 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via th | 85d ago |
| CVE-2026-7755 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enfor | 85d ago |
| CVE-2026-7667 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an at | 85d ago |
| CVE-2026-50289 | 8.8 | — | — | — | systeminformation / systeminformation | systeminformation is a System and OS information library for node.js. | 85d ago |
| CVE-2026-14499 | 8.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands wit | 85d ago |
| CVE-2026-58195 | 8.8 | — | — | — | — | Agentic-Flow is an AI agent orchestration platform. | 85d ago |
| CVE-2026-60025 | 8.8 | — | — | — | — | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Boo | 85d ago |
| CVE-2026-63093 | 8.8 | — | — | — | anysphere / cursor | Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve | 85d ago |
| CVE-2026-13352 | 8.8 | — | — | — | — | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profi | 85d ago |
| CVE-2026-62238 | 8.8 | — | — | — | openremote / openremote | OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export end | 85d ago |
| CVE-2026-62233 | 8.8 | — | — | — | — | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa end | 85d ago |
| CVE-2026-62229 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allow | 85d ago |
| CVE-2026-62228 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-tr | 85d ago |
| CVE-2026-62223 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that a | 85d ago |
| CVE-2026-62218 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve featu | 85d ago |
| CVE-2026-62217 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. | 85d ago |
| CVE-2026-62207 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers t | 85d ago |
| CVE-2026-62203 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails | 85d ago |
| CVE-2026-62202 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that | 85d ago |
| CVE-2026-63085 | 8.8 | — | — | — | — | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authen | 86d ago |
| CVE-2025-45868 | 8.8 | — | — | — | — | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component | 86d ago |
| CVE-2026-5674 | 8.8 | — | — | — | — | A flaw was found in PipeWire, a multimedia server. | 86d ago |
| CVE-2026-15103 | 8.8 | — | — | — | — | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable | 86d ago |
| CVE-2026-15005 | 8.8 | — | — | — | — | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc | 86d ago |
| CVE-2026-13741 | 8.8 | — | — | — | — | The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in | 86d ago |
| CVE-2026-12525 | 8.8 | — | — | — | — | The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when savi | 86d ago |
| CVE-2026-62312 | 8.8 | — | — | — | — | 9Router is an AI router & token saver. | 87d ago |
| CVE-2026-49987 | 8.8 | — | — | — | yamadashy / repomix | Repomix is a tool that packs repositories into AI-friendly files. | 87d ago |
| CVE-2026-40501 | 8.8 | — | — | — | — | Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerabilit | 87d ago |
| CVE-2026-20150 | 8.8 | — | — | — | cisco / roomos | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team | 87d ago |