| CVE-2026-55242 | 8.8 | — | — | — | — | ERPNext is a free and open source Enterprise Resource Planning tool. | 87d ago |
| CVE-2026-45805 | 8.8 | — | — | — | — | Penpot is an open-source design tool for design and code collaboration. | 87d ago |
| CVE-2026-61457 | 8.8 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API medi | 87d ago |
| CVE-2026-58655 | 8.8 | — | — | — | — | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side | 87d ago |
| CVE-2026-57996 | 8.8 | — | — | — | — | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-S | 87d ago |
| CVE-2026-35152 | 8.8 | — | — | — | apache / fineract | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions u | 87d ago |
| CVE-2026-15804 | 8.8 | — | — | — | — | The HCM developed by MetaGuru has a SQL Injection vulnerability. | 87d ago |
| CVE-2026-59733 | 8.8 | — | — | — | rclone / rclone | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. | 87d ago |
| CVE-2026-50130 | 8.8 | — | — | — | pi-hole / pi-hole | Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. | 87d ago |
| CVE-2026-46640 | 8.8 | — | — | — | symfony / twig | Twig is a template language for PHP. | 87d ago |
| CVE-2026-15776 | 8.8 | — | — | — | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute a | 88d ago |
| CVE-2026-15767 | 8.8 | — | — | — | google / chrome | Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to ex | 88d ago |
| CVE-2026-47303 | 8.8 | — | — | — | microsoft / .net | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privilege | 88d ago |
| CVE-2026-47301 | 8.8 | — | — | — | microsoft / configuration manager 2503 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges ove | 88d ago |
| CVE-2026-47300 | 8.8 | — | — | — | microsoft / .net | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate priv | 88d ago |
| CVE-2026-58626 | 8.8 | — | — | — | microsoft / windows 10 21h2 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 88d ago |
| CVE-2026-58594 | 8.8 | — | — | — | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-58534 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privile | 88d ago |
| CVE-2026-58277 | 8.8 | — | — | — | microsoft / sharepoint server | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a n | 88d ago |
| CVE-2026-57102 | 8.8 | — | — | — | microsoft / visual studio code | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to | 88d ago |
| CVE-2026-57094 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 88d ago |
| CVE-2026-57090 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 88d ago |
| CVE-2026-57087 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 88d ago |
| CVE-2026-56647 | 8.8 | — | — | — | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to el | 88d ago |
| CVE-2026-56642 | 8.8 | — | — | — | microsoft / fabric data warehouse | Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over | 88d ago |
| CVE-2026-56197 | 8.8 | — | — | — | microsoft / windows admin center | Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows | 88d ago |
| CVE-2026-56196 | 8.8 | — | — | — | microsoft / windows admin center | Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | 88d ago |
| CVE-2026-56194 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over | 88d ago |
| CVE-2026-55052 | 8.8 | — | — | — | microsoft / sharepoint server | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a ne | 88d ago |
| CVE-2026-54121 | 8.8 | — | — | — | microsoft / windows 10 1607 | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate p | 88d ago |
| CVE-2026-50692 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-50687 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-50670 | 8.8 | — | — | — | microsoft / windows 10 1809 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-50666 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ove | 88d ago |
| CVE-2026-50489 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-50477 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-50474 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-50444 | 8.8 | — | — | — | microsoft / windows 10 1607 | Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to ele | 88d ago |
| CVE-2026-50438 | 8.8 | — | — | — | microsoft / pc manager | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attack | 88d ago |
| CVE-2026-50413 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-50398 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allow | 88d ago |
| CVE-2026-50385 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 88d ago |
| CVE-2026-50382 | 8.8 | — | — | — | microsoft / windows 10 1809 | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | 88d ago |
| CVE-2026-50370 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent | 88d ago |
| CVE-2026-50369 | 8.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a netwo | 88d ago |
| CVE-2026-50360 | 8.8 | — | — | — | microsoft / windows 10 21h2 | Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevat | 88d ago |
| CVE-2026-47295 | 8.8 | — | — | — | microsoft / sql server 2016 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an autho | 88d ago |
| CVE-2026-58608 | 8.8 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spool | 88d ago |
| CVE-2026-57969 | 8.8 | — | — | — | microsoft / azure cyclecloud | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileg | 88d ago |
| CVE-2026-55005 | 8.8 | — | — | — | microsoft / exchange server | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a netwo | 88d ago |
| CVE-2026-55002 | 8.8 | — | — | — | microsoft / sql server 2016 | External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a net | 88d ago |
| CVE-2026-54999 | 8.8 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allo | 88d ago |
| CVE-2026-54982 | 8.8 | — | — | — | microsoft / windows 10 1607 | Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized atta | 88d ago |
| CVE-2026-54107 | 8.8 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allo | 88d ago |
| CVE-2026-50663 | 8.8 | — | — | — | microsoft / age of empires ii | Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute c | 88d ago |
| CVE-2026-50342 | 8.8 | — | — | — | microsoft / windows 11 24h2 | Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally | 88d ago |
| CVE-2026-49795 | 8.8 | — | — | — | microsoft / windows 10 1809 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-49178 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over | 88d ago |
| CVE-2026-48564 | 8.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | 88d ago |
| CVE-2026-47632 | 8.8 | — | — | — | microsoft / azure connected machine agent | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privil | 88d ago |