23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 4951-5000 of 23295 CVEs Page 100 of 466
CVE-2026-54588
Analyzed
9.6
Unknown poweradmin

Poweradmin fails to validate the HTTP_HOST header, allowing unauthenticated attackers to poison redirect URIs and hijack user authentication tokens, l...

2026-06-24
CVE-2026-54574
Analyzed
8.2
Termux proot-distro

proot-distro is a utility for managing proot containers

2026-07-30
CVE-2026-54569
Analyzed
9.8
SENAITE senaite.core

SENAITE.CORE versions 2.0.0 to 2.6.0 are vulnerable to unauthenticated remote code execution via a two-request chain involving missing authorization a...

2026-08-27
CVE-2026-54556
Analyzed
8.2
HP http4s

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of ser...

2026-08-28
CVE-2026-54555
Analyzed
7.8
RTK-AI RTK

rtk filters and compresses command outputs before they reach your LLM context

2026-06-24
CVE-2026-54540
Analyzed
8.8
HP Pheditor

Pheditor is a single-file editor and file manager written in PHP

2026-07-28
CVE-2026-54527
Analyzed
9.3
JupyterLab jupyterlab-git

JupyterLab Git is vulnerable to stored Cross-site Scripting (XSS) via crafted filenames, allowing JavaScript execution when a victim views the rename...

2026-07-09
CVE-2026-54526
Analyzed
8.9
Kubernetes Argo Workflows

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

2026-07-17
CVE-2026-54513
Analyzed
8.1
FasterXML jackson-databind

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor

2026-06-24
CVE-2026-54512
Analyzed
8.1
FasterXML jackson-databind

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor

2026-06-24
CVE-2026-54511
Analyzed
8.6
Unknown logtape

LogTape is an unobtrusive logging library

2026-08-27
CVE-2026-54498
Analyzed
8.7
ViewComponent view_component

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails

2026-07-18
CVE-2026-54496
Analyzed
9.3
ZcashFoundation zebra

A critical flaw in the variable-base scalar multiplication gadget within Zcash-related components allows an attacker to produce valid proofs for Orcha...

2026-07-18
CVE-2026-54469
Analyzed
8.8
Dell Unisphere for PowerMax

Dell Unisphere for PowerMax, version(s) 10

2026-07-11
CVE-2026-54466
Analyzed
9.2
Unknown websocket-driver-node

A vulnerability in the websocket-driver-node frame parsing logic allows remote attackers to cause integer overflows and payload misinterpretation by s...

2026-07-18
CVE-2026-54458
Analyzed
9.6
WWBN AVideo

A stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin of AVideo allows unauthenticated attackers to hijack administrative sessions v...

2026-07-16
CVE-2026-54457
Analyzed
7.7
TensorZero tensorzero

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation

2026-08-23
CVE-2026-54449
Analyzed
8.8
Unknown LangBot

LangBot is a global IM bot platform designed for LLMs

2026-08-21
CVE-2026-54424
Analyzed
8.4
Microsoft Parsec

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege

2026-07-04
CVE-2026-54423
Analyzed
8.2
OpenStack Ironic

In OpenStack Ironic before 37

2026-07-10
CVE-2026-54420
KEV Analyzed
8.5
Linux cPanel plugin

LiteSpeed cPanel plugin before 2

2026-06-14
CVE-2026-54418
Analyzed
8.1
GitHub Leantime

Leantime through 3

2026-08-05
CVE-2026-54414
Analyzed
9.8
HP FileRise

FileRise is vulnerable to path traversal via the shared-folder upload endpoint, allowing an attacker with a valid upload link to overwrite system file...

2026-06-20
CVE-2026-54413
Analyzed
8.2
Unknown iso14229

driftregion iso14229 through 0

2026-06-15
CVE-2026-54412
Analyzed
8.2
LiamBindle MQTT-C

LiamBindle MQTT-C through version 1

2026-06-15
CVE-2026-54410
Analyzed
8.6
Unknown nanoMODBUS

nanoMODBUS through v1

2026-06-15
CVE-2026-54408
Analyzed
8.6
Ubiquiti UniFi Protect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authe...

2026-07-03
CVE-2026-54407
Analyzed
8.6
Ubiquiti UniFi Protect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authe...

2026-07-03
CVE-2026-54406
Analyzed
8.7
Ubiquiti UniFi Network Application

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi...

2026-07-03
CVE-2026-54404
Analyzed
8.8
Ubiquiti UniFi OS Server

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi O...

2026-07-03
CVE-2026-54403
Analyzed
8.6
Ubiquiti UniFi OS Server

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authenti...

2026-07-03
CVE-2026-54402
Analyzed
9.9
Ubiquiti UniFi OS Server

An improper input validation vulnerability in the Ubiquiti UniFi OS Server allows authenticated low-privilege network users to execute arbitrary comma...

2026-07-03
CVE-2026-54400
Analyzed
9.1
Ubiquiti UniFi Access Application

An Improper Access Control vulnerability in the Ubiquiti UniFi Access Application allows an authenticated attacker with high privileges to escalate th...

2026-07-03
CVE-2026-54371
Analyzed
7.1
N/A (Project: attr) attr

attr before version 2

2026-06-30
CVE-2026-54369
Analyzed
7.1
ACL ACL

acl before version 2

2026-06-30
CVE-2026-54368
Analyzed
8.8
Gladinet CentreStack

CentreStack before 17

2026-07-31
CVE-2026-54367
Analyzed
8.6
Gladinet CentreStack

CentreStack before 17

2026-07-31
CVE-2026-5436
Analyzed
8.1
WordPress is vulnerable

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5

2026-04-09
CVE-2026-54353
Analyzed
8.5
Budibase Budibase

Budibase is an open-source low-code platform

2026-06-27
CVE-2026-54352
Analyzed
9.6
Budibase Budibase

An improper path validation vulnerability in the Budibase PWA upload process allows authenticated builders to perform arbitrary file reads on the serv...

2026-06-27
CVE-2026-54351
Analyzed
8.2
Budibase Budibase

Budibase is an open-source low-code platform

2026-06-27
CVE-2026-54350
Analyzed
10
Budibase Budibase

An unauthenticated injection vulnerability in Budibase allows remote attackers to read or modify arbitrary documents in connected databases via malici...

2026-06-27
CVE-2026-5435
Analyzed
7.3
Library Multiple Products

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2

2026-04-30
CVE-2026-54342
Analyzed
8.1
Unknown epa4all

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can pr...

2026-07-25
CVE-2026-54341
Analyzed
7.5
DragonflyDB Dragonfly

Dragonfly is an in-memory data store built for modern application workloads

2026-06-28
CVE-2026-54330
Analyzed
8.1
Ceph Ceph Object Gateway (RGW)

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object...

2026-08-28
CVE-2026-5433
Analyzed
9.1
Honeywell Control Network Module

A command injection vulnerability in the Honeywell Control Network Module web interface allows unauthenticated remote code execution via command delim...

2026-05-22
CVE-2026-54329
Analyzed
8.5
Grokability Snipe-IT

Snipe-IT is an IT asset/license management system

2026-07-11
CVE-2026-54322
Analyzed
7.7
Daytona Daytona

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows

2026-06-24
CVE-2026-54320
Analyzed
8.4
Daytona Daytona

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows

2026-06-24