21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 5051-5100 of 21637 CVEs Page 102 of 433
CVE-2026-45689
Analyzed
9.1
Rocket.Chat Rocket.Chat

An unauthenticated attacker can inject MongoDB operators into the OAuth token endpoint to steal valid access tokens for arbitrary users, including adm...

2026-06-25
CVE-2026-45688
Analyzed
9.1
Rocket.Chat Rocket.Chat

An unauthenticated attacker can use NoSQL injection in the CAS login handler to bypass authentication and hijack active user sessions, including admin...

2026-06-25
CVE-2026-45687
Analyzed
8.5
Rocket.Chat Rocket.Chat

Rocket

2026-06-25
CVE-2026-45677
Analyzed
8.7
Rocket.Chat Rocket.Chat

Rocket

2026-06-25
CVE-2026-45675
Analyzed
8.1
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45674
Analyzed
8.7
Netty Netty

Netty is a network application framework for development of protocol servers and clients

2026-06-13
CVE-2026-45672
Analyzed
8.8
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45671
Analyzed
8
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-4567
Analyzed
9.8
Tenda A15

A stack-based buffer overflow in the Tenda A15 UploadCfg function allows remote attackers to execute arbitrary code via a malicious File argument.

2026-03-23
CVE-2026-45665
Analyzed
8.1
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45663
Analyzed
9.9
Docker PaaS

Dokploy contains a command injection vulnerability in its Docker file upload functionality that allows authenticated users to execute arbitrary OS com...

2026-05-30
CVE-2026-45662
Analyzed
8.8
Docker logout

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-05-30
CVE-2026-45661
Analyzed
9.9
Dokploy PaaS

A path traversal vulnerability in Dokploy allows authenticated users to write arbitrary files to the host or remote servers during application deploym...

2026-05-30
CVE-2026-4566
Analyzed
8.8
Belkin F9K1122

A flaw has been found in Belkin F9K1122 1

2026-03-23
CVE-2026-45659
KEV Analyzed
8.8
Microsoft Office SharePoint

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-05-27
CVE-2026-45657
Analyzed
9.8
Microsoft Windows Kernel

A use-after-free vulnerability in the Windows Kernel allows unauthenticated attackers to execute arbitrary code over the network.

2026-06-10
CVE-2026-4565
8.8
Tenda AC21

A vulnerability was detected in Tenda AC21 16

2026-03-23
CVE-2026-45648
Analyzed
8.8
Microsoft Active Directory Domain Services

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network

2026-06-10
CVE-2026-45641
Analyzed
8.4
Microsoft Windows Hyper-V

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally

2026-06-12
CVE-2026-45633
Analyzed
9.9
Docker PaaS

Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint that allows authenticated users to execute arbitra...

2026-05-30
CVE-2026-45632
Analyzed
9.9
Dokploy PaaS

A broken access control vulnerability in the Dokploy schedule router allows authenticated users to manage schedules belonging to other organizations,...

2026-05-30
CVE-2026-45631
Analyzed
10
Dokploy PaaS

A hardcoded authentication secret in Dokploy allows unauthenticated attackers to forge JWTs, gain administrative access, and execute commands on the h...

2026-05-30
CVE-2026-45629
Analyzed
9.9
Dokploy PaaS

An OS command injection vulnerability in the Dokploy /listen-deployment WebSocket endpoint allows authenticated users to execute arbitrary commands on...

2026-05-30
CVE-2026-45625
Analyzed
9.9
Arcane Docker Container Management Interface

Arcane's REST API fails to enforce admin-level authorization on Git repository management endpoints, allowing authenticated users to exfiltrate sensit...

2026-05-30
CVE-2026-45623
Analyzed
7.5
PostCSS PostCSS

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree

2026-07-28
CVE-2026-4562
7.3
HP of the

A security flaw has been discovered in MacCMS 2025

2026-03-23
CVE-2026-45618
Analyzed
10
Unknown liquidjs

LiquidJS versions prior to 10.26.0 are vulnerable to code injection, allowing unauthenticated attackers to execute arbitrary code via crafted template...

2026-08-12
CVE-2026-45607
Analyzed
8.4
Microsoft Windows Hyper-V

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally

2026-06-12
CVE-2026-45584
Analyzed
8.1
Microsoft Defender allows

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network

2026-05-21
CVE-2026-4558
8.8
Linksys MR9600

A flaw has been found in Linksys MR9600 2

2026-03-23
CVE-2026-45578
Analyzed
8.8
HP builds an

WWBN AVideo is an open source video platform

2026-05-30
CVE-2026-45576
Analyzed
8.3
Unknown zrok

zrok is software for sharing web services, files, and network resources

2026-07-17
CVE-2026-45568
Analyzed
9.9
Unknown zrok

The zrok Python SDK proxy route is vulnerable to a server-side request forgery flaw, allowing attackers to force the proxy to return responses from ar...

2026-07-17
CVE-2026-45567
Analyzed
8.3
Apache Roxy-WI

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers

2026-06-12
CVE-2026-45564
Analyzed
8.8
Apache Roxy-WI

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers

2026-06-11
CVE-2026-45558
Analyzed
9.9
Roxy-WI Roxy-WI (Management Interface for Haproxy, Nginx, Apache, Keepalived)

Roxy-WI 8.2.6.4 and prior allows authenticated users to inject arbitrary HAProxy directives, leading to remote code execution on load balancers.

2026-06-11
CVE-2026-45556
Analyzed
9.9
GitHub Roxy-WI

Roxy-WI contains an authenticated arbitrary file write vulnerability in its WAF rule saving functionality, allowing for Remote Code Execution on manag...

2026-06-11
CVE-2026-45552
Analyzed
9.9
Roxy-WI Roxy-WI (Management Interface for Haproxy, Nginx, Apache, Keepalived)

Roxy-WI 8.2.6.4 and prior contains an authentication bypass vulnerability where multiple administrative endpoints lack proper role and group checks.

2026-06-11
CVE-2026-4555
8.8
D-Link DIR

A weakness has been identified in D-Link DIR-513 1

2026-03-23
CVE-2026-45549
Analyzed
8.5
Apache Roxy-WI

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers

2026-06-11
CVE-2026-45539
Analyzed
7.4
Microsoft APM is

Microsoft APM is an open-source, community-driven dependency manager for AI agents

2026-05-17
CVE-2026-45538
Analyzed
9.8
OpenSIPS opensips

OpenSIPS contains a stack-based buffer overflow vulnerability in the sip_to_json() function, allowing unauthenticated remote attackers to cause a cras...

2026-08-05
CVE-2026-45535
Analyzed
8.7
DataEase DataEase

DataEase is an open source data visualization and analysis tool

2026-07-16
CVE-2026-45533
Analyzed
8.3
Unknown dataease

DataEase is an open source data visualization and analysis tool

2026-07-17
CVE-2026-4553
8.8
Tenda F453

A vulnerability was identified in Tenda F453 1

2026-03-23
CVE-2026-4552
8.8
Tenda F453

A vulnerability was determined in Tenda F453 1

2026-03-23
CVE-2026-4551
8.8
Tenda F453

A vulnerability was found in Tenda F453 1

2026-03-23
CVE-2026-45505
Analyzed
8.8
Apache ActiveMQ

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apa...

2026-06-02
CVE-2026-45504
Analyzed
8.8
Microsoft Exchange Server

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network

2026-06-10
CVE-2026-45503
Analyzed
8.1
Microsoft Exchange Server

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network

2026-06-16