20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 5301-5350 of 20297 CVEs Page 107 of 406
CVE-2026-40750
Analyzed
9.9
Unknown Kids Online Store

An unrestricted file upload vulnerability in themagnifico52 Kids Online Store allows attackers to upload and execute a web shell.

2026-06-17
CVE-2026-40745
7.6
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes-...

2026-04-17
CVE-2026-40744
8.5
Beaver Builder Beaver Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lit...

2026-04-17
CVE-2026-40711
Analyzed
8
Dell Container Storage Modules (CSI PowerStore)

Dell Dell Container Storage Modules, version(s) csi-powerstore v2

2026-06-27
CVE-2026-40706
8.4
Unknown Multiple Products

In NTFS-3G 2022

2026-04-22
CVE-2026-40702
Analyzed
9.4
EVoke EVoke CSMS

The EVoke CSMS platform contains a critical vulnerability where WebSocket endpoints lack authentication, allowing attackers to impersonate charging st...

2026-06-26
CVE-2026-40698
Analyzed
8.7
Unknown Multiple Products

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role ca...

2026-05-14
CVE-2026-4064
8.3
Universal Multiple Products

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026

2026-03-18
CVE-2026-40636
Analyzed
9.8
Dell ECS versions

Dell ECS and ObjectScale contain a hard-coded credentials vulnerability, enabling local attackers to gain unauthorized filesystem access.

2026-05-12
CVE-2026-40631
Analyzed
8.7
Unknown Multiple Products

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in pr...

2026-05-14
CVE-2026-40630
Analyzed
9.8
SenseLive X3050 Multiple Products

A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access...

2026-04-24
CVE-2026-40624
Analyzed
9.8
AVer PTC500S, PTC115, PTC500+, and PTC115+ Cameras

Improper input validation in AVer PTC series cameras allows remote, unauthenticated attackers to execute arbitrary code via crafted web requests.

2026-06-20
CVE-2026-40623
8.1
SenseLive Multiple Products

A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without suffi...

2026-04-24
CVE-2026-40621
Analyzed
9.8
ELECOM Wireless LAN Access Point

Certain ELECOM wireless LAN access points contain an authentication bypass vulnerability, allowing unauthenticated access to specific web URLs.

2026-05-14
CVE-2026-40620
Analyzed
9.8
SenseLive X3050 Multiple Products

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authenticati...

2026-04-24
CVE-2026-4062
7.5
WordPress is vulnerable

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions...

2026-05-03
CVE-2026-40613
7.5
STUN Multiple Products

Coturn is a free open source implementation of TURN and STUN Server

2026-04-22
CVE-2026-40611
8.8
Encrypt Multiple Products

Let's Encrypt client and ACME library written in Go (Lego)

2026-04-22
CVE-2026-4061
7.5
WordPress is vulnerable

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including,...

2026-05-03
CVE-2026-40601
Analyzed
7.5
Chartbrew Chartbrew

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

2026-05-01
CVE-2026-40600
Analyzed
8.1
Chartbrew Chartbrew

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

2026-05-01
CVE-2026-4060
7.5
WordPress is vulnerable

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1

2026-05-03
CVE-2026-40595
Analyzed
7.5
Intel Chartbrew

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

2026-05-01
CVE-2026-40589
7.6
Unknown Multiple Products

FreeScout is a free self-hosted help desk and shared mailbox

2026-04-22
CVE-2026-40588
8.1
Unreal Multiple Products

blueprintUE is a tool to help Unreal Engine developers

2026-04-22
CVE-2026-40586
7.5
Unreal Multiple Products

blueprintUE is a tool to help Unreal Engine developers

2026-04-22
CVE-2026-40581
8.1
HP Multiple Products

ChurchCRM is an open-source church management system

2026-04-18
CVE-2026-40576
Analyzed
9.4
AWS excel-mcp-server

A path traversal vulnerability in excel-mcp-server allows unauthenticated remote attackers to read, write, and overwrite arbitrary files on the host f...

2026-04-22
CVE-2026-40575
Analyzed
9.1
Nginx and not

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forw...

2026-04-22
CVE-2026-40572
Analyzed
9
Unknown Multiple Products

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user...

2026-04-18
CVE-2026-40569
Analyzed
9
HP Multiple Products

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection...

2026-04-22
CVE-2026-40568
8.5
HP Multiple Products

FreeScout is a free self-hosted help desk and shared mailbox

2026-04-22
CVE-2026-40563
7.1
Apache endpoint that

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that a...

2026-05-05
CVE-2026-40560
7.5
Unknown Multiple Products

Starman versions before 0

2026-04-30
CVE-2026-40527
7.8
Unknown Multiple Products

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicio...

2026-04-18
CVE-2026-40525
Analyzed
9.1
OpenViking Multiple Products

OpenViking prior to commit c7bb167 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authenticatio...

2026-04-18
CVE-2026-40524
Analyzed
8.1
FrontAccounting FrontAccounting

FrontAccounting before 2

2026-06-30
CVE-2026-40523
Analyzed
8.1
FrontAccounting FrontAccounting

FrontAccounting before 2

2026-06-30
CVE-2026-40522
Analyzed
7.1
FrontAccounting FrontAccounting

FrontAccounting before 2

2026-06-30
CVE-2026-40521
Analyzed
8.8
FrontAccounting FrontAccounting

FrontAccounting before 2

2026-06-30
CVE-2026-40518
7.1
Unknown Multiple Products

ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation wher...

2026-04-18
CVE-2026-40517
7.8
Unknown Multiple Products

radare2 prior to 6

2026-04-23
CVE-2026-40516
8.3
Arch tools that

OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to...

2026-04-18
CVE-2026-40515
7.5
OpenHarness Multiple Products

OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete pa...

2026-04-18
CVE-2026-40504
Analyzed
9.8
Creolabs Gravity Multiple Products

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-boun...

2026-04-16
CVE-2026-40502
8.8
Unknown Multiple Products

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive a...

2026-04-16
CVE-2026-40501
Analyzed
8.8
CherryHQ cherry-studio

Cherry Studio versions 1

2026-07-16
CVE-2026-40497
8.1
F5 Multiple Products

FreeScout is a free self-hosted help desk and shared mailbox

2026-04-21
CVE-2026-40494
Analyzed
9.8
Unknown Multiple Products

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d7...

2026-04-18
CVE-2026-40493
Analyzed
9.8
Unknown Multiple Products

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff...

2026-04-18