23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 5351-5400 of 23391 CVEs Page 108 of 468
CVE-2026-52469
Analyzed
9.8
Crocus Crocus

An SQL injection vulnerability in the Crocus DeviceInfoMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and...

2026-07-31
CVE-2026-52466
Analyzed
9.8
Open Library Foundation VuFind

Open Library Foundation VuFind v11.0.3 and v4.1 suffer from an incorrect access control vulnerability where requests continue processing despite faile...

2026-08-06
CVE-2026-52439
Analyzed
9.8
Unknown Multiple Products

An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism

2026-08-03
CVE-2026-5242
Analyzed
8.8
MIA Technology MIA Technology Inc (Software)

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc

2026-06-16
CVE-2026-5238
Analyzed
7.3
HP of the

A weakness has been identified in itsourcecode Payroll Management System 1

2026-04-01
CVE-2026-5237
Analyzed
7.3
HP of the

A security flaw has been discovered in itsourcecode Payroll Management System 1

2026-04-01
CVE-2026-52349
Analyzed
7.8
Menyoo MenyooSP

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary c...

2026-07-29
CVE-2026-52348
Analyzed
9.8
Unknown cool-admin-java

A SQL injection vulnerability in the order() method of CrudOption.java within cool-admin-java 8.0.0 allows unauthenticated attackers to compromise the...

2026-07-22
CVE-2026-5231
Analyzed
7.2
WordPress is vulnerable

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and includin...

2026-04-18
CVE-2026-5229
Analyzed
9.8
WordPress is vulnerable

The Form Notify plugin for WordPress suffers from an authentication bypass vulnerability due to improper verification of user-controlled cookie data d...

2026-05-15
CVE-2026-5228
Analyzed
8.8
Kurt Software Studio WriteUp Mobile App

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Co...

2026-06-05
CVE-2026-52203
Analyzed
7.5
MCMS MCMS

An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.

2026-07-22
CVE-2026-52199
Analyzed
9.1
Unknown Multiple Products

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

2026-07-23
CVE-2026-5219
Analyzed
8.3
Unknown E-Commerce Pack

Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd

2026-07-31
CVE-2026-5217
Analyzed
7.2
WordPress is vulnerable

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Sc...

2026-04-12
CVE-2026-5214
Analyzed
8.8
D-Link DNS

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L,...

2026-04-01
CVE-2026-52134
Analyzed
9.8
GitHub libiec61850

The libiec61850 library contains an authentication bypass vulnerability in the parseGoosePayload function that allows unauthenticated attackers to man...

2026-08-27
CVE-2026-52131
Analyzed
7.5
GitHub llama.cpp

llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.

2026-09-05
CVE-2026-5213
Analyzed
8.8
D-Link DNS

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-...

2026-04-01
CVE-2026-5212
Analyzed
8.8
D-Link DNS

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-...

2026-04-01
CVE-2026-5211
Analyzed
8.8
D-Link DNS

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR...

2026-04-01
CVE-2026-52102
Analyzed
9.8
OpenMediaVault openmediavault-md

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows unauthenticated attackers to execute arbitrary...

2026-08-27
CVE-2026-52101
Analyzed
9.1
Linux Multiple Products

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote func...

2026-07-20
CVE-2026-52100
Analyzed
7.5
Linux Multiple Products

Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the...

2026-07-20
CVE-2026-5210
Analyzed
7.3
Unknown Multiple Products

A vulnerability was detected in SourceCodester Leave Application System 1

2026-04-01
CVE-2026-5208
Analyzed
8.2
Unknown Multiple Products

Command injection in alerts in CoolerControl/coolercontrold <4

2026-04-09
CVE-2026-5204
Analyzed
8.8
Tenda CH22

A vulnerability was determined in Tenda CH22 1

2026-04-01
CVE-2026-5201
Analyzed
7.5
Unknown Multiple Products

A flaw was found in the gdk-pixbuf library

2026-04-01
CVE-2026-5200
Analyzed
8.8
WordPress plugin for

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authoriza...

2026-05-20
CVE-2026-5198
Analyzed
7.3
HP of the

A vulnerability was determined in code-projects Student Membership System 1

2026-04-01
CVE-2026-51977
Analyzed
9.1
GitHub T18061 WiFi 3MP Robot Pan-Tilt Security Camera

A privilege escalation vulnerability in Trueview T18061 WiFi 3MP security cameras allows physically proximate attackers to compromise the device via a...

2026-08-26
CVE-2026-51974
Analyzed
8.8
Unknown Fooocus

An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attacke...

2026-09-05
CVE-2026-5195
Analyzed
7.3
Membership Multiple Products

A flaw has been found in code-projects Student Membership System 1

2026-04-01
CVE-2026-51937
Analyzed
7.5
SAP Oneblog

An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the...

2026-07-11
CVE-2026-51926
Analyzed
7.5
HP FSM Client

An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability wa...

2026-07-15
CVE-2026-51925
Analyzed
8.1
HP Multiple Products

A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm...

2026-07-15
CVE-2026-51924
Analyzed
8.1
HP Multiple Products

An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component

2026-07-15
CVE-2026-51923
Analyzed
8.1
Unknown Client

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code...

2026-07-15
CVE-2026-5192
Analyzed
7.5
WordPress is vulnerable

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and in...

2026-05-05
CVE-2026-5190
Analyzed
7.5
Unknown Multiple Products

Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0

2026-04-01
CVE-2026-51833
Analyzed
7.5
Unknown Multiple Products

Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (p...

2026-07-23
CVE-2026-51821
Analyzed
9.8
GitHub Video Conference System

A SQL injection vulnerability in the /user/getUserLogin endpoint of Shenzhou Shihan Video Conference System v.1.0 allows unauthenticated remote attack...

2026-07-17
CVE-2026-5182
Analyzed
7.3
Record Multiple Products

A vulnerability was found in SourceCodester Teacher Record System 1

2026-03-31
CVE-2026-51808
Analyzed
9.8
OpenHTJ2K OpenHTJ2K

A buffer overflow vulnerability in OpenHTJ2K allows remote attackers to execute arbitrary code via multiple decoder functions.

2026-07-18
CVE-2026-51807
Analyzed
9.8
OpenHTJ2K OpenHTJ2K

A buffer overflow vulnerability in OpenHTJ2K up to version 0.18.4 allows unauthenticated attackers to execute arbitrary code via a malicious JPEG 2000...

2026-07-19
CVE-2026-5180
Analyzed
7.3
HP Multiple Products

A flaw has been found in SourceCodester Simple Doctors Appointment System 1

2026-03-31
CVE-2026-5179
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1

2026-03-31
CVE-2026-51775
Analyzed
9.8
HP Fastadmin

A SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows unauthenticated attackers to execute arbitrary code via the Backend.php component.

2026-08-27
CVE-2026-51768
Analyzed
7.5
TOTOLINK T6

Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged...

2026-09-05
CVE-2026-51764
Analyzed
9.8
TOTOLINK T6

An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to overwrite cloud-result tracking files v...

2026-09-05