23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 5401-5450 of 23295 CVEs Page 109 of 466
CVE-2026-51266
Analyzed
9.8
Unknown ESP32-audioI2S

The schreibfaul1 ESP32-audioI2S 3.4.5 library contains a heap-based buffer overflow in its HTTP header construction logic due to insufficient size val...

2026-07-29
CVE-2026-51263
Analyzed
9.8
Unknown ESP32-audioI2S

The Audio::openai_speech function in schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to a heap buffer overflow due to improper validation of externall...

2026-07-29
CVE-2026-51259
Analyzed
9.8
GitHub ESP32-audioI2S

An integer overflow in the buffer size calculation for schreibfaul1 ESP32-audioI2S 3.4.5 results in heap memory corruption, enabling denial of service...

2026-07-29
CVE-2026-51252
Analyzed
9.8
GitHub ESP32-audioI2S

A buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote attackers to execute code...

2026-07-29
CVE-2026-51244
Analyzed
7.5
GitHub ESP32-audioI2S

schreibfaul1 ESP32-audioI2S 3

2026-08-15
CVE-2026-51235
Analyzed
8.8
GitHub LibRaw

LibRaw 0

2026-07-28
CVE-2026-51190
Analyzed
9.8
GitHub Serverless-Devs (s)

The Serverless-Devs command line tool is vulnerable to OS command injection via the s init command, which fails to sanitize user input before passing...

2026-08-27
CVE-2026-5118
Analyzed
9.8
WordPress Divi Form Builder

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated users to register as administrators.

2026-05-22
CVE-2026-51152
Analyzed
9.1
GitHub QD

An unauthenticated server-side request forgery (SSRF) vulnerability in the /har/test endpoint allows attackers to force the server to send arbitrary H...

2026-09-04
CVE-2026-5113
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2

2026-05-02
CVE-2026-5112
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-51119
Analyzed
9.1
Invixium IXM WEB

Invixium IXM WEB v.2.3.85.25 contains a privilege escalation vulnerability in the /SystemUsers/CreateAppUser component that allows unauthorized users...

2026-07-11
CVE-2026-5111
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5110
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5109
Analyzed
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-51080
Analyzed
9.8
Proxmox libpve-storage-perl

The Proxmox libpve-storage-perl library contains an XML External Entity (XXE) vulnerability that could lead to unauthorized data disclosure or service...

2026-07-18
CVE-2026-51078
Analyzed
7.5
HP Multiple Products

An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component

2026-08-23
CVE-2026-51077
Analyzed
7.5
HP Multiple Products

SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_q...

2026-08-22
CVE-2026-51031
Analyzed
7.5
FlareSolverr FlareSolverr

FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker t...

2026-07-27
CVE-2026-51027
Analyzed
9.9
HP FileThingie

FileThingie version 2.5.7 contains a vulnerability in the ft2.php component that allows a remote, authenticated attacker to obtain sensitive informati...

2026-07-21
CVE-2026-5100
Analyzed
7.5
WordPress is vulnerable

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4

2026-05-05
CVE-2026-50884
Analyzed
8.8
Statping-ng statping-ng

Incorrect access control in statping-ng v0

2026-06-17
CVE-2026-5087
Analyzed
7.5
Unknown Multiple Products

PAGI::Middleware::Session::Store::Cookie versions through 0

2026-04-02
CVE-2026-5085
Analyzed
9.1
Unknown Multiple Products

Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the...

2026-04-14
CVE-2026-5081
Analyzed
9.1
Apache mod

The Apache::Session::Generate::ModUniqueId module generates insecure session IDs using predictable environment variables, allowing for potential sessi...

2026-05-07
CVE-2026-50768
Analyzed
9.8
Unknown ImageMaster

T-Systems International GmbH ImageMaster version 9.14.2.8.1 contains a file upload vulnerability in the add attachments feature, allowing remote unaut...

2026-08-18
CVE-2026-5076
Analyzed
9.8
WordPress ARMember Premium Plugin

The ARMember Premium plugin for WordPress stores plaintext password reset keys, allowing unauthenticated attackers to reset user passwords and hijack...

2026-06-03
CVE-2026-50759
Analyzed
7.5
Unknown Multiple Products

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints wit...

2026-08-04
CVE-2026-50758
Analyzed
8.1
Unknown Multiple Products

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

2026-08-04
CVE-2026-50757
Analyzed
7.8
Unknown Multiple Products

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-s...

2026-08-04
CVE-2026-50756
Analyzed
7.5
Unknown Multiple Products

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

2026-08-04
CVE-2026-50755
Analyzed
9.8
Unknown Multiple Products

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

2026-07-31
CVE-2026-50751
KEV Analyzed
9.5
Check Point Security Gateway

Check Point Security Gateway is affected by an improper authentication vulnerability that is currently being exploited in the wild.

2026-06-09
CVE-2026-50748
Analyzed
9.9
Ubiquiti UniFi Access Application

Improper input validation in the UniFi Access Application allows low-privileged network attackers to perform command injection and execute arbitrary c...

2026-07-03
CVE-2026-50747
Analyzed
9.9
Ubiquiti UniFi Talk Application

Authenticated SQL injection vulnerabilities in the UniFi Talk Application allow low-privileged network attackers to escalate privileges on the host de...

2026-07-03
CVE-2026-50746
Analyzed
10
Ubiquiti UniFi Connect Application

An improper access control vulnerability in the UniFi Connect Application allows unauthenticated network attackers to execute arbitrary commands on th...

2026-07-03
CVE-2026-50741
Analyzed
8.8
Revive Adserver

Bypass to the fix for CVE-2026-34916

2026-06-26
CVE-2026-50733
Analyzed
8.8
Markdown Preview Enhanced Markdown Preview Enhanced

Markdown Preview Enhanced before 0

2026-06-07
CVE-2026-50692
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50687
Analyzed
8.8
Microsoft Windows

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50670
Analyzed
8.8
Microsoft Windows Kernel

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-5067
Analyzed
9.8
Zephyr HTTP Server

A memory corruption vulnerability in the Zephyr HTTP server WebSocket upgrade path allows unauthenticated remote attackers to trigger denial of servic...

2026-06-09
CVE-2026-50666
Analyzed
8.8
Microsoft Windows

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-50663
Analyzed
8.8
Microsoft Age of Empires II: Definitive Edition Game

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-5065
Analyzed
8.8
IBM Controller

IBM Controller 11

2026-05-28
CVE-2026-50644
Analyzed
8.6
SOPlanning SOPlanning

SOPlanning is vulnerable to SQL injection in the audit retention configuration

2026-07-10
CVE-2026-50637
Analyzed
8.2
CPAN (Metrics::Any) Metrics::Any::Adapter::Statsd

Metrics::Any::Adapter::Statsd versions before 0

2026-06-12
CVE-2026-50636
Analyzed
8.8
Oracle Multiple Products

The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), wh...

2026-06-10
CVE-2026-50635
Analyzed
8.8
LimeSurvey LimeSurvey

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it

2026-06-10
CVE-2026-50633
Analyzed
8.1
Apache CXF

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able...

2026-06-14