23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 5451-5500 of 23295 CVEs Page 110 of 466
CVE-2026-50632
Analyzed
8.1
Apache CXF

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whic...

2026-06-14
CVE-2026-5063
Analyzed
7.2
WordPress plugin for

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in...

2026-05-04
CVE-2026-50622
Analyzed
8.8
Apache Apache Atlas

Description: Missing Authorization in Apache Atlas

2026-07-30
CVE-2026-50602
Analyzed
8.5
Acer Planet9 background service

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 ba...

2026-08-17
CVE-2026-5059
Analyzed
9.8
AWS CLI Command

The aws-mcp-server is vulnerable to remote code execution via AWS CLI command injection, allowing attackers to execute arbitrary system commands witho...

2026-04-11
CVE-2026-5058
Analyzed
9.8
AWS aws-mcp-server

The aws-mcp-server is vulnerable to remote code execution via command injection due to improper validation of user-supplied input in the allowed comma...

2026-04-11
CVE-2026-50574
Analyzed
8.3
Unknown yt-dlp

yt-dlp is a command-line audio/video downloader

2026-06-24
CVE-2026-50570
Analyzed
8.5
Kubernetes Fission

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes

2026-06-12
CVE-2026-50566
Analyzed
9.9
Kubernetes Fission Framework

An RBAC flaw in Fission allows tenants to run privileged containers under high-privilege service accounts, enabling container-sandbox escape and clust...

2026-06-11
CVE-2026-50564
Analyzed
9.9
Kubernetes Fission (Kubernetes Framework)

Fission prior to 1.24.0 contains a vulnerability in its Environment CRD that allows for privilege escalation by propagating insecure podspec fields wi...

2026-06-11
CVE-2026-50563
Analyzed
9.9
Kubernetes Fission Framework

A privilege management flaw in Fission’s Container Executor allows tenants to supply arbitrary pod specifications, creating potential for unauthorized...

2026-06-11
CVE-2026-50556
Analyzed
8.6
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-50555
Analyzed
8.6
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-50551
Analyzed
9.9
SiYuan SiYuan

A stored cross-site scripting (XSS) vulnerability in the SiYuan Attribute View allows for remote code execution (RCE) within the Electron desktop clie...

2026-06-25
CVE-2026-5055
Analyzed
7.8
Arch Path Element

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

2026-04-11
CVE-2026-50549
Analyzed
9.3
Intel Cursor

A path canonicalization flaw in the Cursor AI code editor allows malicious agents to bypass sandbox restrictions and write arbitrary files, facilitati...

2026-06-26
CVE-2026-50548
Analyzed
9.3
Cursor Cursor

A sandbox escape vulnerability in the Cursor AI code editor allows malicious agents to write arbitrary files outside the workspace, leading to non-san...

2026-06-26
CVE-2026-50545
Analyzed
9.9
Kubernetes Fission Framework

A validation flaw in Fission’s pod specification handling allows for the propagation of dangerous fields, leading to unauthorized control over generat...

2026-06-11
CVE-2026-5054
Analyzed
7.8
Unknown Multiple Products

NoMachine External Control of File Path Local Privilege Escalation Vulnerability

2026-04-11
CVE-2026-50538
Analyzed
8.8
LibVNC libvncserver

LibVNCClient is a library for easy implementation of a VNC client

2026-08-22
CVE-2026-5053
Analyzed
7.1
Unknown Multiple Products

NoMachine External Control of File Path Arbitrary File Deletion Vulnerability

2026-04-12
CVE-2026-50529
Analyzed
8.7
Intel DataEase

DataEase is an open source data visualization and analysis tool

2026-07-08
CVE-2026-50523
Analyzed
7.8
Microsoft PowerShell

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute c...

2026-08-16
CVE-2026-50522
KEV Analyzed
9.8
Microsoft SharePoint

A deserialization vulnerability in Microsoft SharePoint allows an unauthenticated attacker to execute code over a network.

2026-07-15
CVE-2026-50521
Analyzed
8.3
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network

2026-07-03
CVE-2026-50518
Analyzed
9.8
Microsoft Windows Server

A heap-based buffer overflow in the Windows DHCP Server service allows an unauthenticated, remote attacker to execute arbitrary code.

2026-07-15
CVE-2026-50517
Analyzed
9.9
Microsoft Microsoft 365 Copilot

A deserialization of untrusted data vulnerability in Microsoft 365 Copilot allows an authorized attacker to execute code over a network.

2026-07-25
CVE-2026-50515
Analyzed
9.9
Microsoft Azure Service Bus

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

2026-08-27
CVE-2026-5050
Analyzed
7.5
Google Pay gateway

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions u...

2026-04-17
CVE-2026-50489
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50481
Analyzed
9.9
Microsoft Azure Active Directory

Modification of assumed-immutable data in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

2026-08-27
CVE-2026-50477
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50474
Analyzed
8.8
Microsoft Windows

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-5046
Analyzed
8.8
Tenda FH1201

A flaw has been found in Tenda FH1201 1

2026-03-30
CVE-2026-5045
Analyzed
8.8
Tenda FH1201

A vulnerability was detected in Tenda FH1201 1

2026-03-30
CVE-2026-50447
Analyzed
9.8
Microsoft Windows

A heap-based buffer overflow in Windows Message Queuing allows an unauthenticated, remote attacker to execute arbitrary code.

2026-07-15
CVE-2026-50444
Analyzed
8.8
Microsoft Windows Server Update Service

Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-5044
Analyzed
8.8
Belkin F9K1122

A security vulnerability has been detected in Belkin F9K1122 1

2026-03-30
CVE-2026-50438
Analyzed
8.8
Microsoft PC Manager

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-5043
Analyzed
8.8
Belkin F9K1122

A weakness has been identified in Belkin F9K1122 1

2026-03-30
CVE-2026-5042
Analyzed
8.8
Belkin F9K1122

A security flaw has been discovered in Belkin F9K1122 1

2026-03-30
CVE-2026-50413
Analyzed
8.8
Microsoft Windows Runtime

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50398
Analyzed
8.8
Microsoft Windows 11 / Windows Server 2025

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate...

2026-07-15
CVE-2026-50385
Analyzed
8.8
Microsoft Windows 11 / Windows Server 2025

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevat...

2026-07-15
CVE-2026-50382
Analyzed
8.8
Microsoft Windows DirectX

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally

2026-07-15
CVE-2026-50380
Analyzed
9.6
Microsoft Windows

A heap-based buffer overflow in the Windows GDI+ component allows a remote attacker to execute code on affected Windows systems.

2026-07-15
CVE-2026-50370
Analyzed
8.8
Microsoft Windows DHCP Server

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network

2026-07-15
CVE-2026-50369
Analyzed
8.8
Microsoft Windows Remote Desktop Services

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-50360
Analyzed
8.8
Microsoft Windows SMB Server

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-5036
Analyzed
8.8
Tenda Multiple Products

A vulnerability was found in Tenda 4G06 04

2026-03-29