20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 5501-5550 of 20297 CVEs Page 111 of 406
CVE-2026-39910
Analyzed
9.8
STACKIT IaaS API

A missing authorization check in the STACKIT IaaS API allows low-privileged users to escalate privileges to full organization compromise.

2026-06-09
CVE-2026-3991
7.8
Microsoft Data Loss

Symantec Data Loss Prevention Windows Endpoint, prior to 25

2026-03-31
CVE-2026-39893
Analyzed
9.8
Cacti Cacti

A SQL injection vulnerability exists in Cacti versions 1.2.30 and prior, where the rfilter parameter is unsafely concatenated into an RLIKE clause, re...

2026-06-25
CVE-2026-39891
8.8
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-09
CVE-2026-39890
Analyzed
9.8
Microsoft system

PraisonAI versions prior to 4.5.115 are vulnerable to RCE via insecure YAML parsing, allowing execution of arbitrary JavaScript.

2026-04-09
CVE-2026-39889
7.5
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-10
CVE-2026-39888
Analyzed
9.9
Microsoft system

PraisonAI versions prior to 1.5.115 contain a sandbox escape vulnerability in its Python code execution tool, allowing arbitrary code execution.

2026-04-09
CVE-2026-39885
7.5
Unknown Multiple Products

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

2026-04-10
CVE-2026-39884
8.3
Kubernetes is

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management

2026-04-16
CVE-2026-39875
Analyzed
7.8
Apple macOS

A permissions issue was addressed with additional restrictions

2026-07-28
CVE-2026-39874
Analyzed
7.8
Apple macOS

A permissions issue was addressed with additional restrictions

2026-07-28
CVE-2026-39863
7.5
Signaling Multiple Products

Kamailio is an open source implementation of a SIP Signaling Server

2026-04-10
CVE-2026-39860
Analyzed
9
Linux and other

A symlink following vulnerability in the Nix package manager allows users to overwrite files and escalate privileges to root in multi-user installatio...

2026-04-09
CVE-2026-39853
7.8
MSI Multiple Products

osslsigncode is a tool that implements Authenticode signing and timestamping

2026-04-10
CVE-2026-39850
Analyzed
7.4
HP application framework

Yii 2 is a PHP application framework

2026-05-22
CVE-2026-3985
Analyzed
7.5
WordPress is vulnerable

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' paramet...

2026-05-20
CVE-2026-39847
Analyzed
9.1
Emmett Emmett

The Emmett web framework is vulnerable to path traversal attacks via the RSGI static handler, allowing unauthorized access to arbitrary files.

2026-04-08
CVE-2026-39846
Analyzed
9
SiYuan SiYuan Desktop Client

SiYuan personal knowledge management system is vulnerable to stored XSS, which can lead to remote code execution in the Electron desktop client.

2026-04-08
CVE-2026-39843
7.7
Unknown Multiple Products

Plane is an an open-source project management tool

2026-04-10
CVE-2026-39842
Analyzed
9.9
Unknown Multiple Products

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine...

2026-04-16
CVE-2026-39836
7.5
Microsoft Multiple Products

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)

2026-05-09
CVE-2026-39822
Analyzed
7.8
Go Go standard library os

On Unix systems, opening a file in an os

2026-07-09
CVE-2026-39820
7.5
Unknown Multiple Products

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations

2026-05-09
CVE-2026-39816
8.8
Apache NiFi

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi...

2026-05-09
CVE-2026-39815
8.8
Fortinet FortiDDoS

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7

2026-04-15
CVE-2026-39813
Analyzed
9.8
Fortinet FortiSandbox

A path traversal vulnerability in Fortinet FortiSandbox allows unauthenticated attackers to achieve privilege escalation via crafted file paths.

2026-04-15
CVE-2026-39808
KEV Analyzed
9.8
Fortinet FortiSandbox

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4....

2026-04-15
CVE-2026-3978
8.8
D-Link DIR

A vulnerability was detected in D-Link DIR-513 1

2026-03-12
CVE-2026-3976
8.8
Tenda W3

A weakness has been identified in Tenda W3 1

2026-03-12
CVE-2026-3975
8.8
Tenda W3

A security flaw has been discovered in Tenda W3 1

2026-03-12
CVE-2026-3974
8.8
Tenda W3

A vulnerability was identified in Tenda W3 1

2026-03-12
CVE-2026-3973
8.8
Tenda W3

A vulnerability was determined in Tenda W3 1

2026-03-12
CVE-2026-3972
8.8
Tenda W3

A vulnerability was found in Tenda W3 1

2026-03-12
CVE-2026-3971
8.8
Tenda i3

A vulnerability has been found in Tenda i3 1

2026-03-12
CVE-2026-3970
8.8
Tenda i3

A flaw has been found in Tenda i3 1

2026-03-12
CVE-2026-39684
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicfo...

2026-04-10
CVE-2026-39623
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife al...

2026-04-10
CVE-2026-39621
8.8
Web Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server

2026-04-10
CVE-2026-39591
Analyzed
9.9
WordPress WP-BusinessDirectory

An arbitrary file upload vulnerability exists in the WP-BusinessDirectory plugin for WordPress, allowing attackers to upload malicious files.

2026-06-16
CVE-2026-39587
Analyzed
8.1
WordPress WP BASE Booking

Unauthenticated Privilege Escalation in WP BASE Booking <= 5

2026-06-16
CVE-2026-39583
Analyzed
9.8
WordPress Ecommerce Delivery

An unauthenticated privilege escalation vulnerability exists in the Datalogics Ecommerce Delivery WordPress plugin, allowing attackers to gain adminis...

2026-06-16
CVE-2026-39581
Analyzed
8.5
WordPress WP Sessions Time Monitoring Full Automatic

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1

2026-06-17
CVE-2026-39579
Analyzed
8.8
WordPress B Blocks

Contributor Privilege Escalation in B Blocks <= 2

2026-06-16
CVE-2026-39532
Analyzed
8.8
HP Events Calendar for GeoDirectory

Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2

2026-06-16
CVE-2026-39531
Analyzed
9.3
WordPress WP Directory Kit

The WP Directory Kit plugin for WordPress is vulnerable to Blind SQL Injection, allowing attackers to extract sensitive database information.

2026-05-22
CVE-2026-3953
8.8
Gosoft Software Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd

2026-05-08
CVE-2026-39502
Analyzed
9.3
WordPress Form Maker

The Form Maker by 10Web plugin for WordPress is vulnerable to unauthenticated SQL injection, allowing attackers to extract information from the databa...

2026-06-16
CVE-2026-39493
Analyzed
9.3
Unknown Simply Schedule Appointments Plugin

An unauthenticated SQL injection vulnerability in the Simply Schedule Appointments plugin allows attackers to extract sensitive database information.

2026-06-16
CVE-2026-39492
Analyzed
9.3
WordPress WP Maps Plugin

The WP Maps plugin for WordPress is vulnerable to unauthenticated SQL injection, enabling attackers to extract sensitive information from the database...

2026-06-16
CVE-2026-39478
Analyzed
8.8
HP Anti-Malware Security and Brute-Force Firewall

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4

2026-06-16