21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 5601-5650 of 21637 CVEs Page 113 of 433
CVE-2026-4321
Analyzed
9.8
Raera Destekz

A critical SQL injection vulnerability in the Raera Destekz application allows unauthenticated attackers to execute arbitrary SQL commands.

2026-07-03
CVE-2026-4319
7.3
HP Multiple Products

A vulnerability was identified in code-projects Simple Food Order System 1

2026-03-19
CVE-2026-4318
8.8
UTT Multiple Products

A vulnerability was determined in UTT HiPER 810G up to 1

2026-03-18
CVE-2026-4314
Analyzed
8.8
WordPress Toolkit

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3

2026-03-22
CVE-2026-4312
Analyzed
9.8
DrangSoft GCB/FCB Audit Software

A missing authentication vulnerability in DrangSoft GCB/FCB Audit Software allows unauthenticated remote attackers to create unauthorized administrati...

2026-03-17
CVE-2026-43113
Analyzed
8.8
Linux Kernel (wl1251 driver)

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb(...

2026-06-02
CVE-2026-43112
Analyzed
8.8
Linux Kernel (CIFS client)

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitiz...

2026-06-02
CVE-2026-43110
Analyzed
8.8
Linux Kernel (brcmfmac driver)

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF events brcmf_fweh_handle_if_event(...

2026-06-02
CVE-2026-4306
7.5
WordPress is vulnerable

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2

2026-03-24
CVE-2026-43057
7.5
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback NETIF_F_IPV6_CS...

2026-05-03
CVE-2026-43056
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in add_adev() error path If auxiliary_device_add()...

2026-05-03
CVE-2026-43055
7.5
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd The target_core_file doesn't in...

2026-05-03
CVE-2026-43051
8.1
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_ir...

2026-05-03
CVE-2026-43048
8.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: HID: core: Mitigate potential OOB by removing bogus memset() The memset() in hid...

2026-05-03
CVE-2026-43047
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possib...

2026-05-03
CVE-2026-43044
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - fix DMA corruption on long hmac keys When a key longer than block...

2026-05-03
CVE-2026-4304
Analyzed
7.5
WordPress is vulnerable

The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3

2026-05-06
CVE-2026-43033
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption...

2026-05-03
CVE-2026-43031
7.5
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets When a TX packe...

2026-05-03
CVE-2026-43030
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix regsafe() for pointers to packet In case rold->reg->range == BEYOND_PKT...

2026-05-03
CVE-2026-43029
7.5
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix soft lockup in mptcp_recvmsg() syzbot reported a soft lockup in mptcp...

2026-05-03
CVE-2026-43025
7.3
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ignore explicit helper on new expectations Use the existin...

2026-05-03
CVE-2026-43023
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_connect() sco_sock_connect() che...

2026-05-03
CVE-2026-4302
7.2
WordPress is vulnerable

The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1

2026-03-22
CVE-2026-43019
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync hci_conn lookup an...

2026-05-03
CVE-2026-43018
8.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_...

2026-05-03
CVE-2026-43016
Analyzed
7.8
Google Google Compute

In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready(...

2026-05-03
CVE-2026-43009
7.8
Linux kernel

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix incorrect pruning due to atomic fetch precision tracking When backtrack...

2026-05-03
CVE-2026-43003
Analyzed
8
Unknown Multiple Products

An issue was discovered in OpenStack ironic-python-agent 1

2026-05-02
CVE-2026-43001
7.9
OpenStack Multiple Products

An issue was discovered in OpenStack Keystone 13 through 29

2026-05-02
CVE-2026-42997
7.7
Ironic Multiple Products

An issue was discovered in idrac in OpenStack Ironic before 35

2026-05-06
CVE-2026-42990
Analyzed
9.8
Microsoft Windows

A heap-based buffer overflow exists in the SQL Server ODBC driver on various Windows versions, allowing unauthenticated remote code execution.

2026-07-15
CVE-2026-42985
Analyzed
8.8
Microsoft Remote Desktop Client

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2026-06-10
CVE-2026-4297
Analyzed
8.8
WordPress Welcome Software Publishing Plugin

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0

2026-06-24
CVE-2026-42960
Analyzed
10
NLnet Labs Unbound

NLnet Labs Unbound is vulnerable to cache poisoning via promiscuous RRSets in the authority section of DNS replies, allowing attackers to inject malic...

2026-05-21
CVE-2026-42959
Analyzed
7.5
Unknown Multiple Products

NLnet Labs Unbound up to and including version 1

2026-05-21
CVE-2026-42958
Analyzed
7.8
Intel Proteus

The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files

2026-07-08
CVE-2026-42953
Analyzed
8.4
Labcenter Proteus

The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of...

2026-07-08
CVE-2026-42952
Analyzed
7.5
Hydro-Québec Le Circuit Electrique charging station backend

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a...

2026-07-12
CVE-2026-4295
7.8
Unknown Multiple Products

Improper trust boundary enforcement in Kiro IDE before version 0

2026-03-18
CVE-2026-42947
Analyzed
8.8
Naxclow IoT Platform (Smart Doorbell X3, X Smart Home, V720, ix cam)

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbit...

2026-06-13
CVE-2026-42945
Analyzed
8.1
Nginx Plus and

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

2026-05-15
CVE-2026-42944
Analyzed
7.5
Labs Multiple Products

NLnet Labs Unbound 1

2026-05-21
CVE-2026-42933
Analyzed
10
Pronetiqs Panduit Intravue

Pronetiqs Panduit Intravue is vulnerable to an unintended proxy or intermediary flaw that allows unauthenticated attackers to bypass OT network segmen...

2026-07-24
CVE-2026-42930
Analyzed
8.7
Unknown Multiple Products

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG...

2026-05-14
CVE-2026-42924
Analyzed
8.7
Unknown Multiple Products

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting...

2026-05-14
CVE-2026-42898
Analyzed
9.9
Microsoft Dynamics

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a...

2026-05-13
CVE-2026-42897
KEV Analyzed
8.1
Microsoft Exchange Server

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p...

2026-05-16
CVE-2026-4289
7.3
Unknown Multiple Products

A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7

2026-03-17
CVE-2026-42889
Analyzed
9.1
Unknown Multiple Products

Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSo...

2026-05-13