20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 5651-5700 of 20297 CVEs Page 114 of 406
CVE-2026-38566
Analyzed
8.1
Unknown Multiple Products

HireFlow v1

2026-05-13
CVE-2026-38532
8.1
HP endpoint of

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController

2026-04-15
CVE-2026-38530
8.1
HP endpoint of

A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController

2026-04-15
CVE-2026-38529
8.8
HP endpoint of

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController

2026-04-15
CVE-2026-38527
8.5
Unknown Multiple Products

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2

2026-04-15
CVE-2026-38526
Analyzed
9.9
HP file

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arb...

2026-04-15
CVE-2026-3847
8.8
Unknown Multiple Products

Memory safety bugs present in Firefox 148

2026-03-11
CVE-2026-38450
9.8
Unknown Multiple Products

An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of...

2026-07-20
CVE-2026-3845
8.8
Google Multiple Products

Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android

2026-03-11
CVE-2026-38447
Analyzed
9.8
Unknown osTicket

osTicket 1.18.3 uses insecure MD5 hashing with predictable inputs to generate API keys, allowing attackers to brute-force authentication credentials.

2026-08-04
CVE-2026-3844
Analyzed
9.8
WordPress is vulnerable

The Breeze Cache plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the Gravatar fetching function.

2026-04-23
CVE-2026-3843
Analyzed
9.8
HP contains

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration...

2026-03-11
CVE-2026-3839
7.3
HP file

Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability

2026-03-17
CVE-2026-3838
8.8
HP file

Unraid Update Request Path Traversal Remote Code Execution Vulnerability

2026-03-17
CVE-2026-38361
7.5
Unknown Multiple Products

An issue in fohrloop dash-uploader v

2026-05-09
CVE-2026-38360
Analyzed
9.8
Unknown Multiple Products

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_...

2026-05-09
CVE-2026-3830
8.6
WordPress plugin before

The Product Filter for WooCommerce by WBW WordPress plugin before 3

2026-04-14
CVE-2026-3828
Analyzed
7.2
Hikvision switch products

Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input v...

2026-05-10
CVE-2026-3826
Analyzed
9.8
WellChoose IFTOP

A Local File Inclusion (LFI) vulnerability in WellChoose IFTOP allows unauthenticated remote attackers to execute arbitrary code on the server.

2026-03-11
CVE-2026-3823
Analyzed
8.8
Atop Technologies EHG2408 series switch

EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to con...

2026-03-09
CVE-2026-3821
Analyzed
8.8
SMCI X14DBG-DAP, X14DBI

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI

2026-07-22
CVE-2026-3818
7.3
Microsoft Multiple Products

A flaw has been found in Tiandy Easy7 CMS Windows 7

2026-03-10
CVE-2026-38158
Analyzed
9.8
Youseries ureport

A SQL injection vulnerability in the ureport component allows unauthenticated attackers to execute arbitrary SQL queries and access sensitive database...

2026-07-21
CVE-2026-3815
8.8
UTT Multiple Products

A weakness has been identified in UTT HiPER 810G up to 1

2026-03-10
CVE-2026-3814
8.8
UTT Multiple Products

A security flaw has been discovered in UTT HiPER 810G up to 1

2026-03-10
CVE-2026-3811
8.8
Tenda FH1202

A vulnerability was found in Tenda FH1202 1

2026-03-10
CVE-2026-3810
8.8
Tenda FH1202

A vulnerability has been found in Tenda FH1202 1

2026-03-09
CVE-2026-3809
8.8
Tenda FH1202

A flaw has been found in Tenda FH1202 1

2026-03-09
CVE-2026-3808
8.8
Tenda FH1202

A vulnerability was detected in Tenda FH1202 1

2026-03-09
CVE-2026-38076
Analyzed
7.5
Artifex jbig2dec

An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a craf...

2026-07-14
CVE-2026-3807
8.8
Tenda FH1202

A security vulnerability has been detected in Tenda FH1202 1

2026-03-09
CVE-2026-38059
Analyzed
7.5
ST Engineering iDirect Evolution iQ‑Series terminals

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication

2026-07-12
CVE-2026-38057
Analyzed
8.1
ST Engineering iDirect Evolution iQ-Series terminals

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication

2026-07-11
CVE-2026-3804
8.8
Tenda i3

A security flaw has been discovered in Tenda i3 1

2026-03-09
CVE-2026-3803
8.8
Tenda i3

A vulnerability was identified in Tenda i3 1

2026-03-09
CVE-2026-3802
8.8
Tenda i3

A vulnerability was determined in Tenda i3 1

2026-03-09
CVE-2026-3801
8.8
Tenda i3

A vulnerability was found in Tenda i3 1

2026-03-09
CVE-2026-3799
8.8
Tenda i3

A flaw has been found in Tenda i3 1

2026-03-09
CVE-2026-3794
7.3
Unknown Multiple Products

A vulnerability was identified in doramart DoraCMS 3

2026-03-09
CVE-2026-3787
7
Arch path

A weakness has been identified in UltraVNC 1

2026-03-09
CVE-2026-3780
7.3
Arch paths that

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-...

2026-04-01
CVE-2026-3779
7.8
Unknown Multiple Products

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows cra...

2026-04-01
CVE-2026-3775
7.8
Arch path that

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by l...

2026-04-01
CVE-2026-37749
Analyzed
9.8
HP Multiple Products

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication v...

2026-04-18
CVE-2026-3772
8.8
WordPress is vulnerable

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1

2026-05-02
CVE-2026-37709
Analyzed
9.8
HP component

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to e...

2026-05-08
CVE-2026-3769
8.8
Tenda F453

A vulnerability was detected in Tenda F453 1

2026-03-09
CVE-2026-3768
8.8
Tenda F453

A security vulnerability has been detected in Tenda F453 1

2026-03-09
CVE-2026-3765
7.3
HP Multiple Products

A vulnerability was identified in itsourcecode University Management System 1

2026-03-09
CVE-2026-3764
Analyzed
7.3
HP Client Database Management System

A vulnerability was determined in SourceCodester Client Database Management System 1

2026-03-09