21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 5651-5700 of 21637 CVEs Page 114 of 433
CVE-2026-42882
Analyzed
9.4
AWS s3 proxy

The oxyno-zeta s3-proxy contains an authentication bypass vulnerability due to inconsistent path interpretation, allowing unauthorized S3 operations.

2026-05-12
CVE-2026-42880
Analyzed
9.6
Kubernetes Secret data

A missing authorization gap in Argo CD allows read-only users to extract plaintext Kubernetes Secret data via the ServerSideDiff endpoint.

2026-05-08
CVE-2026-4288
7.3
Unknown Multiple Products

A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7

2026-03-17
CVE-2026-4287
7.3
Unknown Multiple Products

A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7

2026-03-17
CVE-2026-42869
Analyzed
10
Docker Compose setup

SOCFortress CoPilot uses a hardcoded JWT signing secret, allowing unauthenticated attackers to forge administrative tokens.

2026-05-12
CVE-2026-42864
Analyzed
9.9
AWS credentials attached

FireFighter incident management application contains an unauthenticated SSRF vulnerability that can lead to the theft of AWS IAM credentials.

2026-05-12
CVE-2026-42860
Analyzed
8.5
Unknown Multiple Products

The Open edx Enterprise Service app provides enterprise features to the Open edX platform

2026-05-12
CVE-2026-42858
Analyzed
8.5
F5 Open edX Platform

Open edX Platform enables the authoring and delivery of online learning at any scale

2026-05-12
CVE-2026-42854
Analyzed
9.8
Unknown Multiple Products

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer mu...

2026-05-13
CVE-2026-42851
Analyzed
7.8
Kitty Kitty Terminal

Kitty is a cross-platform GPU based terminal

2026-06-14
CVE-2026-42850
Analyzed
8.8
Kovid Goyal Kitty

Kitty is a cross-platform GPU based terminal

2026-06-17
CVE-2026-42846
Analyzed
9.8
ClipBucket ClipBucket v5

ClipBucket v5 contains a command injection vulnerability in the Remote Play feature, allowing authenticated users to execute arbitrary shell commands...

2026-06-12
CVE-2026-42843
Analyzed
8.8
Grav Multiple Products

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system manag...

2026-05-12
CVE-2026-42835
Analyzed
8.1
Microsoft Teams for Android

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized...

2026-06-14
CVE-2026-42834
Analyzed
7.8
Microsoft Portal Windows

Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privilege...

2026-05-21
CVE-2026-42833
Analyzed
9.1
Microsoft Dynamics

An execution with unnecessary privileges vulnerability in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute arbitrary code...

2026-05-13
CVE-2026-4283
Analyzed
9.1
WordPress is vulnerable

The WP DSGVO Tools (GDPR) plugin for WordPress allows unauthenticated attackers to permanently destroy non-administrator accounts by bypassing the ema...

2026-03-24
CVE-2026-42826
Analyzed
10
Microsoft DevOps allows

An exposure of sensitive information in Azure DevOps allows an unauthenticated attacker to disclose data over a network.

2026-05-08
CVE-2026-42823
Analyzed
9.9
Microsoft Logic Apps

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

2026-05-13
CVE-2026-42822
Analyzed
10
Microsoft Local Disconnected

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to perform privilege escalation over the network.

2026-05-19
CVE-2026-4282
Analyzed
7.4
Keycloak Keycloak

A flaw was found in Keycloak

2026-04-04
CVE-2026-42812
Analyzed
9.9
Apache Iceberg

A security-sensitive metadata write bypass in Apache Iceberg allows authorized users to perform unauthorized operations on storage locations by manipu...

2026-05-05
CVE-2026-42811
Analyzed
9.9
Google Cloud Storage

A credential injection vulnerability in Apache Polaris allows attackers to bypass storage path restrictions in Google Cloud Storage via crafted namesp...

2026-05-05
CVE-2026-42810
Analyzed
9.9
Apache Polaris accepts

Apache Polaris is vulnerable to cross-table access due to improper handling of wildcard characters in object names, which results in insecure S3 IAM p...

2026-05-05
CVE-2026-42809
Analyzed
9.9
Apache Polaris can

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been vali...

2026-05-05
CVE-2026-42800
7.4
Linux on Linux

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation

2026-05-01
CVE-2026-42799
7.4
ASR Kestrel Multiple Products

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers

2026-05-01
CVE-2026-42796
Analyzed
9.8
Arelle Multiple Products

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins quer...

2026-05-05
CVE-2026-42779
Analyzed
9.8
Apache MINA

Apache MINA's AbstractIoBuffer.resolveClass() contains a branch that fails to validate classes, allowing for arbitrary code execution via deserializat...

2026-05-02
CVE-2026-42778
Analyzed
9.8
Apache MINA AbstractIoBuffer

An incomplete fix for a deserialization vulnerability in Apache MINA's AbstractIoBuffer.getObject() allows for remote code execution via classname all...

2026-05-02
CVE-2026-4276
7.5
Unknown Multiple Products

LibreChat RAG API, version 0

2026-03-18
CVE-2026-42758
Analyzed
9.8
Saleswonder Team Multiple Products

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affec...

2026-05-28
CVE-2026-42757
Analyzed
9.9
Saleswonder Team Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignit...

2026-05-28
CVE-2026-42756
Analyzed
9.9
Ludwig You Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Image...

2026-05-28
CVE-2026-4275
Analyzed
8.8
WordPress Divi Torque Lite – Divi Modules for the Divi Builder & Theme

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...

2026-07-10
CVE-2026-42748
Analyzed
9.9
HP Woo Czech

An unrestricted file upload vulnerability in the WPify Woo Czech plugin allows unauthenticated attackers to upload and execute a web shell on the serv...

2026-05-28
CVE-2026-42742
Analyzed
8.5
Aman Views Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite al...

2026-05-13
CVE-2026-42741
Analyzed
8.5
Aman Ninja Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Edi...

2026-05-13
CVE-2026-42737
Analyzed
8.6
Unknown Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbook...

2026-05-29
CVE-2026-42735
Analyzed
8.2
Iqonic Design Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Rec...

2026-05-29
CVE-2026-42731
Analyzed
9.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This is...

2026-05-28
CVE-2026-42730
Analyzed
8.5
Stylemix MasterStudy Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learnin...

2026-05-29
CVE-2026-4272
8.1
Honeywell Handheld Handheld Scanners

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse

2026-04-06
CVE-2026-4269
Analyzed
7.5
Unknown Multiple Products

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0

2026-03-17
CVE-2026-42687
Analyzed
8.1
HP EventPrime

Unauthenticated PHP Object Injection in EventPrime <= 4

2026-06-16
CVE-2026-42680
Analyzed
9.8
WordPress Contest Gallery Pro

Contest Gallery Pro for WordPress contains an incorrect privilege assignment vulnerability that allows privilege escalation.

2026-06-02
CVE-2026-4267
7.2
WordPress plugin for

The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['RE...

2026-04-01
CVE-2026-42664
Analyzed
8.2
Motive AI Product Search for WooCommerce

Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search <= 1

2026-06-16
CVE-2026-42661
Analyzed
8.8
WP Customer Area WP Customer Area Plugin

Custom role Path Traversal in WP Customer Area <= 8

2026-06-16
CVE-2026-42652
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration al...

2026-05-01