23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 5751-5800 of 23391 CVEs Page 116 of 468
CVE-2026-49186
Analyzed
9.8
Acer Connect M6E 5G Portable WiFi Router

The local MQTT broker on the Acer Connect M6E 5G router fails to enforce ACLs, allowing unauthorized clients to enumerate devices and publish rogue co...

2026-06-05
CVE-2026-49185
Analyzed
9.8
Acer Connect M6E 5G Portable WiFi Router

The FieldX MDM component in the Acer Connect M6E 5G router is vulnerable to command injection via unverified payloads in the adb messaging topic.

2026-06-05
CVE-2026-49179
Analyzed
8.8
Microsoft Windows

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to exe...

2026-08-12
CVE-2026-49178
Analyzed
8.8
Microsoft Active Directory Domain Services

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-49172
Analyzed
9.8
Microsoft Windows

A heap-based buffer overflow in the Windows FTP Service allows an unauthenticated attacker to execute arbitrary code over a network.

2026-07-15
CVE-2026-49158
Analyzed
7.5
Apache Apache Thrift

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings

2026-07-28
CVE-2026-49157
Analyzed
8.8
Apache ActiveMQ

Incorrect Default Permissions vulnerability in Apache ActiveMQ

2026-06-02
CVE-2026-49143
Analyzed
8.8
BrowserStack Runner

BrowserStack Runner through 0

2026-06-03
CVE-2026-49127
Analyzed
8.6
Unknown Multiple Products

Music Player Daemon (MPD) before version 0

2026-05-29
CVE-2026-49120
Analyzed
8.5
Medplum Medplum

Medplum before 5

2026-06-04
CVE-2026-49113
Analyzed
8.5
Cornerstone Cornerstone

Subscriber Arbitrary Code Execution in Cornerstone < 7

2026-06-18
CVE-2026-49111
Analyzed
8.8
WordPress Masteriyo - LMS

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation

2026-06-16
CVE-2026-49109
Analyzed
9.8
HP Integration for Salesforce

An unauthenticated PHP Object Injection vulnerability in the CRM Perks Integration for Salesforce allows remote attackers to achieve arbitrary code ex...

2026-06-16
CVE-2026-49106
Analyzed
9.8
HP Integration for Contact Form 7 and Constant Contact

An unauthenticated PHP Object Injection vulnerability exists in the CRM Perks Integration for Contact Form 7 and Constant Contact, enabling potential...

2026-06-16
CVE-2026-49105
Analyzed
9.8
HP WP Zendesk

An unauthenticated PHP Object Injection vulnerability in the WP Zendesk integration for WordPress allows attackers to execute arbitrary code via deser...

2026-06-16
CVE-2026-49104
Analyzed
9.8
HP Integration for Keap/infusionsoft

An unauthenticated PHP Object Injection vulnerability in the CRM Perks Integration for Keap/infusionsoft allows remote attackers to perform deserializ...

2026-06-16
CVE-2026-49085
Analyzed
9.8
HP WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

An unauthenticated PHP Object Injection vulnerability exists in the WP Insightly integration plugin for various WordPress form builders, allowing pote...

2026-06-16
CVE-2026-49073
Analyzed
8.5
Unknown Directorist Booking

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injec...

2026-06-18
CVE-2026-49065
Analyzed
8.2
Hippoo Mobile App for WooCommerce

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1

2026-06-16
CVE-2026-49062
Analyzed
8.8
WP Engine Faust.Js

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust

2026-06-16
CVE-2026-49060
Analyzed
9.8
Hippoo Mobile Hippoo Mobile App for WooCommerce

An incorrect privilege assignment vulnerability in Hippoo Mobile App for WooCommerce allows remote attackers to perform privilege escalation.

2026-06-12
CVE-2026-4906
Analyzed
8.8
Tenda AC5

A vulnerability was determined in Tenda AC5 15

2026-03-27
CVE-2026-49050
Analyzed
8.8
Apache DolphinScheduler

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3

2026-08-26
CVE-2026-4905
Analyzed
8.8
Tenda AC5

A vulnerability was found in Tenda AC5 15

2026-03-27
CVE-2026-49049
Analyzed
7.5
Joomla Helix3 extension

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files...

2026-06-30
CVE-2026-49046
Analyzed
8.5
Arjun Thakur Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blin...

2026-05-29
CVE-2026-49042
Analyzed
7.3
Apache Camel

Improper Input Validation vulnerability in Apache Camel

2026-07-07
CVE-2026-4904
Analyzed
8.8
Tenda AC5

A vulnerability has been found in Tenda AC5 15

2026-03-27
CVE-2026-49035
Analyzed
8.1
MZ Automation libIEC61850

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request

2026-07-24
CVE-2026-49033
Analyzed
7.8
Labcenter Proteus

The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code

2026-07-08
CVE-2026-4903
Analyzed
8.8
Tenda AC5

A flaw has been found in Tenda AC5 15

2026-03-27
CVE-2026-4902
Analyzed
8.8
Tenda AC5

A vulnerability was detected in Tenda AC5 15

2026-03-27
CVE-2026-49003
Analyzed
9.6
ZTE ZXDU68 S202 V5.0

A command injection vulnerability in the ZTE ZXDU68 S202 V5.0 allows unauthenticated attackers to gain root privileges, delete critical system files,...

2026-09-01
CVE-2026-48970
Analyzed
8.1
WordPress Really Simple SSL

Unauthenticated Broken Authentication in Really Simple SSL <= 9

2026-06-16
CVE-2026-48967
Analyzed
8.5
WordPress Geo Mashup Plugin

Subscriber SQL Injection in Geo Mashup <= 1

2026-06-18
CVE-2026-48964
Analyzed
8.5
WordPress HelpDesk & Customer Ticketing System

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3

2026-06-16
CVE-2026-4896
Analyzed
8.1
WordPress is vulnerable

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct...

2026-04-04
CVE-2026-48939
KEV Analyzed
9.5
Joomla iCagenda extension for Joomla

iCagenda is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to execute arbitrary code on the server.

2026-07-11
CVE-2026-48920
Analyzed
8.8
Jenkins Email Extension

Jenkins Email Extension Plugin 1933

2026-05-28
CVE-2026-4892
Analyzed
8.4
DHCPv6 Multiple Products

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root priv...

2026-05-12
CVE-2026-48908
KEV Analyzed
9.5
Joomla SP Page Builder

JoomShaper SP Page Builder is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to execute arbitrary code.

2026-07-08
CVE-2026-48907
KEV Analyzed
9.5
Joomla Joomla Content Editor

An improper access control vulnerability in the Widget Factory Joomla Content Editor allows unauthorized users to perform restricted actions.

2026-06-17
CVE-2026-48904
Analyzed
9.8
Joomla CMS

An improper access check in the Joomla CMS `com_users` webservice endpoint allows for privilege escalation.

2026-05-27
CVE-2026-4890
Analyzed
7.5
DNSSEC validation Multiple Products

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS pac...

2026-05-12
CVE-2026-48899
Analyzed
9.8
Joomla CMS

Joomla CMS contains an improper access check in the `com_users` batch task, allowing for privilege escalation.

2026-05-27
CVE-2026-48898
Analyzed
9.8
Joomla CMS

An improper access check in the Joomla CMS `com_users` batch task allows for privilege escalation.

2026-05-27
CVE-2026-48889
Analyzed
8.8
WordPress Amelia Plugin

Subscriber Privilege Escalation in Amelia <= 2

2026-06-16
CVE-2026-48882
Analyzed
8.5
WordPress WP Time Slots Booking Form

Subscriber SQL Injection in WP Time Slots Booking Form <= 1

2026-06-16
CVE-2026-48879
Analyzed
9.8
WordPress AIWU

The AIWU plugin for WordPress is vulnerable to privilege escalation due to incorrect privilege assignment.

2026-06-02
CVE-2026-48874
Analyzed
8.5
WordPress GamiPress

Subscriber SQL Injection in GamiPress <= 7

2026-06-16