21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 5751-5800 of 21637 CVEs Page 116 of 433
CVE-2026-42477
7.1
Infor Multiple Products

A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows user-as...

2026-05-02
CVE-2026-42476
7.1
Infor Multiple Products

Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 exist in RWStl_Reader::Rea...

2026-05-02
CVE-2026-42473
Analyzed
9.8
HP Framework

The MixPHP Framework is vulnerable to unsafe deserialization of session and cache data stored on the filesystem, potentially allowing remote code exec...

2026-05-02
CVE-2026-42472
Analyzed
9.8
HP Framework

The MixPHP Framework is vulnerable to unsafe deserialization of session and cache data stored in Redis, potentially allowing remote code execution.

2026-05-02
CVE-2026-42471
8.1
HP Framework

Unsafe deserialization vulnerability in MixPHP Framework 2

2026-05-02
CVE-2026-42469
8.6
Unknown Multiple Products

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3

2026-05-02
CVE-2026-42468
8.8
Unknown Multiple Products

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3

2026-05-02
CVE-2026-42467
7.5
Unknown Multiple Products

An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_Transfer_DM1...

2026-05-02
CVE-2026-42457
Analyzed
9
Kubernetes platform for

A stored Cross-Site Scripting (XSS) vulnerability in the vCluster Platform allows attackers to execute arbitrary scripts and potentially escalate priv...

2026-05-15
CVE-2026-42454
Analyzed
9.9
Docker container management

Termix is vulnerable to OS command injection in its Docker management endpoints, leading to remote code execution.

2026-05-09
CVE-2026-42452
8.1
Unknown Multiple Products

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

2026-05-09
CVE-2026-42450
Analyzed
8.4
Unknown OpenColorIO

OpenColorIO is a color management framework for visual effects and animation

2026-06-25
CVE-2026-42449
8.5
MCP Multiple Products

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations

2026-05-08
CVE-2026-42440
Analyzed
7.5
Apache OpenNLP AbstractModelReader

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 2

2026-05-06
CVE-2026-42439
8.5
OpenClaw Multiple Products

OpenClaw before 2026

2026-05-06
CVE-2026-42438
7.7
OpenClaw Multiple Products

OpenClaw versions 2026

2026-05-06
CVE-2026-42437
7.5
OpenClaw Multiple Products

OpenClaw versions 2026

2026-05-06
CVE-2026-42436
7.7
OpenClaw Multiple Products

OpenClaw before 2026

2026-05-06
CVE-2026-42435
8.8
Unknown Multiple Products

OpenClaw versions from 2026

2026-05-06
CVE-2026-42434
8.8
OpenClaw Multiple Products

OpenClaw versions 2026

2026-05-06
CVE-2026-42432
7.8
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-29
CVE-2026-42431
8.1
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-29
CVE-2026-42426
8.8
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-29
CVE-2026-42423
7.5
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-29
CVE-2026-42422
8.8
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-29
CVE-2026-42411
Analyzed
8.1
WordPress CloudSecure WP Security

Unauthenticated Broken Authentication in CloudSecure WP Security <= 1

2026-06-16
CVE-2026-42406
Analyzed
8.7
Certificate Multiple Products

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can m...

2026-05-14
CVE-2026-42403
7.5
Apache Neethi does

Apache Neethi does not properly detect circular references in policy definitions

2026-05-02
CVE-2026-42402
7.5
Apache Neethi is

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization

2026-05-02
CVE-2026-42383
Analyzed
7.6
YITH YITH WooCommerce Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Bli...

2026-05-21
CVE-2026-42382
Analyzed
8.1
Elated-Themes Audrey

Unauthenticated Local File Inclusion in Audrey <= 1

2026-07-03
CVE-2026-42379
7.7
WPDeveloper Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data

2026-04-28
CVE-2026-42376
Analyzed
9.8
D-Link DIR

D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0...

2026-05-05
CVE-2026-42375
Analyzed
9.8
D-Link DIR

D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh...

2026-05-05
CVE-2026-42374
Analyzed
9.8
D-Link DIR

D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh...

2026-05-05
CVE-2026-42373
Analyzed
9.8
D-Link DIR

D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telne...

2026-05-05
CVE-2026-42372
8.8
D-Link DIR

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor

2026-05-05
CVE-2026-42370
Analyzed
9
GeoVision GV-VMS

A stack overflow in the WebCam Server Login functionality of GeoVision GV-VMS 20.0.2 allows unauthenticated remote attackers to achieve arbitrary code...

2026-05-04
CVE-2026-4237
7.3
HP Multiple Products

A flaw has been found in itsourcecode Free Hotel Reservation System 1

2026-03-17
CVE-2026-42369
Analyzed
10
GeoVision GV-VMS

A stack-based buffer overflow in the GV-VMS WebCam Server gvapi endpoint allows remote attackers to gain SYSTEM-level code execution via a specially c...

2026-05-04
CVE-2026-42368
Analyzed
9.9
GeoVision LPC2011/LPC2211

A privilege escalation vulnerability in the GeoVision LPC2011/LPC2211 web interface allows an attacker to execute privileged operations via a crafted...

2026-05-04
CVE-2026-42366
7.4
Unknown Multiple Products

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi

2026-05-04
CVE-2026-42365
Analyzed
8.6
GeoVision LPC2011/LPC2211

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1

2026-05-04
CVE-2026-42364
Analyzed
9.9
GeoVision LPC2011/LPC2211

An OS command injection vulnerability in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 allows arbitrary command execution via crafted...

2026-05-04
CVE-2026-42363
Analyzed
9.3
LG GV-IP Device Utility

GeoVision GV-IP Device Utility 9.0.5 uses insufficient encryption for administrative credentials, allowing attackers to intercept and decrypt sensitiv...

2026-04-27
CVE-2026-4236
7.3
Enrollment Multiple Products

A security vulnerability has been detected in itsourcecode Online Enrollment System 1

2026-03-17
CVE-2026-42359
Analyzed
8.8
Apache Airflow

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a D...

2026-06-03
CVE-2026-42354
Analyzed
9.1
Sentry Sentry

Sentry's SAML SSO implementation is vulnerable to an account takeover flaw when using a malicious SAML Identity Provider.

2026-05-09
CVE-2026-42353
8.2
Unknown Multiple Products

i18next-http-middleware is a middleware to be used with Node

2026-05-09
CVE-2026-42352
8.6
Python Multiple Products

pygeoapi is a Python server implementation of the OGC API suite of standards

2026-05-09