20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 551-600 of 20297 CVEs Page 12 of 406
CVE-2026-7579
7.3
Unknown Multiple Products

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4

2026-05-02
CVE-2026-7574
Analyzed
8.7
Anthropic Claude Desktop Cowork

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1

2026-06-24
CVE-2026-7571
Analyzed
7.1
Infor Multiple Products

A flaw was found in Keycloak

2026-05-20
CVE-2026-7570
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-7569
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability

2026-06-25
CVE-2026-7567
Analyzed
9.8
WordPress is vulnerable

The Temporary Login plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers to log in as any temporary user.

2026-05-02
CVE-2026-7555
7.3
HP Multiple Products

A vulnerability was identified in itsourcecode Electronic Judging System 1

2026-05-01
CVE-2026-7551
8.8
Unknown Multiple Products

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to...

2026-05-01
CVE-2026-7550
7.3
HP Multiple Products

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-05-01
CVE-2026-7549
7.3
HP Multiple Products

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-05-01
CVE-2026-7548
8.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink NR1800X 9

2026-05-01
CVE-2026-7546
Analyzed
9.8
TOTOLINK NR1800X

A stack-based buffer overflow exists in the Totolink NR1800X lighttpd component, allowing remote attackers to trigger a crash or execute code via the...

2026-05-01
CVE-2026-7545
7.3
HP of the

A weakness has been identified in SourceCodester Advanced School Management System 1

2026-05-01
CVE-2026-7538
Analyzed
9.8
TOTOLINK A8000RU

The Totolink A8000RU router is vulnerable to remote OS command injection via the proto parameter in the CGI handler, allowing unauthenticated attacker...

2026-05-01
CVE-2026-7524
Analyzed
9.8
IBM Langflow OSS

IBM Langflow OSS is vulnerable to remote code execution during archive extraction due to improper validation of symbolic links.

2026-05-28
CVE-2026-7522
Analyzed
8.8
WordPress is vulnerable

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4

2026-05-20
CVE-2026-7520
Analyzed
8.1
WordPress Mailmunch Forms for Mailchimp

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sig...

2026-08-05
CVE-2026-7519
7.3
Unknown Multiple Products

A vulnerability has been found in Fujian Apex LiveBOS up to 2

2026-05-01
CVE-2026-7515
Analyzed
9.8
HP BetterDocs Pro

The BetterDocs Pro plugin for WordPress contains a Local File Inclusion vulnerability in the doc_style parameter, allowing unauthenticated attackers t...

2026-06-20
CVE-2026-7513
8.8
UTT Multiple Products

A vulnerability has been found in UTT HiPER 1200GW up to 2

2026-05-01
CVE-2026-7512
8.8
UTT Multiple Products

A flaw has been found in UTT HiPER 1200GW up to 2

2026-05-01
CVE-2026-7507
Analyzed
7.5
Unknown Multiple Products

A session fixation vulnerability was found in Keycloak's login-actions endpoints

2026-05-20
CVE-2026-7506
7.3
HP Multiple Products

A vulnerability has been found in SourceCodester Hotel Management System 1

2026-05-01
CVE-2026-7505
7.3
Unknown Multiple Products

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3

2026-05-01
CVE-2026-7504
Analyzed
8.1
Infor Multiple Products

A flaw was found in Keycloak's URL validation logic during redirect operations

2026-05-20
CVE-2026-7503
8.8
Unknown Multiple Products

A vulnerability was detected in code-projects for Plugin 4

2026-05-01
CVE-2026-7498
Analyzed
8.8
Unknown Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Or...

2026-05-19
CVE-2026-7491
8.1
School Multiple Products

School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific pa...

2026-05-03
CVE-2026-7490
7.2
Unknown Multiple Products

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell bac...

2026-05-04
CVE-2026-7489
Analyzed
8.8
Sunnet CTMS

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,...

2026-05-03
CVE-2026-7488
Analyzed
7.5
IKAS Technology E-Commerce

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc

2026-07-19
CVE-2026-7486
Analyzed
9.8
Netcad Software E-İmar

An SQL injection vulnerability in Netcad Software E-İmar allows unauthorized attackers to manipulate database queries and potentially access sensitive...

2026-06-10
CVE-2026-7483
Analyzed
8.5
ESET ESET Endpoint Security for macOS

Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user

2026-07-25
CVE-2026-7482
Analyzed
9.1
Ollama Multiple Products

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied...

2026-05-05
CVE-2026-7481
Analyzed
8.7
GitLab has remediated

GitLab has remediated an issue in GitLab EE affecting all versions from 16

2026-05-14
CVE-2026-7474
Analyzed
8.8
Unknown Nomad and

HashiCorp Nomad and Nomad Enterprise prior to 2

2026-05-13
CVE-2026-7473
KEV Analyzed
9.5
Arista Extensible Operating System

Arista Extensible Operating System is affected by an incomplete comparison vulnerability, currently tracked in the CISA KEV catalog.

2026-06-10
CVE-2026-7470
8.8
Tenda Multiple Products

A flaw has been found in Tenda 4G300 US_4G300V1

2026-04-30
CVE-2026-7468
7.3
Unknown Multiple Products

A security vulnerability has been detected in 1024-lab smart-admin up to 3

2026-05-01
CVE-2026-7467
Analyzed
8.8
WordPress is vulnerable

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3

2026-05-20
CVE-2026-7466
Analyzed
8.8
Unknown Multiple Products

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controll...

2026-04-30
CVE-2026-7465
Analyzed
8.8
WordPress is vulnerable

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...

2026-05-31
CVE-2026-7461
7.2
Microsoft Multiple Products

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before...

2026-05-01
CVE-2026-7458
Analyzed
9.8
WordPress is vulnerable

The User Verification plugin for WordPress is vulnerable to authentication bypass due to loose comparison of OTP codes, allowing unauthenticated login...

2026-05-02
CVE-2026-7448
7.2
WordPress is vulnerable

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_n...

2026-05-06
CVE-2026-7446
Analyzed
7.3
F5 mcp-server-semgrep

A vulnerability was detected in VetCoders mcp-server-semgrep 1

2026-05-01
CVE-2026-7444
Analyzed
8.1
WordPress Search Analytics for WP

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1

2026-08-05
CVE-2026-7443
7.3
Infor Multiple Products

A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1

2026-05-01
CVE-2026-7435
7.2
Unknown Multiple Products

SSCMS v7

2026-05-01
CVE-2026-7426
8.1
Insufficient Multiple Products

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4

2026-04-30