20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 6001-6050 of 20297 CVEs Page 121 of 406
CVE-2026-35064
7.5
SenseLive Multiple Products

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol,...

2026-04-24
CVE-2026-35056
8.8
XenForo Multiple Products

XenForo before 2

2026-04-01
CVE-2026-35050
Analyzed
9.1
Unknown text-generation-webui

The text-generation-webui application allows arbitrary Python file overwriting via extension settings, leading to remote code execution.

2026-04-07
CVE-2026-35048
Analyzed
9.8
HP Piwigo

The Piwigo installer improperly sanitizes database configuration POST parameters, allowing unauthenticated attackers to inject and execute arbitrary P...

2026-07-21
CVE-2026-35045
8.1
Tandoor Multiple Products

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists

2026-04-07
CVE-2026-35044
8.8
Arch Multiple Products

BentoML is a Python library for building online serving systems optimized for AI apps and model inference

2026-04-07
CVE-2026-35043
7.8
Unknown Multiple Products

BentoML is a Python library for building online serving systems optimized for AI apps and model inference

2026-04-07
CVE-2026-35042
7.5
Unknown Multiple Products

fast-jwt provides fast JSON Web Token (JWT) implementation

2026-04-07
CVE-2026-35039
Analyzed
9.1
Unknown fast-jwt

A cache collision vulnerability in fast-jwt allows for JWT token misidentification, potentially causing users to be authenticated as other users.

2026-04-07
CVE-2026-35036
7.5
Docker bridge

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing

2026-04-07
CVE-2026-35031
Analyzed
9.9
Unknown Multiple Products

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Vi...

2026-04-15
CVE-2026-35029
8.8
Unknown Multiple Products

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

2026-04-08
CVE-2026-35025
Analyzed
8.1
ProFTPD ProFTPD

ProFTPD through 1

2026-06-25
CVE-2026-35022
Analyzed
9.8
AWS Claude Code CLI and Claude Agent SDK

Anthropic Claude CLI and SDK are vulnerable to OS command injection via unvalidated authentication helper configuration parameters, allowing arbitrary...

2026-04-07
CVE-2026-35021
7.8
Unknown Multiple Products

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attac...

2026-04-07
CVE-2026-35020
8.4
Unknown Multiple Products

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launc...

2026-04-07
CVE-2026-3502
KEV
7.8
TrueConf Multiple Products

TrueConf Client downloads application update code and applies it without performing verification

2026-03-31
CVE-2026-35019
Analyzed
8.1
NetComm NF20MESH

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to g...

2026-06-24
CVE-2026-35018
Analyzed
8.8
NetComm NF20MESH

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated at...

2026-06-24
CVE-2026-3499
8.8
WordPress is vulnerable

The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in v...

2026-04-08
CVE-2026-34986
7.5
LG field indicates

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (...

2026-04-07
CVE-2026-34982
8.2
Unknown Multiple Products

Vim is an open source, command line text editor

2026-04-07
CVE-2026-34976
Analyzed
10
Dgraph Dgraph

Dgraph contains an unauthenticated admin mutation, allowing attackers to overwrite databases, read sensitive files, and perform SSRF attacks.

2026-04-07
CVE-2026-34975
8.5
AWS SES

Plunk is an open-source email platform built on top of AWS SES

2026-04-07
CVE-2026-34965
8.8
HP code into

Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticat...

2026-04-30
CVE-2026-34963
Analyzed
8.4
Unknown Multiple Products

barebox version prior to 2026

2026-05-12
CVE-2026-34955
Analyzed
8.8
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34954
Analyzed
8.6
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34953
Analyzed
9.1
Microsoft system

A critical authentication bypass in PraisonAI's OAuthManager allows unauthenticated attackers to gain full access to all registered tools and agent ca...

2026-04-04
CVE-2026-34952
Analyzed
9.1
Microsoft system

PraisonAI Gateway prior to 4.5.97 lacks authentication for WebSocket and info endpoints. Attackers can enumerate AI agents and send arbitrary messages...

2026-04-04
CVE-2026-34950
Analyzed
9.1
LG fast-jwt

The fast-jwt library is vulnerable to an algorithm confusion attack due to a flawed regex implementation that fails to properly sanitize leading white...

2026-04-07
CVE-2026-34938
Analyzed
10
Microsoft system

PraisonAI agents prior to 1.5.90 contain a sandbox bypass in the execute_code() function. Attackers can execute arbitrary OS commands on the host by b...

2026-04-04
CVE-2026-34937
Analyzed
7.8
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34936
Analyzed
7.7
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34935
Analyzed
9.8
Microsoft system

PraisonAI CLI versions 4.5.15 through 4.5.68 are vulnerable to OS command injection via the --mcp argument. The argument is passed to the system shell...

2026-04-04
CVE-2026-34934
Analyzed
9.8
Microsoft system

PraisonAI prior to 4.5.90 is vulnerable to SQL injection in the get_all_user_threads function. Attackers can gain full database access by injecting ma...

2026-04-04
CVE-2026-34930
Analyzed
7.8
Apex Multiple Products

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2026-34929
Analyzed
7.8
Apex Multiple Products

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2026-34928
Analyzed
7.8
Apex Multiple Products

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2026-34927
Analyzed
7.8
Apex Multiple Products

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2026-34926
KEV Analyzed
9.5
Trend Micro Apex One

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability - Active in CISA KEV catalog.

2026-05-22
CVE-2026-34916
Analyzed
8.8
Revive Adserver

A missing validation of user input when saving delivery limitations in Revive Adserver 6

2026-06-24
CVE-2026-34914
Analyzed
8.3
Revive Adserver

A missing sanitisation of user input in the zone-include

2026-06-24
CVE-2026-34911
Analyzed
7.7
Infor Multiple Products

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files...

2026-05-22
CVE-2026-34910
KEV Analyzed
10
Ubiquiti UniFi OS

An improper input validation flaw in Ubiquiti UniFi OS enables network-adjacent attackers to execute arbitrary commands on the underlying system.

2026-05-22
CVE-2026-34909
KEV Analyzed
10
Ubiquiti UniFi OS

A path traversal vulnerability in Ubiquiti UniFi OS allows network-adjacent attackers to read sensitive system files and potentially compromise user a...

2026-05-22
CVE-2026-34908
KEV Analyzed
10
Ubiquiti UniFi OS

An improper access control vulnerability in Ubiquiti UniFi OS devices allows network-adjacent attackers to modify system configurations without author...

2026-05-22
CVE-2026-34901
Analyzed
9.8
WordPress iControlWP

iControlWP contains an unauthenticated privilege escalation vulnerability that allows remote attackers to gain elevated access to the system.

2026-06-16
CVE-2026-3490
Analyzed
10
Unknown picklescan

A security bypass in the picklescan library allows attackers to resolve dangerous functions through indirect calls, leading to remote code execution.

2026-06-18
CVE-2026-3489
7.5
WordPress is vulnerable

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in...

2026-04-17