23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 6051-6100 of 23391 CVEs Page 122 of 468
CVE-2026-47645
Analyzed
8.8
Microsoft 365 Copilot Business Chat

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ove...

2026-06-20
CVE-2026-47643
Analyzed
9.8
Microsoft Azure Stack Edge

Azure Stack Edge contains a path traversal vulnerability that allows unauthenticated remote attackers to execute arbitrary code over the network.

2026-06-10
CVE-2026-47635
Analyzed
8.4
Microsoft Office

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally

2026-06-12
CVE-2026-47632
Analyzed
8.8
Microsoft Azure Monitor Agent Metrics Extension

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network

2026-07-15
CVE-2026-47631
Analyzed
8.1
Microsoft Exchange Server

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to p...

2026-06-16
CVE-2026-47623
Analyzed
8.2
NVIDIA Dynamo

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data

2026-08-05
CVE-2026-4758
Analyzed
8.8
WordPress is vulnerable

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfiel...

2026-03-26
CVE-2026-4756
Analyzed
7.8
Google Multiple Products

Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7

2026-03-24
CVE-2026-4755
Analyzed
9.8
Google Android-ImageMagick7

A critical improper input validation vulnerability (CWE-20) in MolotovCherry Android-ImageMagick7 can lead to severe system instability or unauthorize...

2026-03-24
CVE-2026-4753
Analyzed
9.1
Unknown Multiple Products

Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.

2026-03-24
CVE-2026-4750
Analyzed
9.1
Unknown Multiple Products

Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.

2026-03-24
CVE-2026-47483
Analyzed
8.2
NVIDIA DCGM Exporter

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource con...

2026-07-29
CVE-2026-4748
Analyzed
7.5
Unknown Multiple Products

A regression in the way hashes were calculated caused rules containing the address range syntax (x

2026-04-02
CVE-2026-4747
Analyzed
8.8
SAP SAP Software (RPCSEC_GSS implementation)

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet

2026-03-27
CVE-2026-47429
Analyzed
9.8
Microsoft vitest

The Vitest UI/API server is vulnerable to path traversal and arbitrary script execution due to improper path validation on Windows systems.

2026-07-15
CVE-2026-47428
Analyzed
9.6
Unknown vitest

A cross-site scripting vulnerability in Vitest Browser Mode allows attackers to inject malicious JavaScript and steal sensitive API tokens via crafted...

2026-07-15
CVE-2026-4740
Analyzed
8.2
Red Hat Advanced Cluster

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM)

2026-04-08
CVE-2026-47389
Analyzed
8.6
Mastodon Mastodon

Mastodon is a free, open-source social network server based on ActivityPub

2026-06-25
CVE-2026-47387
Analyzed
8.4
NocoDB NocoDB

NocoDB is software for building databases as spreadsheets

2026-06-24
CVE-2026-47373
Analyzed
7.5
Unknown Multiple Products

Crypt::SaltedHash versions through 0

2026-05-22
CVE-2026-47370
Analyzed
9.9
Ubiquiti UniFi OS

Certain Ubiquiti devices running UniFi OS contain an improper input validation vulnerability allowing low-privileged network attackers to execute arbi...

2026-06-12
CVE-2026-47369
Analyzed
9.9
Ubiquiti UniFi OS

Certain Ubiquiti devices running UniFi OS are susceptible to an improper input validation vulnerability that allows network-based attackers to escalat...

2026-06-12
CVE-2026-47368
Analyzed
8.6
Ubiquiti UniFi OS

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data fro...

2026-06-12
CVE-2026-47367
Analyzed
9.9
Ubiquiti UID Enterprise Agent

The Ubiquiti UID Enterprise Agent contains an improper input validation vulnerability that allows low-privileged network attackers to execute arbitrar...

2026-06-12
CVE-2026-47365
Analyzed
9.9
WordPress WordPress Toolkit

An argument injection vulnerability in WordPress Toolkit allows authenticated users to bypass cross-tenant authorization and execute arbitrary CLI com...

2026-06-12
CVE-2026-47358
Analyzed
7.5
Arch Multiple Products

Terrascan v1

2026-05-20
CVE-2026-47357
Analyzed
7.5
Arch Multiple Products

Terrascan v1

2026-05-20
CVE-2026-47356
Analyzed
7.5
Arch Multiple Products

Terrascan v1

2026-05-20
CVE-2026-47342
Analyzed
8.8
Apache OFBiz

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apac...

2026-06-13
CVE-2026-47314
Analyzed
7.8
Samsung Open Source

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers

2026-05-19
CVE-2026-47311
Analyzed
7.8
Samsung Open Source

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers

2026-05-19
CVE-2026-47310
Analyzed
7.8
Samsung Open Source

Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation

2026-05-19
CVE-2026-47303
Analyzed
8.8
Microsoft .NET

Authentication bypass by assumed-immutable data in ASP

2026-07-15
CVE-2026-47301
Analyzed
8.8
Microsoft Configuration Manager

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-47300
Analyzed
8.8
Microsoft .NET

Incorrect implementation of authentication algorithm in ASP

2026-07-15
CVE-2026-47298
Analyzed
8
Microsoft Office SharePoint

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-06-14
CVE-2026-47295
Analyzed
8.8
Microsoft SQL Server

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2026-07-15
CVE-2026-47291
Analyzed
9.8
Microsoft Windows HTTP.sys

An integer overflow or wraparound vulnerability in the Windows HTTP.sys driver allows unauthorized attackers to execute arbitrary code over a network.

2026-06-10
CVE-2026-47289
Analyzed
8.8
Microsoft Remote Desktop Client

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2026-06-10
CVE-2026-4727
Analyzed
7.5
Unknown Multiple Products

Denial-of-service in the Libraries component in NSS

2026-03-26
CVE-2026-47267
Analyzed
8.3
Intel Gogs

Gogs is an open source self-hosted Git service

2026-06-25
CVE-2026-4726
Analyzed
7.5
Unknown Multiple Products

Denial-of-service in the XML component

2026-03-26
CVE-2026-47255
Analyzed
8.2
Unknown @agenticmail/api and @agenticmail/core

AgenticMail gives AI agents real email addresses and phone numbers

2026-07-21
CVE-2026-4725
Analyzed
10
Mozilla Firefox and Thunderbird

A use-after-free vulnerability in the Graphics: Canvas2D component of Mozilla Firefox and Thunderbird enables a critical sandbox escape.

2026-03-25
CVE-2026-47249
Analyzed
7.5
Klever Klever-Go

Klever-Go is the Go implementation of the Klever blockchain protocol

2026-08-09
CVE-2026-4723
Analyzed
9.8
Mozilla Firefox and Thunderbird

A use-after-free vulnerability in the JavaScript Engine of Mozilla Firefox and Thunderbird allows for critical remote code execution.

2026-03-25
CVE-2026-47220
Analyzed
7.5
Envoy Proxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications

2026-06-28
CVE-2026-4722
Analyzed
8.8
Privilege Multiple Products

Privilege escalation in the IPC component

2026-03-25
CVE-2026-47211
Analyzed
8.4
Q00 ouroboros

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior

2026-08-04
CVE-2026-47210
Analyzed
9.8
Unknown vm2

The vm2 sandbox for Node.js is vulnerable to a sandbox escape that allows arbitrary code execution in the host process when using WebAssembly JSPI.

2026-06-13