21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 6251-6300 of 21637 CVEs Page 126 of 433
CVE-2026-40471
Analyzed
9.6
Unknown Multiple Products

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage se...

2026-04-24
CVE-2026-40470
Analyzed
9.9
Haskell.org Hackage Server

A Cross-Site Scripting (XSS) vulnerability in the Hackage server allows an attacker to hijack user sessions by serving malicious JavaScript via upload...

2026-04-24
CVE-2026-40466
8.8
Apache ActiveMQ Broker

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apa...

2026-04-25
CVE-2026-40461
7.5
Anviz Multiple Products

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e

2026-04-18
CVE-2026-4046
Analyzed
7.5
IBM C Library (glibc)

The iconv() function in the GNU C Library versions 2

2026-03-31
CVE-2026-40454
Analyzed
7.5
Apache Apache IoTDB C++ client

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer c...

2026-07-14
CVE-2026-40453
Analyzed
9.9
Google Camel

Improper header filtering in Apache Camel allows attackers to inject case-variant headers, leading to remote code execution and arbitrary file writes.

2026-04-28
CVE-2026-40452
Analyzed
7.5
Apache Apache IoTDB

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data...

2026-07-14
CVE-2026-40436
7.1
ZTE Multiple Products

The ZTE ZXEDM iEMS product has a password reset vulnerability for any user

2026-04-13
CVE-2026-40434
8.1
Unknown Multiple Products

Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to...

2026-04-18
CVE-2026-4043
8.8
Tenda i12

A security vulnerability has been detected in Tenda i12 1

2026-03-13
CVE-2026-40420
Analyzed
8.8
Microsoft Office Click

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally

2026-05-13
CVE-2026-4042
8.8
Tenda i12

A weakness has been identified in Tenda i12 1

2026-03-13
CVE-2026-40415
Analyzed
8.1
Microsoft Multiple Products

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network

2026-05-13
CVE-2026-4041
8.8
Tenda i12

A security flaw has been discovered in Tenda i12 1

2026-03-13
CVE-2026-40403
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally

2026-05-13
CVE-2026-40402
Analyzed
9.3
Microsoft Windows Hyper-V

A use-after-free vulnerability in Windows Hyper-V allows an unauthorized attacker to elevate privileges on the local system.

2026-05-13
CVE-2026-40393
8.1
Mesa Multiple Products

In Mesa before 25

2026-04-13
CVE-2026-4038
Analyzed
9.8
WordPress is vulnerable

The Aimogen Pro plugin for WordPress allows unauthenticated arbitrary function calls. Attackers can exploit this to change the default user role to ad...

2026-03-20
CVE-2026-40379
Analyzed
9.3
Microsoft Entra ID

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

2026-05-13
CVE-2026-40372
Analyzed
9.1
Unknown Multiple Products

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

2026-04-22
CVE-2026-40371
Analyzed
8.8
Microsoft Dynamics 365

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privilege...

2026-06-10
CVE-2026-40370
Analyzed
8.8
Unknown Multiple Products

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network

2026-05-13
CVE-2026-40367
Analyzed
8.4
Microsoft Office Word

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally

2026-05-13
CVE-2026-40366
Analyzed
8.4
Microsoft Office Word

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2026-05-13
CVE-2026-40365
Analyzed
8.8
Microsoft Office SharePoint

Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-05-13
CVE-2026-40364
Analyzed
8.4
Microsoft Office Word

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally

2026-05-13
CVE-2026-40363
Analyzed
8.4
Microsoft Office allows

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2026-05-13
CVE-2026-40361
Analyzed
8.4
Microsoft Office Word

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2026-05-13
CVE-2026-40358
Analyzed
8.4
Microsoft Office allows

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2026-05-13
CVE-2026-40357
Analyzed
8.8
Microsoft Office SharePoint

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-05-13
CVE-2026-40352
8.8
MongoDB query operators

FastGPT is an AI Agent building platform

2026-04-18
CVE-2026-40351
Analyzed
9.8
MongoDB query operator

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runt...

2026-04-18
CVE-2026-40350
8.8
Unknown Multiple Products

Movary is a self hosted web app to track and rate a user's watched movies

2026-04-18
CVE-2026-40349
8.8
Unknown Multiple Products

Movary is a self hosted web app to track and rate a user's watched movies

2026-04-18
CVE-2026-40348
7.7
Unknown Multiple Products

Movary is a self hosted web app to track and rate a user's watched movies

2026-04-18
CVE-2026-40342
Analyzed
9.9
Unknown Multiple Products

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader conc...

2026-04-18
CVE-2026-40324
Analyzed
9.1
Kubernetes Multiple Products

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf...

2026-04-18
CVE-2026-40322
Analyzed
9
SiYuan SiYuan

SiYuan versions 3.6.3 and below are vulnerable to stored XSS in Mermaid diagrams, which can be escalated to arbitrary code execution on Electron-based...

2026-04-17
CVE-2026-40321
8
Microsoft ecosystem

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-04-18
CVE-2026-40318
8.5
Unknown Multiple Products

SiYuan is an open-source personal knowledge management system

2026-04-17
CVE-2026-40317
Analyzed
9.3
Unknown Multiple Products

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary e...

2026-04-18
CVE-2026-40316
8.8
GitHub Multiple Products

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more

2026-04-16
CVE-2026-40313
Analyzed
9.1
Docker Actions workflows

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cred...

2026-04-14
CVE-2026-40303
7.5
Gigabyte Multiple Products

zrok is software for sharing web services, files, and network resources

2026-04-18
CVE-2026-4030
Analyzed
8.1
WordPress plugin for

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and inclu...

2026-05-16
CVE-2026-40291
8.8
PUT Multiple Products

Chamilo LMS is an open-source learning management system

2026-04-15
CVE-2026-40289
Analyzed
9.1
SUSE of model

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser...

2026-04-14
CVE-2026-40288
Analyzed
9.8
Microsoft system

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to a...

2026-04-14
CVE-2026-40287
8.4
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-14