21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 6351-6400 of 21637 CVEs Page 128 of 433
CVE-2026-40061
Analyzed
8.7
Unknown Multiple Products

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenti...

2026-05-14
CVE-2026-40050
Analyzed
9.8
CrowdStrike LogScale

A critical unauthenticated path traversal vulnerability in CrowdStrike LogScale allows remote attackers to read arbitrary files from the server filesy...

2026-04-22
CVE-2026-40048
7.8
Apache Camel

The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>

2026-04-28
CVE-2026-40047
Analyzed
9.1
Apache Apache Camel

An argument injection vulnerability in the Apache Camel Docling component allows attackers to inject malicious CLI flags and perform directory travers...

2026-07-07
CVE-2026-40046
7.5
Apache ActiveMQ

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT

2026-04-11
CVE-2026-40044
Analyzed
9.8
HP object payloads

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialize...

2026-04-14
CVE-2026-40042
Analyzed
9.8
Pachno Multiple Products

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsaf...

2026-04-14
CVE-2026-40040
8.8
HP Multiple Products

Pachno 1

2026-04-14
CVE-2026-40038
7.2
Pachno Multiple Products

Pachno 1

2026-04-14
CVE-2026-40036
7.5
Unfurl Multiple Products

Unfurl before 2026

2026-04-10
CVE-2026-40035
Analyzed
9.1
Infor Unfurl

Unfurl contains an improper input validation vulnerability in configuration parsing that enables Flask debug mode by default, potentially leading to r...

2026-04-09
CVE-2026-40033
Analyzed
8.8
FreeRDP FreeRDP

FreeRDP before 3

2026-05-27
CVE-2026-40032
7.8
Unknown Multiple Products

UAC (Unix-like Artifacts Collector) before 3

2026-04-09
CVE-2026-40031
7.8
IBM Multiple Products

MemProcFS before 5

2026-04-09
CVE-2026-40030
7.8
Unknown Multiple Products

parseusbs before 1

2026-04-09
CVE-2026-4003
Analyzed
9.8
WordPress is vulnerable

The Users manager – PN WordPress plugin contains a privilege escalation flaw allowing unauthenticated attackers to modify arbitrary user metadata.

2026-04-08
CVE-2026-40029
7.8
Unknown Multiple Products

parseusbs before 1

2026-04-09
CVE-2026-40022
8.2
Apache Camel embedded

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root contex...

2026-04-28
CVE-2026-40010
Analyzed
9.1
Apache Wicket

Apache Wicket fails to invoke the changeSessionId method after session binding, exposing the application to session fixation attacks.

2026-05-07
CVE-2026-4001
Analyzed
9.8
HP is vulnerable

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to unauthenticated Remote Code Execution (RCE) via the PHP eval() functio...

2026-03-24
CVE-2026-40008
Analyzed
9.8
Apache IoTDB

Apache IoTDB versions 1.0.0 through 2.0.9 are vulnerable to unsafe reflection via the pipe processor, which fails to validate externally controlled Ja...

2026-07-11
CVE-2026-40007
Analyzed
7.5
Apache Apache IoTDB

Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap rec...

2026-07-14
CVE-2026-40006
Analyzed
7.5
Apache Apache IoTDB

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulner...

2026-07-13
CVE-2026-40005
Analyzed
9.1
Apache IoTDB

A path traversal vulnerability in Apache IoTDB allows unauthenticated attackers to write arbitrary files to the filesystem by leveraging an unsafe API...

2026-07-11
CVE-2026-3999
Analyzed
8.8
Unknown Multiple Products

A broken access control may allow an authenticated user to perform a horizontal privilege escalation

2026-06-09
CVE-2026-39987
KEV
9.5
Marimo Marimo

Marimo Remote Code Execution Vulnerability - Active in CISA KEV catalog.

2026-04-24
CVE-2026-39983
8.6
FTP Multiple Products

basic-ftp is an FTP client for Node

2026-04-10
CVE-2026-39981
8.8
Unknown Multiple Products

AGiXT is a dynamic AI Agent Automation Platform

2026-04-10
CVE-2026-39980
Analyzed
9.1
Intel OpenCTI

OpenCTI prior to 6.9.5 contains an EJS template injection vulnerability allowing authenticated users with Manage customization capabilities to execute...

2026-04-10
CVE-2026-39974
Analyzed
8.5
Oracle Multiple Products

n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and oper...

2026-04-10
CVE-2026-39973
7.1
Google Multiple Products

Apktool is a tool for reverse engineering Android APK files

2026-04-21
CVE-2026-39955
Analyzed
9.8
HP Cacti

The Cacti performance management framework is vulnerable to a pre-authentication SQL injection via an improperly validated input parameter in graph_vi...

2026-06-25
CVE-2026-39948
Analyzed
9.3
HP Cacti

An SQL injection vulnerability in Cacti allows unauthenticated attackers to execute arbitrary database commands via the rfilter parameter in graph_vie...

2026-06-25
CVE-2026-39942
8.5
Unknown Multiple Products

Directus is a real-time API and App dashboard for managing SQL database content

2026-04-10
CVE-2026-39938
Analyzed
9.8
Cacti Cacti

Cacti versions 1.2.30 and prior contain an unauthenticated Local File Inclusion (LFI) vulnerability via the graph_theme parameter, potentially allowin...

2026-06-25
CVE-2026-39932
Analyzed
9.1
Unknown openemr

OpenEMR contains a remote code execution vulnerability via eval injection in the CategoryTree component, allowing authenticated administrators to exec...

2026-08-04
CVE-2026-39923
Analyzed
8.1
Flarum Flarum Framework

Flarum before 1

2026-08-06
CVE-2026-39920
Analyzed
9.8
Apache Multiple Products

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with...

2026-04-25
CVE-2026-39918
Analyzed
9.8
HP configuration file

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized int...

2026-04-21
CVE-2026-39912
Analyzed
9.1
V2Board Multiple Products

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the l...

2026-04-10
CVE-2026-39911
8.8
Unknown Multiple Products

Hashgraph Guardian through version 3

2026-04-10
CVE-2026-39910
Analyzed
9.8
STACKIT IaaS API

A missing authorization check in the STACKIT IaaS API allows low-privileged users to escalate privileges to full organization compromise.

2026-06-09
CVE-2026-3991
7.8
Microsoft Data Loss

Symantec Data Loss Prevention Windows Endpoint, prior to 25

2026-03-31
CVE-2026-39893
Analyzed
9.8
Cacti Cacti

A SQL injection vulnerability exists in Cacti versions 1.2.30 and prior, where the rfilter parameter is unsafely concatenated into an RLIKE clause, re...

2026-06-25
CVE-2026-39891
8.8
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-09
CVE-2026-39890
Analyzed
9.8
Microsoft system

PraisonAI versions prior to 4.5.115 are vulnerable to RCE via insecure YAML parsing, allowing execution of arbitrary JavaScript.

2026-04-09
CVE-2026-39889
7.5
Microsoft system

PraisonAI is a multi-agent teams system

2026-04-10
CVE-2026-39888
Analyzed
9.9
Microsoft system

PraisonAI versions prior to 1.5.115 contain a sandbox escape vulnerability in its Python code execution tool, allowing arbitrary code execution.

2026-04-09
CVE-2026-39885
7.5
Unknown Multiple Products

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

2026-04-10
CVE-2026-39884
8.3
Kubernetes is

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management

2026-04-16