21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 6401-6450 of 21637 CVEs Page 129 of 433
CVE-2026-39875
Analyzed
7.8
Apple macOS

A permissions issue was addressed with additional restrictions

2026-07-28
CVE-2026-39874
Analyzed
7.8
Apple macOS

A permissions issue was addressed with additional restrictions

2026-07-28
CVE-2026-39873
9.8
Apple macOS

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting...

2026-08-19
CVE-2026-39863
7.5
Signaling Multiple Products

Kamailio is an open source implementation of a SIP Signaling Server

2026-04-10
CVE-2026-39860
Analyzed
9
Linux and other

A symlink following vulnerability in the Nix package manager allows users to overwrite files and escalate privileges to root in multi-user installatio...

2026-04-09
CVE-2026-39853
7.8
MSI Multiple Products

osslsigncode is a tool that implements Authenticode signing and timestamping

2026-04-10
CVE-2026-39850
Analyzed
7.4
HP application framework

Yii 2 is a PHP application framework

2026-05-22
CVE-2026-3985
Analyzed
7.5
WordPress is vulnerable

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' paramet...

2026-05-20
CVE-2026-39847
Analyzed
9.1
Emmett Emmett

The Emmett web framework is vulnerable to path traversal attacks via the RSGI static handler, allowing unauthorized access to arbitrary files.

2026-04-08
CVE-2026-39846
Analyzed
9
SiYuan SiYuan Desktop Client

SiYuan personal knowledge management system is vulnerable to stored XSS, which can lead to remote code execution in the Electron desktop client.

2026-04-08
CVE-2026-39843
7.7
Unknown Multiple Products

Plane is an an open-source project management tool

2026-04-10
CVE-2026-39842
Analyzed
9.9
Unknown Multiple Products

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine...

2026-04-16
CVE-2026-39836
7.5
Microsoft Multiple Products

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)

2026-05-09
CVE-2026-39822
Analyzed
7.8
Go Go standard library os

On Unix systems, opening a file in an os

2026-07-09
CVE-2026-39820
7.5
Unknown Multiple Products

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations

2026-05-09
CVE-2026-39816
8.8
Apache NiFi

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi...

2026-05-09
CVE-2026-39815
8.8
Fortinet FortiDDoS

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7

2026-04-15
CVE-2026-39813
Analyzed
9.8
Fortinet FortiSandbox

A path traversal vulnerability in Fortinet FortiSandbox allows unauthenticated attackers to achieve privilege escalation via crafted file paths.

2026-04-15
CVE-2026-39808
KEV Analyzed
9.8
Fortinet FortiSandbox

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4....

2026-04-15
CVE-2026-3978
8.8
D-Link DIR

A vulnerability was detected in D-Link DIR-513 1

2026-03-12
CVE-2026-3976
8.8
Tenda W3

A weakness has been identified in Tenda W3 1

2026-03-12
CVE-2026-3975
8.8
Tenda W3

A security flaw has been discovered in Tenda W3 1

2026-03-12
CVE-2026-3974
8.8
Tenda W3

A vulnerability was identified in Tenda W3 1

2026-03-12
CVE-2026-3973
8.8
Tenda W3

A vulnerability was determined in Tenda W3 1

2026-03-12
CVE-2026-3972
8.8
Tenda W3

A vulnerability was found in Tenda W3 1

2026-03-12
CVE-2026-3971
8.8
Tenda i3

A vulnerability has been found in Tenda i3 1

2026-03-12
CVE-2026-3970
8.8
Tenda i3

A flaw has been found in Tenda i3 1

2026-03-12
CVE-2026-39684
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicfo...

2026-04-10
CVE-2026-39623
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife al...

2026-04-10
CVE-2026-39621
8.8
Web Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server

2026-04-10
CVE-2026-39591
Analyzed
9.9
WordPress WP-BusinessDirectory

An arbitrary file upload vulnerability exists in the WP-BusinessDirectory plugin for WordPress, allowing attackers to upload malicious files.

2026-06-16
CVE-2026-39587
Analyzed
8.1
WordPress WP BASE Booking

Unauthenticated Privilege Escalation in WP BASE Booking <= 5

2026-06-16
CVE-2026-39583
Analyzed
9.8
WordPress Ecommerce Delivery

An unauthenticated privilege escalation vulnerability exists in the Datalogics Ecommerce Delivery WordPress plugin, allowing attackers to gain adminis...

2026-06-16
CVE-2026-39581
Analyzed
8.5
WordPress WP Sessions Time Monitoring Full Automatic

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1

2026-06-17
CVE-2026-39579
Analyzed
8.8
WordPress B Blocks

Contributor Privilege Escalation in B Blocks <= 2

2026-06-16
CVE-2026-39532
Analyzed
8.8
HP Events Calendar for GeoDirectory

Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2

2026-06-16
CVE-2026-39531
Analyzed
9.3
WordPress WP Directory Kit

The WP Directory Kit plugin for WordPress is vulnerable to Blind SQL Injection, allowing attackers to extract sensitive database information.

2026-05-22
CVE-2026-3953
8.8
Gosoft Software Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd

2026-05-08
CVE-2026-39502
Analyzed
9.3
WordPress Form Maker

The Form Maker by 10Web plugin for WordPress is vulnerable to unauthenticated SQL injection, allowing attackers to extract information from the databa...

2026-06-16
CVE-2026-39493
Analyzed
9.3
Unknown Simply Schedule Appointments Plugin

An unauthenticated SQL injection vulnerability in the Simply Schedule Appointments plugin allows attackers to extract sensitive database information.

2026-06-16
CVE-2026-39492
Analyzed
9.3
WordPress WP Maps Plugin

The WP Maps plugin for WordPress is vulnerable to unauthenticated SQL injection, enabling attackers to extract sensitive information from the database...

2026-06-16
CVE-2026-39478
Analyzed
8.8
HP Anti-Malware Security and Brute-Force Firewall

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4

2026-06-16
CVE-2026-39474
Analyzed
8.8
HP Post Duplicator

Contributor PHP Object Injection in Post Duplicator <= 3

2026-06-16
CVE-2026-39467
7.2
MetaSlider Responsive Multiple Products

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection

2026-04-21
CVE-2026-39462
8.1
Unknown Multiple Products

A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of cr...

2026-04-24
CVE-2026-39461
Analyzed
8.8
Unknown Multiple Products

libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available

2026-05-22
CVE-2026-39457
7.8
Unknown Multiple Products

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive

2026-05-01
CVE-2026-39454
7.8
SKYSEA Multiple Products

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co

2026-04-21
CVE-2026-3945
7.5
HTTP chunked Multiple Products

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1

2026-03-30
CVE-2026-39441
Analyzed
9.3
WordPress Feed KuantoKusta for WooCommerce

The Feed KuantoKusta for WooCommerce plugin contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databas...

2026-06-16