23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 6501-6550 of 23295 CVEs Page 131 of 466
CVE-2026-45214
Analyzed
8.5
Xpro Xpro Elementor Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons...

2026-05-13
CVE-2026-45211
Analyzed
8.5
Saad Iqbal APIExperts Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woo...

2026-05-13
CVE-2026-45208
Analyzed
7.8
Apex Multiple Products

A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2026-45207
Analyzed
7.8
Apex Multiple Products

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2026-45206
Analyzed
7.8
Apex Multiple Products

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations

2026-05-22
CVE-2026-45203
Analyzed
7.8
Imagination Graphics DDK

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted...

2026-07-16
CVE-2026-45198
Analyzed
7.8
Imagination Technologies Graphics DDK

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using d...

2026-08-27
CVE-2026-45196
Analyzed
7.8
Imagination Graphics DDK

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead...

2026-07-16
CVE-2026-45195
Analyzed
7.8
Imagination Graphics DDK

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the pe...

2026-06-27
CVE-2026-45185
Analyzed
9.8
Exim Multiple Products

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a cl...

2026-05-13
CVE-2026-45162
Analyzed
8
Pimcore Pimcore

Pimcore is an Open Source Data & Experience Management Platform

2026-07-18
CVE-2026-45137
Analyzed
8.2
Unknown Multiple Products

Anchor is a framework providing several convenient developer tools for writing Solana programs

2026-05-29
CVE-2026-45135
Analyzed
8.1
Caddy Caddy Server

Caddy is an extensible server platform that uses TLS by default

2026-06-24
CVE-2026-45132
Analyzed
10
GitHub Open Source Helm Charts

A GitHub Actions workflow in CloudPirates Helm Charts exposes Personal Access Tokens and SSH signing keys to untrusted code.

2026-06-02
CVE-2026-45131
Analyzed
10
GitHub Open Source Helm Charts

A GitHub Actions workflow in CloudPirates Helm Charts executes attacker-controlled code from forks, exposing repository secrets.

2026-06-02
CVE-2026-45108
Analyzed
8.4
Microsoft Azure Entra

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune

2026-05-29
CVE-2026-45102
Analyzed
9.9
OneUptime OneUptime

OneUptime is vulnerable to a sandbox escape in its Node.js environment due to the improper use of the vm module.

2026-05-28
CVE-2026-45091
Analyzed
9.1
Unknown sealed-env

The sealed-env library incorrectly embeds literal TOTP secrets in unencrypted JWS payloads, allowing unauthorized parties to extract sensitive credent...

2026-05-13
CVE-2026-45089
Analyzed
8.2
Unknown Multiple Products

Dalfox is a powerful open-source XSS scanner and utility focused on automation

2026-05-29
CVE-2026-45087
Analyzed
10
Dalfox Dalfox

Dalfox contains an unauthenticated remote code execution vulnerability in its REST API server mode due to insecure deserialization of scan options.

2026-05-28
CVE-2026-45084
Analyzed
8.7
OpenSIPS opensips

OpenSIPS is a Session Initiation Protocol (SIP) server implementation

2026-08-05
CVE-2026-4508
Analyzed
7.3
HP of the

A vulnerability was identified in PbootCMS up to 3

2026-03-22
CVE-2026-45071
Analyzed
8.7
HP Symfony

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

2026-07-15
CVE-2026-45069
Analyzed
8.8
HP Symfony

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

2026-07-15
CVE-2026-45068
Analyzed
8.7
HP Symfony

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

2026-07-15
CVE-2026-45060
Analyzed
9.8
HP ClipBucket

The ClipBucket video sharing platform is vulnerable to unauthenticated blind SQL injection, allowing attackers to execute unauthorized database querie...

2026-06-12
CVE-2026-4504
Analyzed
7.3
Unknown Multiple Products

A flaw has been found in eosphoros-ai db-gpt up to 0

2026-03-22
CVE-2026-45039
Analyzed
9.8
RustFS Distributed Object Storage System

RustFS uses a hardcoded default secret key for internode RPC authentication, allowing attackers to bypass security if the environment is not explicitl...

2026-05-29
CVE-2026-45037
Analyzed
7.1
ABB Multiple Products

Tabby (formerly Terminus) is a highly configurable terminal emulator

2026-05-17
CVE-2026-45036
Analyzed
7
ABB Multiple Products

Tabby (formerly Terminus) is a highly configurable terminal emulator

2026-05-17
CVE-2026-45034
Analyzed
9.2
Microsoft PhpSpreadsheet

An input validation flaw in PhpSpreadsheet allows attackers to bypass wrapper protections, leading to potential Remote Code Execution (RCE) via phar d...

2026-06-23
CVE-2026-4503
Analyzed
7.5
IBM Langflow Desktop

IBM Langflow Desktop 1

2026-05-01
CVE-2026-45018
Analyzed
9.8
Chainlit chainlit

Chainlit versions 2.4.0rc0 through 2.11.x are vulnerable to unauthenticated OS command injection via the MCP endpoint when features.mcp.enabled is tru...

2026-08-26
CVE-2026-45013
Analyzed
8.1
Intel ApostropheCMS

ApostropheCMS is an open-source Node

2026-06-14
CVE-2026-45010
Analyzed
9.1
HP phpMyFAQ

phpMyFAQ lacks rate limiting on its TOTP authentication endpoint, allowing unauthenticated attackers to brute-force two-factor authentication tokens.

2026-05-16
CVE-2026-45006
Analyzed
8.8
OpenClaw Multiple Products

OpenClaw before 2026

2026-05-12
CVE-2026-45004
Analyzed
7.8
OpenClaw Multiple Products

OpenClaw before 2026

2026-05-12
CVE-2026-45001
Analyzed
7.1
OpenClaw Multiple Products

OpenClaw before 2026

2026-05-12
CVE-2026-44995
Analyzed
7.3
OpenClaw Multiple Products

OpenClaw before 2026

2026-05-12
CVE-2026-44990
Analyzed
9.3
ApostropheCMS sanitize-html

The sanitize-html library contains a sanitizer bypass vulnerability that can lead to stored XSS in applications rendering user-controlled content.

2026-06-13
CVE-2026-4499
Analyzed
7.3
D-Link DIR

A vulnerability was determined in D-Link DIR-820LW 2

2026-03-22
CVE-2026-44988
Analyzed
8.8
VNC Multiple Products

LibVNCClient is a library for easy implementation of a VNC client

2026-05-28
CVE-2026-44986
Analyzed
9.9
Intel Penpot

Penpot contains an authentication bypass vulnerability that allows registered users to hijack arbitrary accounts by manipulating invitation flows and...

2026-07-16
CVE-2026-44981
Analyzed
8.2
CrowdSecurity CrowdSec

CrowdSec offers crowdsourced protection against malicious IPs

2026-07-17
CVE-2026-4498
Analyzed
7.7
Arch RBAC scope

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elastics...

2026-04-09
CVE-2026-44974
Analyzed
7.7
Unknown content

@hapi/content provided HTTP Content-* headers parsing

2026-07-18
CVE-2026-44971
Analyzed
8.2
GitHub credentials with

GuardDog is a CLI tool to identify malicious PyPI packages

2026-05-29
CVE-2026-4497
Analyzed
7.3
TOTOLINK Multiple Products

A vulnerability was determined in Totolink WA300 5

2026-03-22
CVE-2026-44966
Analyzed
8.3
Shepherdwind Velocity.js

Velocity

2026-06-04
CVE-2026-44962
Analyzed
9.9
Arch functionality

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XP...

2026-05-30