21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 6501-6550 of 21637 CVEs Page 131 of 433
CVE-2026-3917
Analyzed
8.8
Google Chrome prior

Use after free in Agents in Google Chrome prior to 146

2026-03-13
CVE-2026-3915
Analyzed
8.8
Google Chrome prior

Heap buffer overflow in WebML in Google Chrome prior to 146

2026-03-13
CVE-2026-3914
8.8
Google Chrome prior

Integer overflow in WebML in Google Chrome prior to 146

2026-03-13
CVE-2026-3913
Analyzed
8.8
Google Chrome prior

Heap buffer overflow in WebML in Google Chrome prior to 146

2026-03-13
CVE-2026-39118
Analyzed
8.4
Iru, Inc Kandji Agent

An issue in Iru, Inc Kandji Agent before v

2026-06-17
CVE-2026-39111
7.5
HP Multiple Products

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1

2026-04-21
CVE-2026-39110
8.2
HP Multiple Products

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1

2026-04-21
CVE-2026-39109
Analyzed
9.4
HP Multiple Products

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the log...

2026-04-21
CVE-2026-3910
KEV Analyzed
8.8
Google Chrome prior

Inappropriate implementation in V8 in Google Chrome prior to 146

2026-03-14
CVE-2026-3909
KEV Analyzed
8.8
Google Chrome prior

Out of bounds write in Skia in Google Chrome prior to 146

2026-03-14
CVE-2026-39087
Analyzed
9.8
Ntfy ntfy.sh

A vulnerability in the `parseActions` function of ntfy.sh allows remote attackers to execute arbitrary code.

2026-04-24
CVE-2026-39079
Analyzed
7.5
PrestaShop upsshipping all

An issue in prestashop upsshipping all versions through at least 2

2026-05-19
CVE-2026-39054
Analyzed
7.3
Oinone Multiple Products

Oinone Pamirs 7

2026-05-17
CVE-2026-39047
Analyzed
7.5
EPSON L14150 FL27PB

Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TC...

2026-05-22
CVE-2026-39042
Analyzed
7.5
MikroTik RouterOS

An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of...

2026-07-17
CVE-2026-3902
7.5
Unknown Multiple Products

An issue was discovered in 6

2026-04-09
CVE-2026-38991
8.8
HP file extension

Cockpit 2

2026-04-30
CVE-2026-38976
Analyzed
7.5
GitHub mrubyc

mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level...

2026-07-11
CVE-2026-38934
8.8
HP Multiple Products

Cross Site Request Forgery vulnerability in diskoverdata diskover-community v

2026-04-28
CVE-2026-3893
Analyzed
9.4
Carlson VASCO-B GNSS Receiver

The Carlson VASCO-B GNSS Receiver lacks authentication, allowing unauthenticated attackers to modify configurations and operational functions.

2026-04-29
CVE-2026-3891
Analyzed
9.8
WordPress is vulnerable

The Pix for WooCommerce WordPress plugin (up to 1.5.0) is vulnerable to unauthenticated arbitrary file uploads due to missing capability checks and fi...

2026-03-14
CVE-2026-3888
7.8
Linux allows local

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tm...

2026-03-18
CVE-2026-38807
Analyzed
8.8
Unknown Multiple Products

Insecure Permissions vulnerability in kvf-admin v1

2026-05-29
CVE-2026-3880
7.3
Microsoft Exchange Reporter

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report

2026-04-05
CVE-2026-3879
7.3
Microsoft Exchange Reporter

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report

2026-04-05
CVE-2026-38765
Analyzed
7.8
GitHub Protegent 360

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

2026-08-01
CVE-2026-38764
7.8
Unknown Multiple Products

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

2026-08-14
CVE-2026-38755
7.5
Unknown Multiple Products

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cra...

2026-07-21
CVE-2026-38754
7.5
Unknown Multiple Products

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a craf...

2026-07-21
CVE-2026-38753
7.5
Unknown Multiple Products

A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a craf...

2026-07-21
CVE-2026-38752
Analyzed
7.5
BusyBox BusyBox

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying...

2026-07-21
CVE-2026-38751
7.2
HP Multiple Products

OpenSTAManager version 2

2026-05-06
CVE-2026-3873
7.2
Avantra Multiple Products

Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs

2026-03-15
CVE-2026-38728
Analyzed
7.5
Unknown Multiple Products

An issue in Nodemailer smtp_server before v

2026-05-17
CVE-2026-3872
Analyzed
7.3
Red Hat Keycloak

A flaw was found in Keycloak

2026-04-04
CVE-2026-38707
Analyzed
9.8
InHand Networks IR302, IR305, IR315, and IR615

A command injection vulnerability in the IPSec VPN feature of various InHand Networks devices allows remote unauthenticated attackers to execute arbit...

2026-05-29
CVE-2026-38704
Analyzed
9.8
InHand Networks IR302, IR305, IR315, and IR615

A command injection vulnerability in the WireGuard VPN feature of various InHand Networks devices allows remote unauthenticated attackers to execute a...

2026-05-29
CVE-2026-38703
Analyzed
9.8
InHand Networks Industrial Routers (IR302, IR305, IR315, IR615)

A command injection vulnerability in the ZeroTier VPN feature of InHand Networks industrial routers allows remote attackers to gain root privileges.

2026-05-29
CVE-2026-38702
Analyzed
9.8
InHand Networks Industrial Routers (IR302, IR305, IR315, IR615)

A command injection vulnerability in the Admin Access feature of InHand Networks industrial routers allows remote attackers to gain root privileges.

2026-05-29
CVE-2026-38651
8.2
Unknown Multiple Products

Authentication Bypass vulnerability exists in Netmaker versions prior to 1

2026-04-29
CVE-2026-38581
Analyzed
9.8
HP thaipalliative_lte

A SQL injection vulnerability in thaipalliative_lte allows remote attackers to execute arbitrary SQL commands via unsanitized input in the idFormMain...

2026-06-12
CVE-2026-3857
8.1
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17

2026-03-26
CVE-2026-38568
Analyzed
8.1
Unknown Multiple Products

HireFlow v1

2026-05-12
CVE-2026-38566
Analyzed
8.1
Unknown Multiple Products

HireFlow v1

2026-05-13
CVE-2026-38532
8.1
HP endpoint of

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController

2026-04-15
CVE-2026-38530
8.1
HP endpoint of

A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController

2026-04-15
CVE-2026-38529
8.8
HP endpoint of

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController

2026-04-15
CVE-2026-38527
8.5
Unknown Multiple Products

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2

2026-04-15
CVE-2026-38526
Analyzed
9.9
HP file

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arb...

2026-04-15
CVE-2026-3847
8.8
Unknown Multiple Products

Memory safety bugs present in Firefox 148

2026-03-11