21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 6651-6700 of 21637 CVEs Page 134 of 433
CVE-2026-3700
8.8
UTT Multiple Products

A weakness has been identified in UTT HiPER 810G up to 1

2026-03-08
CVE-2026-3699
8.8
UTT Multiple Products

A security flaw has been discovered in UTT HiPER 810G up to 1

2026-03-08
CVE-2026-3698
8.8
UTT Multiple Products

A vulnerability was identified in UTT HiPER 810G up to 1

2026-03-08
CVE-2026-36960
8.8
Unknown Multiple Products

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1

2026-05-01
CVE-2026-3696
7.3
TOTOLINK Multiple Products

A vulnerability was found in Totolink N300RH 6

2026-03-08
CVE-2026-36959
7.5
Unknown Multiple Products

U-SPEED N300 router V1

2026-05-01
CVE-2026-36958
7.5
Unknown Multiple Products

A denial-of-service vulnerability exists in the U-SPEED N300 V1

2026-05-01
CVE-2026-36957
7.5
Dbit Multiple Products

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1

2026-05-01
CVE-2026-36956
8.8
Unknown Multiple Products

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1

2026-05-01
CVE-2026-3693
Analyzed
7.3
Unknown Multiple Products

A flaw has been found in Shy2593666979 AgentChat up to 2

2026-03-08
CVE-2026-3690
Analyzed
7.4
OpenClaw Canvas

OpenClaw Canvas Authentication Bypass Vulnerability

2026-04-12
CVE-2026-3688
Analyzed
8.1
WordPress WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...

2026-07-09
CVE-2026-36848
Analyzed
7.5
Gigamon GVOS

Gigamon GVOS v5

2026-06-30
CVE-2026-36841
Analyzed
9.8
TOTOLINK N200RE V5

A command injection vulnerability in the TOTOLINK N200RE V5 router allows remote code execution via specifically crafted parameters in the formMapDelD...

2026-04-30
CVE-2026-36837
7.5
TOTOLINK Multiple Products

TOTOLINK A3002RU V3 <= V3

2026-04-30
CVE-2026-36829
Analyzed
9.8
Panabit PAP-XM320

An authentication bypass vulnerability in the Panabit PAP-XM320 embedded HTTP server allows attackers to bypass login requirements via directory trave...

2026-05-20
CVE-2026-36828
Analyzed
8.8
Unknown Multiple Products

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7

2026-05-20
CVE-2026-3679
8.8
Tenda FH451

A vulnerability was identified in Tenda FH451 1

2026-03-08
CVE-2026-3678
8.8
Tenda FH451

A vulnerability was determined in Tenda FH451 1

2026-03-08
CVE-2026-3677
8.8
Tenda FH451

A vulnerability was found in Tenda FH451 1

2026-03-08
CVE-2026-36767
Analyzed
10
Unknown Shopizer

A path traversal vulnerability in Shopizer v3.2.5 allows remote attackers to write arbitrary files to any writable path via the image upload endpoint.

2026-05-01
CVE-2026-36760
Analyzed
9.6
JeeSite JeeSite

Authenticated attackers with file upload permissions can exploit a path traversal vulnerability in JeeSite v5.15.1 to upload arbitrary files to the fi...

2026-05-01
CVE-2026-36734
Analyzed
8.8
Unknown Multiple Products

EDIMAX BR-6428nS V3 1

2026-05-13
CVE-2026-36723
Analyzed
8.8
Bookcars Bookcars

An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8

2026-06-11
CVE-2026-36670
Analyzed
8.8
OpenSIPS Control Panel (opensips-cp)

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9

2026-06-17
CVE-2026-36669
9.8
Microsoft Multiple Products

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious...

2026-07-23
CVE-2026-3666
Analyzed
8.8
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2

2026-04-05
CVE-2026-36608
Analyzed
8.8
Mercusys AC12G (EU) V1 Router

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interfa...

2026-06-04
CVE-2026-36607
Analyzed
8.8
Mercusys AC12G (EU) V1 Router

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code...

2026-06-04
CVE-2026-3660
Analyzed
9.8
IBM Engineering Lifecycle Management

IBM Engineering Lifecycle Management allows unauthenticated remote attackers to update server property files, potentially resulting in unauthorized ac...

2026-05-27
CVE-2026-36590
Analyzed
7.5
GitHub NanoMQ

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

2026-07-20
CVE-2026-3658
7.5
WordPress is vulnerable

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' pa...

2026-03-20
CVE-2026-36576
Analyzed
9.8
F5 docker-wkhtmltopdf-aas

An OS command injection vulnerability in the app.py component allows unauthenticated attackers to execute arbitrary commands via a crafted POST reques...

2026-06-04
CVE-2026-3655
Analyzed
9.8
WordPress OTP Login With Phone Number, OTP Verification Plugin

The OTP Login With Phone Number plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers to hijack user account...

2026-05-29
CVE-2026-3643
7.2
WordPress is vulnerable

The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3

2026-04-17
CVE-2026-36425
Analyzed
7.8
GitHub AppRemover

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send...

2026-07-21
CVE-2026-36365
7.8
Unknown Multiple Products

An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via t...

2026-05-06
CVE-2026-36356
Analyzed
9.1
MeiG Smart FORGE_SLT711

The GoAhead web server on MeiG Smart FORGE_SLT711 devices allows unauthenticated remote attackers to perform OS command injection via the /action/SetR...

2026-05-06
CVE-2026-36355
Analyzed
7.7
F5 rtl819x Jungle SDK

The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3

2026-05-06
CVE-2026-36340
8.1
Unknown Multiple Products

An issue in Krayin CRM v

2026-05-01
CVE-2026-3631
7.5
Delta Electronics COMMGR2

Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability

2026-03-09
CVE-2026-3630
Analyzed
9.8
Delta Electronics COMMGR2

Delta Electronics COMMGR2 is affected by a stack-based buffer overflow vulnerability that could lead to arbitrary code execution or system crashes.

2026-03-09
CVE-2026-3629
Analyzed
8.1
WordPress is vulnerable

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1

2026-03-22
CVE-2026-3621
7.5
IBM WebSphere Application

IBM WebSphere Application Server - Liberty 17

2026-04-24
CVE-2026-3614
8.8
WordPress is vulnerable

The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9

2026-04-16
CVE-2026-3611
Analyzed
10
Honeywell IQ4x building

Honeywell IQ4x controllers allow unauthenticated remote attackers to create administrative accounts and take full control of building management syste...

2026-03-13
CVE-2026-3605
8.1
Unknown Multiple Products

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or...

2026-04-17
CVE-2026-36044
Analyzed
8.8
Unknown Multiple Products

@pensar/apex <= 0

2026-05-28
CVE-2026-3599
7.5
WordPress is vulnerable

The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-jso...

2026-04-17
CVE-2026-3596
Analyzed
9.8
WordPress is vulnerable

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin regist...

2026-04-16