23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 7201-7250 of 23295 CVEs Page 145 of 466
CVE-2026-4213
Analyzed
8.8
D-Link DNS

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-32...

2026-03-17
CVE-2026-42129
Analyzed
7.7
Grafana Loki Datasource Plugin

The Loki datasource plugin's callResource handler contains a path traversal vulnerability

2026-06-23
CVE-2026-42127
Analyzed
7.5
Grafana Grafana Enterprise

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory...

2026-06-23
CVE-2026-4212
Analyzed
8.8
D-Link DNS

A security vulnerability has been detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, D...

2026-03-17
CVE-2026-4211
Analyzed
8.8
D-Link DNS

A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-...

2026-03-17
CVE-2026-42097
Analyzed
8.8
Sparx Systems Pro Cloud Server

Sparx Pro Cloud Server requires authentication based on requested URL

2026-06-03
CVE-2026-42096
Analyzed
8.8
Sparx Systems Pro Cloud Server

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database

2026-06-03
CVE-2026-42090
Analyzed
9.6
Apple Multiple Products

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android...

2026-05-05
CVE-2026-42089
Analyzed
8.6
Yeoman Environment

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved

2026-06-17
CVE-2026-42088
Analyzed
9.6
Docker database

A vulnerability in the OpenC3 COSMOS Script Runner widget allows authenticated users to bypass permissions and perform administrative actions on Redis...

2026-05-05
CVE-2026-42087
Analyzed
9.6
OpenC3 COSMOS

A SQL injection vulnerability in the OpenC3 COSMOS Time-Series Database component allows unauthenticated attackers to execute arbitrary SQL commands.

2026-05-05
CVE-2026-42084
Analyzed
8.1
Unknown Multiple Products

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

2026-05-05
CVE-2026-42083
Analyzed
8.2
Unknown Multiple Products

free5GC is an open-source implementation of the 5G core network

2026-05-29
CVE-2026-42079
Analyzed
8.6
Unknown Multiple Products

PPTAgent is an agentic framework for reflective PowerPoint generation

2026-05-05
CVE-2026-42076
Analyzed
9.8
Unknown Multiple Products

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function...

2026-05-05
CVE-2026-42075
Analyzed
8.1
Unknown Multiple Products

Evolver is a GEP-powered self-evolving engine for AI agents

2026-05-05
CVE-2026-42072
Analyzed
9.8
Arch Nornicdb

Nornicdb fails to bind the Bolt server to the configured host, defaulting to all interfaces and exposing the database with default credentials to the...

2026-05-09
CVE-2026-42062
Analyzed
9.8
ELECOM Wireless LAN Access Point

ELECOM wireless LAN access points are vulnerable to OS command injection via the username parameter, allowing unauthenticated remote code execution.

2026-05-14
CVE-2026-42048
Analyzed
9.6
Unknown Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowled...

2026-05-13
CVE-2026-42047
Analyzed
8.6
Infor Multiple Products

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration

2026-05-08
CVE-2026-42046
Analyzed
7.8
Unknown Multiple Products

libcaca is a colour ASCII art library

2026-05-12
CVE-2026-42043
Analyzed
7.2
HTTP Multiple Products

Axios is a promise based HTTP client for the browser and Node

2026-04-25
CVE-2026-42035
Analyzed
7.4
HTTP Multiple Products

Axios is a promise based HTTP client for the browser and Node

2026-04-25
CVE-2026-42033
Analyzed
7.4
HTTP Multiple Products

Axios is a promise based HTTP client for the browser and Node

2026-04-25
CVE-2026-42017
Analyzed
8.8
JFrog Artifactory

An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions

2026-07-28
CVE-2026-42016
Analyzed
8.1
JFrog Artifactory

JFrog Artifactory (Self Hosted) versions before 7

2026-07-28
CVE-2026-4201
Analyzed
7.3
Infor Multiple Products

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393

2026-03-17
CVE-2026-42009
Analyzed
7.5
GnuTLS GnuTLS

A flaw was found in gnutls

2026-05-19
CVE-2026-42001
Analyzed
7.5
Insufficient Multiple Products

Insufficient Validation of Autoprimary SOA Queries

2026-05-22
CVE-2026-4200
Analyzed
7.3
Unknown Multiple Products

A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393

2026-03-17
CVE-2026-41964
Analyzed
8.4
Unknown Multiple Products

Permission control vulnerability in the web

2026-05-15
CVE-2026-41957
Analyzed
8.8
Unknown Multiple Products

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility

2026-05-14
CVE-2026-41953
Analyzed
8.7
Unknown Multiple Products

A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify co...

2026-05-14
CVE-2026-41952
Analyzed
7.8
Acronis DeviceLock DLP

Local privilege escalation due to improper input validation

2026-04-30
CVE-2026-41951
Analyzed
7.2
Path Multiple Products

Path traversal vulnerability exists in GROWI v7

2026-05-12
CVE-2026-41948
Analyzed
7.7
Dify Multiple Products

Dify version 1

2026-05-19
CVE-2026-41947
Analyzed
7.4
Dify Multiple Products

Dify version 1

2026-05-19
CVE-2026-41940
KEV Analyzed
9.8
Unknown cPanel and WHM

An authentication bypass vulnerability in the cPanel and WHM login flow allows unauthenticated remote attackers to gain unauthorized access to the con...

2026-04-30
CVE-2026-4194
Analyzed
7.3
D-Link DNS

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-32...

2026-03-17
CVE-2026-41939
Analyzed
9.8
Care Everywhere Care Everywhere Gateway

Care Everywhere Gateway 14.3.10 is vulnerable to remote code execution due to hard-coded credentials in the bundled WildFly management interface, allo...

2026-07-30
CVE-2026-41938
Analyzed
8.8
HP handler

Vvveb before version 1

2026-05-07
CVE-2026-41936
Analyzed
8.1
HP to inject

Vvveb before version 1

2026-05-07
CVE-2026-41934
Analyzed
8.8
HP handler

Vvveb before version 1

2026-05-07
CVE-2026-41930
Analyzed
9.8
HP Vvveb

Vvveb contains hard-coded credentials in its docker-compose-apache.yaml configuration, allowing unauthenticated remote access to the bundled phpMyAdmi...

2026-05-07
CVE-2026-4193
Analyzed
7.3
D-Link DIR

A security vulnerability has been detected in D-Link DIR-823G 1

2026-03-17
CVE-2026-41919
Analyzed
9.1
Apache OFBiz

Apache OFBiz is susceptible to LDAP injection, enabling attackers to manipulate LDAP queries through unsanitized user input.

2026-05-20
CVE-2026-41914
Analyzed
8.5
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-29
CVE-2026-41912
Analyzed
7.6
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-29
CVE-2026-4191
Analyzed
7.3
Unknown Multiple Products

A flaw has been found in JawherKl node-api-postgres up to 2

2026-03-17
CVE-2026-41905
Analyzed
7.7
HP Multiple Products

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework

2026-05-09