23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 7401-7450 of 23391 CVEs Page 149 of 468
CVE-2026-41524
Analyzed
8.7
Brave Multiple Products

Brave CMS is an open-source CMS

2026-05-09
CVE-2026-41523
Analyzed
7.5
Unknown vLLM Inference Engine

vLLM is an inference and serving engine for large language models (LLMs)

2026-06-23
CVE-2026-41521
Analyzed
8.2
Neutrinolabs xrdp

xrdp is an open source RDP server

2026-07-21
CVE-2026-41520
Analyzed
7.9
Unknown Multiple Products

Cilium is a networking, observability, and security solution with an eBPF-based dataplane

2026-05-09
CVE-2026-4152
Analyzed
7.8
Unknown Multiple Products

GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2026-04-11
CVE-2026-41512
Analyzed
9.9
NVIDIA garak

ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerabi...

2026-05-09
CVE-2026-4151
Analyzed
7.8
Unknown Multiple Products

GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability

2026-04-11
CVE-2026-41507
Analyzed
9.8
Unknown math-codegen

The math-codegen library is vulnerable to RCE because it injects unsanitized string literals into a new Function body.

2026-05-09
CVE-2026-41505
Analyzed
8.7
Unknown Multiple Products

RELATE is a web-based courseware package

2026-05-08
CVE-2026-41501
Analyzed
9.8
Linux electerm

A command injection vulnerability exists in electerm prior to version 3.3.8, where remote version strings are unsafely passed to system commands.

2026-05-08
CVE-2026-41500
Analyzed
9.8
GitHub Electerm

A command injection vulnerability in Electerm allows attackers to execute arbitrary code by supplying a malicious release name.

2026-05-08
CVE-2026-4150
Analyzed
7.8
Unknown Multiple Products

GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability

2026-04-11
CVE-2026-41497
Analyzed
9.8
Microsoft system

PraisonAI fails to validate commands in parse_mcp_command(), allowing unauthenticated attackers to execute arbitrary system commands via subprocesses.

2026-05-09
CVE-2026-41496
Analyzed
8.1
Microsoft system

PraisonAI is a multi-agent teams system

2026-05-09
CVE-2026-41492
Analyzed
9.8
Unknown Multiple Products

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/va...

2026-04-25
CVE-2026-41491
Analyzed
8.1
Unknown Multiple Products

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge

2026-05-09
CVE-2026-41490
Analyzed
8.3
Delta Multiple Products

Dagster is an orchestration platform for the development, production, and observation of data assets

2026-05-08
CVE-2026-4149
Analyzed
10
Sonos Era Era 300

The Sonos Era 300 is vulnerable to remote code execution due to an out-of-bounds memory access issue within SMB response handling.

2026-04-11
CVE-2026-41489
Analyzed
8.8
Unknown Multiple Products

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software

2026-05-12
CVE-2026-41485
Analyzed
7.7
Microsoft Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams

2026-04-24
CVE-2026-4148
Analyzed
8.8
Unknown Multiple Products

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup...

2026-03-18
CVE-2026-41478
Analyzed
9.9
Saltcorn Multiple Products

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability i...

2026-04-25
CVE-2026-41477
Analyzed
7.8
Unknown Multiple Products

Deskflow is a keyboard and mouse sharing app

2026-04-25
CVE-2026-41471
Analyzed
7.5
WordPress versions

Easy PayPal Events & Tickets plugin for WordPress versions 1

2026-05-05
CVE-2026-41468
Analyzed
8.7
Unknown Multiple Products

Beghelli Sicuro24 SicuroWeb embeds AngularJS 1

2026-04-23
CVE-2026-41463
Analyzed
8.8
ProjeQtor Multiple Products

ProjeQtor versions 7

2026-04-28
CVE-2026-41462
Analyzed
9.8
ProjeQtor Multiple Products

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is di...

2026-04-28
CVE-2026-41461
Analyzed
8.5
SocialEngine Multiple Products

SocialEngine versions 7

2026-04-24
CVE-2026-41460
Analyzed
9.8
SocialEngine Multiple Products

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input pa...

2026-04-24
CVE-2026-41455
Analyzed
8.5
WeKan Multiple Products

WeKan before 8

2026-04-23
CVE-2026-41454
Analyzed
8.3
WeKan Multiple Products

WeKan before 8

2026-04-23
CVE-2026-41453
Analyzed
8.8
Krayin Laravel CRM

Krayin CRM before 2

2026-08-04
CVE-2026-41452
Analyzed
9.8
Unknown laravel-crm

A missing authentication vulnerability in the Krayin CRM installer middleware allows unauthenticated remote attackers to overwrite the administrator a...

2026-08-04
CVE-2026-41451
Analyzed
7.8
Unknown uac

UAC (Unix-like Artifacts Collector) versions prior to 3

2026-08-23
CVE-2026-41450
Analyzed
7.8
Unknown uac

UAC (Unix-like Artifacts Collector) versions prior to 3

2026-08-23
CVE-2026-4145
Analyzed
7.8
Lenovo Software Fix

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to...

2026-04-17
CVE-2026-41449
Analyzed
7.8
Unknown uac

UAC (Unix-like Artifacts Collector) versions prior to 3

2026-08-23
CVE-2026-41447
Analyzed
7.8
Microsoft FirmaCheck

FirmaCheck for Windows before 1

2026-08-04
CVE-2026-41445
Analyzed
8.8
Unknown Multiple Products

KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr

2026-04-21
CVE-2026-41433
Analyzed
8.4
Unknown Multiple Products

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard

2026-04-25
CVE-2026-41432
Analyzed
7.1
Intel New API

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

2026-05-10
CVE-2026-41431
Analyzed
8
GitHub release pipeline

Zen is a firefox-based browser

2026-05-12
CVE-2026-41429
Analyzed
8.8
Unknown Multiple Products

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers

2026-04-25
CVE-2026-41428
Analyzed
9.1
Arch Budibase

Budibase contains an authentication bypass vulnerability where unanchored regular expressions allow attackers to access protected endpoints via crafte...

2026-04-25
CVE-2026-41422
Analyzed
8.3
Unknown Multiple Products

Daptin is a GraphQL/JSON-API headless CMS

2026-05-08
CVE-2026-41421
Analyzed
8.8
Unknown Multiple Products

SiYuan is an open-source personal knowledge management system

2026-04-25
CVE-2026-41419
Analyzed
7.6
Arch Multiple Products

4ga Boards is a boards system for realtime project management

2026-04-25
CVE-2026-41414
Analyzed
7.4
GitHub user can

Skim is a fuzzy finder designed to through files, lines, and commands

2026-04-25
CVE-2026-41409
Analyzed
9.8
Apache MINA AbstractIoBuffer

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized w...

2026-04-28
CVE-2026-41405
Analyzed
7.5
Microsoft webhook request

OpenClaw before 2026

2026-04-29