20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 701-750 of 20297 CVEs Page 15 of 406
CVE-2026-7202
Analyzed
9.8
TOTOLINK Multiple Products

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of...

2026-04-28
CVE-2026-7201
Analyzed
8.8
Progress Sitefinity

CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15

2026-06-03
CVE-2026-7199
7.3
HP Multiple Products

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-7198
Analyzed
9.8
Progress Sitefinity

Improper access control in Progress Sitefinity web services allows unauthenticated attackers to access restricted content and fully compromise the ins...

2026-06-03
CVE-2026-7195
Analyzed
8.8
Progress Sitefinity

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14

2026-06-03
CVE-2026-7194
7.3
HP Multiple Products

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-7189
Analyzed
7.5
Proliz Software Proliz's OBS

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd

2026-07-19
CVE-2026-7187
Analyzed
8.8
Universal Software UKBS

Missing authentication for critical function vulnerability in Universal Software Inc

2026-07-29
CVE-2026-71847
Analyzed
8.7
Ruby JSON

Ruby JSON is a JSON implementation for Ruby

2026-08-08
CVE-2026-7178
7.3
Infor Multiple Products

A weakness has been identified in ChatGPTNextWeb NextChat up to 2

2026-04-28
CVE-2026-7177
7.3
Infor Multiple Products

A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2

2026-04-28
CVE-2026-7166
Analyzed
9.2
Gaudire Assassin game

The Gaudire Assassin game API and local database improperly protect sensitive information, leading to the unauthorized exposure of email addresses, ph...

2026-06-23
CVE-2026-7165
Analyzed
9.4
Gaudire Assassin game

The Gaudire Assassin game contains multiple vulnerabilities in the ‘/addJugador’ endpoint, including insecure parameter handling, improper input valid...

2026-06-23
CVE-2026-7164
7.5
Unknown Multiple Products

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters

2026-05-01
CVE-2026-7162
Analyzed
7.8
WinFsp WinFsp

Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software

2026-07-13
CVE-2026-7161
Analyzed
9.3
LG GV-IP Device Utility

An insufficient encryption vulnerability in the GeoVision GV-IP Device Utility allows attackers on the same LAN to decrypt administrative credentials...

2026-05-04
CVE-2026-7160
8.8
Tenda Multiple Products

A vulnerability was determined in Tenda HG3 2

2026-04-28
CVE-2026-7159
7.3
Unknown Multiple Products

A vulnerability was found in douinc mkdocs-mcp-plugin up to 0

2026-04-28
CVE-2026-7158
7.3
Infor Multiple Products

A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6

2026-04-28
CVE-2026-7157
7.3
Infor Multiple Products

A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc

2026-04-28
CVE-2026-7156
Analyzed
9.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the comp...

2026-04-28
CVE-2026-71558
Analyzed
9.8
Apache Apache Fory

A heap type confusion vulnerability in Apache Fory C++ allows remote attackers to trigger denial of service or arbitrary code execution via crafted pa...

2026-08-08
CVE-2026-7155
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary system commands...

2026-04-28
CVE-2026-7154
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary system commands...

2026-04-28
CVE-2026-7153
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary system commands...

2026-04-28
CVE-2026-7152
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary commands by man...

2026-04-28
CVE-2026-7151
8.8
Tenda HG3

A vulnerability was determined in Tenda HG3 2

2026-04-28
CVE-2026-7149
7.3
Infor Multiple Products

A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d

2026-04-28
CVE-2026-71476
Analyzed
8.7
Unknown nx

Nx is a monorepo solution for TypeScript and polyglot codebases

2026-08-07
CVE-2026-7147
7.3
Infor Multiple Products

A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1

2026-04-28
CVE-2026-7146
7.3
Infor Multiple Products

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d

2026-04-28
CVE-2026-71445
Analyzed
8.2
Unknown ail-framework

AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint

2026-08-07
CVE-2026-7140
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability exists in the Totolink A8000RU CGI handler, allowing unauthenticated remote attackers to execute arbitrary syste...

2026-04-28
CVE-2026-7139
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the mode parameter in the setWiFiAclRules...

2026-04-28
CVE-2026-7138
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the tz parameter in the setNtpCfg function...

2026-04-28
CVE-2026-7137
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the sambaEnabled parameter in the setStora...

2026-04-28
CVE-2026-7136
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the wanIdx parameter in the setDmzCfg func...

2026-04-28
CVE-2026-71320
Analyzed
8.1
Nuxt Nuxt

Nuxt is an open-source web development framework for Vue

2026-08-06
CVE-2026-71315
Analyzed
8.2
Unknown nuxt

Nuxt is an open-source web development framework for Vue

2026-08-06
CVE-2026-7131
7.3
HP Multiple Products

A vulnerability has been found in code-projects Online Lot Reservation System up to 1

2026-04-28
CVE-2026-71309
Analyzed
8.6
Unknown rclone

rclone is a command-line program to sync files and directories to and from different cloud storage providers

2026-08-06
CVE-2026-7130
7.3
HP Multiple Products

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-71291
Analyzed
8.8
Bolt core

Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase

2026-08-06
CVE-2026-71289
Analyzed
9.8
NASA-AMMOS anms

The NASA-AMMOS ANMS reference implementation exposes its REST API directly to the network without authentication, allowing remote attackers to send un...

2026-08-06
CVE-2026-71288
Analyzed
8.8
Koha Koha

Koha's guided report builder (reports/guided_reports

2026-08-06
CVE-2026-71287
Analyzed
8.8
Cacti cacti

Cacti's sanitize_sql_column() (lib/functions

2026-08-06
CVE-2026-71281
Analyzed
8.8
Hugging Face peft

Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda

2026-08-06
CVE-2026-71280
Analyzed
8.5
Unknown shiori

go-shiori's DownloadBookmark() (internal/core/download

2026-08-06
CVE-2026-7128
7.3
HP Multiple Products

A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-71278
Analyzed
9.8
Unknown rust-iot-platform

The rust-iot-platform software lacks authentication on a calc rule creation endpoint, allowing unauthenticated attackers to execute arbitrary JavaScri...

2026-08-06