21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 7601-7650 of 21637 CVEs Page 153 of 433
CVE-2026-32692
7.6
Vault secrets Multiple Products

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3

2026-03-19
CVE-2026-32680
7.8
Microsoft Multiple Products

The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder

2026-03-26
CVE-2026-32679
7.8
Microsoft Multiple Products

The installers of LiveOn Meet Client for Windows (Downloader5Installer

2026-04-23
CVE-2026-32673
Analyzed
8.7
Unknown Multiple Products

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to e...

2026-05-14
CVE-2026-32669
8.8
Buffalo Wi

Code injection vulnerability exists in BUFFALO Wi-Fi router products

2026-03-27
CVE-2026-32666
Analyzed
7.5
Automated Logic WebCTRL

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication

2026-03-22
CVE-2026-32663
7.3
Unknown Multiple Products

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session...

2026-03-22
CVE-2026-32661
Analyzed
9.8
Unknown GUARDIANWALL MailSuite/Mail Security Cloud

A stack-based buffer overflow exists in GUARDIANWALL MailSuite and Mail Security Cloud, potentially allowing arbitrary code execution.

2026-05-14
CVE-2026-32658
Analyzed
8
Dell Automation Platform

Dell Automation Platform versions prior to 2

2026-05-12
CVE-2026-32650
7.5
Anviz Multiple Products

Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent...

2026-04-18
CVE-2026-32647
7.8
Nginx Open Source

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read o...

2026-03-25
CVE-2026-32646
Analyzed
7.5
Unknown the affected software

A specific administrative endpoint is accessible without proper authentication, exposing device management functions

2026-04-04
CVE-2026-32644
Analyzed
9.8
Specific firmware Multiple Products

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

2026-04-28
CVE-2026-32643
Analyzed
8.7
Certificate Multiple Products

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can m...

2026-05-14
CVE-2026-32634
8.1
Unknown Multiple Products

Glances is an open-source system cross-platform monitoring tool

2026-03-19
CVE-2026-32633
Analyzed
9.1
Glances Glances

The Glances monitoring tool exposes sensitive HTTP Basic credentials for downstream servers via an unauthenticated API endpoint when the central brows...

2026-03-19
CVE-2026-32631
7.4
Microsoft Multiple Products

Git for Windows is the Windows port of Git

2026-04-17
CVE-2026-32628
Analyzed
8.8
PostgreSQL Multiple Products

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting

2026-03-17
CVE-2026-32627
8.7
Unknown Multiple Products

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library

2026-03-17
CVE-2026-32626
Analyzed
9.6
Unknown AnythingLLM Desktop

A Streaming Phase XSS in AnythingLLM Desktop's chat pipeline escalates to Remote Code Execution (RCE) on the host OS due to insecure Electron configur...

2026-03-17
CVE-2026-32621
Analyzed
9.9
Arch Federation

A prototype pollution vulnerability in Apollo Federation's query plan execution allows attackers to pollute Object.prototype, potentially leading to r...

2026-03-17
CVE-2026-32617
7.1
Unknown Multiple Products

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting

2026-03-17
CVE-2026-32616
8.2
Unknown Multiple Products

Pigeon is a message board/notepad/social system/blog

2026-03-17
CVE-2026-32614
7.5
LG Multiple Products

Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2/...

2026-03-17
CVE-2026-32613
Analyzed
9.9
Infor Multiple Products

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to proces...

2026-04-21
CVE-2026-32611
7
Unknown Multiple Products

Glances is an open-source system cross-platform monitoring tool

2026-03-19
CVE-2026-32610
8.1
Infor Multiple Products

Glances is an open-source system cross-platform monitoring tool

2026-03-19
CVE-2026-3261
7.3
HP of the

A flaw has been found in itsourcecode School Management System 1

2026-02-27
CVE-2026-32609
7.5
Unknown Multiple Products

Glances is an open-source system cross-platform monitoring tool

2026-03-19
CVE-2026-32608
7
Unknown Multiple Products

Glances is an open-source system cross-platform monitoring tool

2026-03-19
CVE-2026-32606
7.6
Unknown Multiple Products

IncusOS is an immutable OS image dedicated to running Incus

2026-03-18
CVE-2026-32605
7.5
LG Multiple Products

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

2026-04-14
CVE-2026-32604
Analyzed
9.9
Unknown Multiple Products

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor ca...

2026-04-21
CVE-2026-32600
8.2
Unknown Multiple Products

xml-security is a library that implements XML signatures and encryption

2026-03-17
CVE-2026-32597
Analyzed
7.5
Unknown Multiple Products

PyJWT is a JSON Web Token implementation in Python

2026-03-14
CVE-2026-32596
7.5
Infor Multiple Products

Glances is an open-source system cross-platform monitoring tool

2026-03-19
CVE-2026-32573
Analyzed
9.1
WordPress Nelio AB Testing

Nelio AB Testing plugin for WordPress contains a code injection vulnerability. This allows remote attackers to execute arbitrary code by exploiting im...

2026-03-26
CVE-2026-3257
Analyzed
9.8
Unknown Multiple Products

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Vers...

2026-03-06
CVE-2026-32539
Analyzed
9.3
HP PublishPress Revisions

PublishPress Revisions is vulnerable to Blind SQL Injection due to improper neutralization of special elements in SQL commands. This affects versions...

2026-03-26
CVE-2026-32536
Analyzed
9.9
HP Green Downloads

Green Downloads allows unrestricted upload of files with dangerous types, enabling the use of malicious files. This affects versions up to 2.08.

2026-03-26
CVE-2026-32534
8.5
JoomSky JS Help Desk Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Bl...

2026-03-26
CVE-2026-32531
8.1
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP...

2026-03-26
CVE-2026-32530
8.8
WPFunnels Creator LMS Multiple Products

Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation

2026-03-27
CVE-2026-32525
Analyzed
9.9
HP JetFormBuilder

JetFormBuilder is vulnerable to Code Injection due to improper control of code generation. This affects versions up to and including 3.5.6.1.

2026-03-26
CVE-2026-32522
8.6
Unknown Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce...

2026-03-27
CVE-2026-32516
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculousco...

2026-03-27
CVE-2026-32513
8.8
Miguel Useche JS Multiple Products

Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection

2026-03-26
CVE-2026-32484
8.8
BoldGrid weForms Multiple Products

Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection

2026-03-27
CVE-2026-32474
Analyzed
9.9
WordPress Templatiq

The Templatiq WordPress plugin is vulnerable to an arbitrary file upload flaw, allowing authenticated contributors to execute malicious code on the se...

2026-08-19
CVE-2026-32463
Analyzed
9.9
WordPress Sync Post With Other Site

The Sync Post With Other Site WordPress plugin is vulnerable to an arbitrary file upload flaw, allowing authenticated contributors to execute maliciou...

2026-08-19