20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 7651-7700 of 20297 CVEs Page 154 of 406
CVE-2026-27479
7.7
Unknown Multiple Products

Wallos is an open-source, self-hostable personal subscription tracker

2026-02-21
CVE-2026-27478
Analyzed
9.1
Unity Unity Catalog

Unity Catalog 0.4.0 and earlier contains a critical authentication bypass in the token exchange endpoint due to improper validation of the issuer clai...

2026-03-12
CVE-2026-27476
Analyzed
9.8
Unknown Multiple Products

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 w...

2026-02-20
CVE-2026-27475
8.1
SPIP Multiple Products

SPIP before 4

2026-02-20
CVE-2026-27470
8.8
HP file within

ZoneMinder is a free, open source closed-circuit television software application

2026-02-21
CVE-2026-27466
Analyzed
7.2
Ubuntu firewall

BigBlueButton is an open-source virtual classroom

2026-02-22
CVE-2026-27464
7.7
Infor Multiple Products

Metabase is an open-source data analytics platform

2026-02-21
CVE-2026-27449
Analyzed
7.5
Intel Multiple Products

Umbraco Engage is a business intelligence platform

2026-02-27
CVE-2026-27436
Analyzed
9.1
Rustaurius Five Star Business Profile and Schema

An arbitrary code execution vulnerability exists in Rustaurius Five Star Business Profile and Schema versions 2.3.19 and earlier, exploitable by authe...

2026-07-03
CVE-2026-27419
Analyzed
9.9
WordPress Zegen

An arbitrary file upload vulnerability in Zozothemes Zegen allows authenticated attackers to execute malicious code.

2026-07-03
CVE-2026-27414
Analyzed
8.8
HP Werkstatt

Contributor PHP Object Injection in Werkstatt <= 4

2026-07-03
CVE-2026-27413
Analyzed
9.3
Cozmoslabs Profile Profile Builder Pro

Cozmoslabs Profile Builder Pro is vulnerable to Blind SQL Injection, allowing attackers to extract sensitive information from the database by sending...

2026-03-19
CVE-2026-27412
Analyzed
8.1
StylemixThemes Pearl - Corporate Business

Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3

2026-07-03
CVE-2026-27400
Analyzed
8.6
BookPro BookPro

Unauthenticated Arbitrary File Deletion in BookPro <= 1

2026-06-18
CVE-2026-2740
Analyzed
8.4
Unknown ADSelfService Plus

Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Aut...

2026-05-22
CVE-2026-27343
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifact...

2026-02-21
CVE-2026-27333
Analyzed
8.1
Unknown Paid Videochat Turnkey Site

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7

2026-06-16
CVE-2026-27314
8.8
Apache Cassandra

Privilege escalation in Apache Cassandra 5

2026-04-08
CVE-2026-27309
7.8
Stager Multiple Products

Substance3D - Stager versions 3

2026-03-28
CVE-2026-27306
8.4
ColdFusion Multiple Products

ColdFusion versions 2023

2026-04-15
CVE-2026-27305
8.6
ColdFusion Multiple Products

ColdFusion versions 2023

2026-04-15
CVE-2026-27304
Analyzed
9.3
ColdFusion Multiple Products

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code executi...

2026-04-15
CVE-2026-27303
Analyzed
9.6
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code...

2026-04-15
CVE-2026-27291
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27290
8.6
Adobe Framemaker versions

Adobe Framemaker versions 2022

2026-04-15
CVE-2026-27284
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27283
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27274
7.8
Stager Multiple Products

Substance3D - Stager versions 3

2026-03-11
CVE-2026-27273
7.8
Stager Multiple Products

Substance3D - Stager versions 3

2026-03-11
CVE-2026-27269
7.8
Pro Multiple Products

Premiere Pro versions 25

2026-03-11
CVE-2026-27246
Analyzed
9.3
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this...

2026-04-15
CVE-2026-27245
Analyzed
9.3
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convi...

2026-04-15
CVE-2026-27243
Analyzed
9.3
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convi...

2026-04-15
CVE-2026-27238
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27208
Analyzed
9.2
Docker api-gateway-deploy

A critical attack chain involving OS command injection and privilege escalation in api-gateway-deploy allows for root-level execution and container es...

2026-02-25
CVE-2026-27206
8.1
HP variables in

Zumba Json Serializer is a library to serialize PHP variables in JSON format

2026-02-21
CVE-2026-27203
8.3
MCP Multiple Products

eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs

2026-02-21
CVE-2026-27198
Analyzed
8.8
Unknown Multiple Products

Formwork is a flat file-based Content Management System (CMS)

2026-02-21
CVE-2026-27197
Analyzed
9.1
Intel Sentry (SAML SSO)

A critical flaw in Sentry's SAML SSO implementation allows account takeover via malicious Identity Providers in multi-organization or specifically con...

2026-02-21
CVE-2026-27196
8.1
Unknown Multiple Products

Statmatic is a Laravel and Git powered content management system (CMS)

2026-02-21
CVE-2026-27195
7.5
Unknown Multiple Products

Wasmtime is a runtime for WebAssembly

2026-02-26
CVE-2026-27190
Analyzed
8.1
Unknown Multiple Products

Deno is a JavaScript, TypeScript, and WebAssembly runtime

2026-02-21
CVE-2026-27182
8.4
Mouse Multiple Products

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending s...

2026-02-19
CVE-2026-27181
7.5
Unknown Multiple Products

MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module

2026-02-19
CVE-2026-27180
Analyzed
9.8
HP files

MajorDoMo is vulnerable to unauthenticated remote code execution via update URL poisoning, allowing an attacker to force the system to download and ex...

2026-02-19
CVE-2026-27179
8.2
Unknown Multiple Products

MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module

2026-02-19
CVE-2026-27178
7.2
HP rendering code

MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method parameter injection into the shoutbox

2026-02-19
CVE-2026-27177
7.2
HP Multiple Products

MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=set endpoint, which is intention...

2026-02-19
CVE-2026-27175
Analyzed
9.8
HP script

MajorDoMo is vulnerable to unauthenticated remote code execution via a race condition and unsanitized user input in the rc/index.php and cycle_execs.p...

2026-02-19
CVE-2026-27174
Analyzed
9.8
HP console feature

MajorDoMo allows unauthenticated remote code execution via the admin panel's PHP console due to a logic error that bypasses authentication and passes...

2026-02-19