21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 7651-7700 of 21637 CVEs Page 154 of 433
CVE-2026-32459
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps...

2026-03-14
CVE-2026-32458
7.6
RealMag777 Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bulk-editor allows Blind SQL Inj...

2026-03-14
CVE-2026-3245
Analyzed
7.5
Canon Production Printing PRISMAproduction

A deserialization vulnerability in PRISMAproduction Version 6

2026-08-03
CVE-2026-32444
Analyzed
9.9
WordPress Cwicly

A remote code execution vulnerability exists in the Cwicly plugin for WordPress, allowing authenticated users with contributor-level access to execute...

2026-08-19
CVE-2026-32433
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contac...

2026-03-14
CVE-2026-3243
8.8
WordPress is vulnerable

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop...

2026-04-09
CVE-2026-32426
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core med...

2026-03-14
CVE-2026-32422
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart all...

2026-03-14
CVE-2026-32418
7.6
Jordy Meow Meow Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Blin...

2026-03-14
CVE-2026-32414
7.2
ILLID Advanced Woo Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion

2026-03-15
CVE-2026-32400
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemetechMount Boldman boldma...

2026-03-14
CVE-2026-32399
Analyzed
8.5
David Lingren Media Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-libr...

2026-03-14
CVE-2026-32368
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind...

2026-03-14
CVE-2026-32366
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-catego...

2026-03-14
CVE-2026-32358
7.6
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind...

2026-03-14
CVE-2026-32324
7.7
Anviz Multiple Products

Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential...

2026-04-18
CVE-2026-32323
Analyzed
7.3
VPN Multiple Products

Mullvad VPN is a VPN client app for desktop and mobile

2026-05-19
CVE-2026-32321
8.8
HP Multiple Products

ClipBucket v5 is an open source video sharing platform

2026-03-19
CVE-2026-32319
Analyzed
7.5
Ella Multiple Products

Ella Core is a 5G core designed for private networks

2026-03-14
CVE-2026-32318
7.6
Unknown Multiple Products

Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud

2026-03-21
CVE-2026-32317
7.6
Google Multiple Products

Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud

2026-03-21
CVE-2026-32316
8.2
Unknown Multiple Products

jq is a command-line JSON processor

2026-04-14
CVE-2026-32313
8.2
HP for working

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures

2026-03-17
CVE-2026-32308
Analyzed
7.6
Unknown Multiple Products

OneUptime is a solution for monitoring and managing online services

2026-03-14
CVE-2026-32306
Analyzed
9.9
OneUptime OneUptime

OneUptime versions prior to 10.0.23 are vulnerable to SQL injection in the telemetry aggregation API due to improper interpolation of user-controlled...

2026-03-14
CVE-2026-32304
Analyzed
9.8
Locutus Locutus

The Locutus library prior to version 3.0.14 is vulnerable to arbitrary code execution because the `create_function` implementation passes unsanitized...

2026-03-14
CVE-2026-32303
7.6
Hub Multiple Products

Cryptomator encrypts data being stored on cloud infrastructure

2026-03-21
CVE-2026-32302
Analyzed
8.1
Unknown Multiple Products

OpenClaw is a personal AI assistant

2026-03-14
CVE-2026-32301
Analyzed
9.3
Centrifugo Centrifugo

Centrifugo versions prior to 6.7.0 are vulnerable to Server-Side Request Forgery (SSRF) when using dynamic JWKS endpoints, allowing unauthenticated at...

2026-03-14
CVE-2026-32300
8.1
Infor Multiple Products

Connect-CMS is a content management system

2026-03-24
CVE-2026-32299
7.5
Infor Multiple Products

Connect-CMS is a content management system

2026-03-24
CVE-2026-32298
Analyzed
9.1
Angeet ES3 KVM

The Angeet ES3 KVM contains an OS command injection vulnerability in the 'cfg.lua' script, allowing authenticated attackers to execute arbitrary syste...

2026-03-18
CVE-2026-32297
Analyzed
7.5
Unknown Multiple Products

The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries

2026-03-18
CVE-2026-32296
8.2
NanoKVM Multiple Products

Sipeed NanoKVM before 2

2026-03-18
CVE-2026-32295
7.5
JetKVM Multiple Products

JetKVM before 0

2026-03-18
CVE-2026-32292
7.5
Unknown Multiple Products

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials

2026-03-18
CVE-2026-32278
8.2
Unknown Multiple Products

Connect-CMS is a content management system

2026-03-24
CVE-2026-32277
8.7
Unknown Multiple Products

Connect-CMS is a content management system

2026-03-24
CVE-2026-32276
8.8
Unknown Multiple Products

Connect-CMS is a content management system

2026-03-24
CVE-2026-32260
Analyzed
8.1
Unknown Multiple Products

Deno is a JavaScript, TypeScript, and WebAssembly runtime

2026-03-13
CVE-2026-32256
7.5
Unknown Multiple Products

music-metadata is a metadata parser for audio and video media files

2026-03-19
CVE-2026-32255
Analyzed
8.6
Nginx Kan Project Management Tool

Kan is an open-source project management tool

2026-03-19
CVE-2026-32254
7.1
Kubernetes networking

Kube-router is a turnkey solution for Kubernetes networking

2026-03-19
CVE-2026-32252
Analyzed
7.7
Unknown Multiple Products

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

2026-04-11
CVE-2026-32247
8.1
Arch Multiple Products

Graphiti is a framework for building and querying temporal context graphs for AI agents

2026-03-13
CVE-2026-32246
8.5
Unknown Multiple Products

Tinyauth is an authentication and authorization server

2026-03-13
CVE-2026-32242
7.4
Parse Multiple Products

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node

2026-03-14
CVE-2026-32241
7.5
Kubernetes Node annotations

Flannel is a network fabric for containers, designed for Kubernetes

2026-03-29
CVE-2026-32238
Analyzed
9.1
Unknown Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command i...

2026-03-20
CVE-2026-32231
8.2
Unknown Multiple Products

ZeptoClaw is a personal AI assistant

2026-03-13