23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 8151-8200 of 23295 CVEs Page 164 of 466
CVE-2026-35439
Analyzed
8.8
Microsoft Office SharePoint

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-05-13
CVE-2026-35438
Analyzed
8.3
Microsoft Multiple Products

Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network

2026-05-13
CVE-2026-35436
Analyzed
8.8
Microsoft Office Click

Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally

2026-05-13
CVE-2026-35435
Analyzed
8.6
Microsoft AI Foundry

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network

2026-05-08
CVE-2026-35431
Analyzed
10
Microsoft Entra ID

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Entra ID Entitlement Management allows unauthorized attackers to perform spoofing over...

2026-04-24
CVE-2026-35430
Analyzed
8.8
Microsoft Privileged Identity Management

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges ove...

2026-05-27
CVE-2026-3543
Analyzed
8.8
Google Chrome prior

Inappropriate implementation in V8 in Google Chrome prior to 145

2026-03-06
CVE-2026-35428
Analyzed
9.6
Microsoft Cloud Shell

A command injection vulnerability in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

2026-05-08
CVE-2026-35425
Analyzed
8
Microsoft Azure API Management (APIM)

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network

2026-07-25
CVE-2026-3542
Analyzed
8.8
Google Chrome prior

Inappropriate implementation in WebAssembly in Google Chrome prior to 145

2026-03-06
CVE-2026-3541
Analyzed
8.8
Google Chrome prior

Inappropriate implementation in CSS in Google Chrome prior to 145

2026-03-06
CVE-2026-35409
Analyzed
7.7
Unknown Multiple Products

Directus is a real-time API and App dashboard for managing SQL database content

2026-04-07
CVE-2026-35408
Analyzed
8.7
Google Multiple Products

Directus is a real-time API and App dashboard for managing SQL database content

2026-04-07
CVE-2026-35405
Analyzed
7.5
Unknown Multiple Products

libp2p-rust is the official rust language Implementation of the libp2p networking stack

2026-04-09
CVE-2026-35401
Analyzed
7.5
Unknown Multiple Products

Saleor is an e-commerce platform

2026-04-10
CVE-2026-3540
Analyzed
8.8
Google Chrome prior

Inappropriate implementation in WebAudio in Google Chrome prior to 145

2026-03-06
CVE-2026-35395
Analyzed
8.8
HP Multiple Products

WeGIA is a Web manager for charitable institutions

2026-04-07
CVE-2026-35394
Analyzed
8.3
MCP Multiple Products

Mobile Next is an MCP server for mobile development and automation

2026-04-07
CVE-2026-35393
Analyzed
9.8
Unknown goshs

The goshs SimpleHTTPServer fails to sanitize directories during multipart POST uploads, enabling unauthorized file placement.

2026-04-07
CVE-2026-35392
Analyzed
9.8
Unknown goshs

The goshs SimpleHTTPServer fails to sanitize file paths during PUT uploads, enabling arbitrary file write/overwrite.

2026-04-07
CVE-2026-3539
Analyzed
8.8
Google Chrome prior

Object lifecycle issue in DevTools in Google Chrome prior to 145

2026-03-05
CVE-2026-35385
Analyzed
7.5
OpenSSH Multiple Products

In OpenSSH before 10

2026-04-03
CVE-2026-3538
Analyzed
8.8
Google Chrome prior

Integer overflow in Skia in Google Chrome prior to 145

2026-03-06
CVE-2026-3537
Analyzed
8.8
Google Chrome on

Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145

2026-03-06
CVE-2026-35368
Analyzed
7.8
Unknown Multiple Products

A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option

2026-04-23
CVE-2026-3536
Analyzed
8.8
Google Chrome prior

Integer overflow in ANGLE in Google Chrome prior to 145

2026-03-06
CVE-2026-35352
Analyzed
7
Unknown Multiple Products

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils

2026-04-24
CVE-2026-3535
Analyzed
9.8
Google Web Fonts

The Google Web Fonts GDPR plugin for WordPress is vulnerable to unauthenticated arbitrary file upload via the `DSGVOGWPdownloadGoogleFonts()` function...

2026-04-08
CVE-2026-35341
Analyzed
7.1
Unknown Multiple Products

A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files

2026-04-24
CVE-2026-35338
Analyzed
7.3
Unknown Multiple Products

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism

2026-04-24
CVE-2026-35337
Analyzed
8.8
Apache Storm

Deserialization of Untrusted Data vulnerability in Apache Storm

2026-04-14
CVE-2026-3533
Analyzed
8.8
WordPress is vulnerable

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as wel...

2026-03-24
CVE-2026-35325
Analyzed
8.8
Oracle WebCenter Content

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

2026-06-18
CVE-2026-35324
Analyzed
8.8
Oracle WebCenter Content

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

2026-06-18
CVE-2026-35323
Analyzed
9.9
Oracle WebCenter Content

A critical vulnerability in Oracle WebCenter Content allows a low-privileged attacker to achieve full system takeover via network-based HTTP exploitat...

2026-06-18
CVE-2026-35322
Analyzed
8.8
Oracle WebCenter Content

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

2026-06-18
CVE-2026-35321
Analyzed
9.9
Oracle WebCenter Content

A critical vulnerability in Oracle WebCenter Content allows a low-privileged attacker to achieve full system takeover via network-based HTTP exploitat...

2026-06-18
CVE-2026-35318
Analyzed
8.8
Oracle WebCenter Sites

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

2026-06-18
CVE-2026-35317
Analyzed
8.8
Oracle WebCenter Content

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

2026-06-18
CVE-2026-35316
Analyzed
9.9
Oracle WebCenter Content

A critical vulnerability in the Oracle WebCenter Content server allows a low-privileged, network-adjacent attacker to achieve full system takeover via...

2026-06-18
CVE-2026-35315
Analyzed
8.8
Oracle WebCenter Content

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

2026-06-18
CVE-2026-35313
Analyzed
9.9
Oracle Access Manager

A critical vulnerability in the Oracle Access Manager authentication engine allows a low-privileged, network-adjacent attacker to achieve full system...

2026-06-18
CVE-2026-35311
Analyzed
8.8
Oracle Fusion Middleware (WebLogic Server)

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core)

2026-06-18
CVE-2026-35308
Analyzed
10
Oracle Coherence

A critical flaw in the Oracle Coherence Centralized Third Party Jars component allows unauthenticated attackers to achieve full system compromise via...

2026-06-18
CVE-2026-35307
Analyzed
10
Oracle Coherence

A critical vulnerability in the Oracle Coherence core component allows unauthenticated attackers to compromise the application via network-accessible...

2026-06-18
CVE-2026-35303
Analyzed
8.8
Oracle Fusion Middleware (WebLogic Server)

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console)

2026-06-18
CVE-2026-35302
Analyzed
8.3
Oracle WebLogic Server

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console)

2026-06-20
CVE-2026-35301
Analyzed
10
Oracle WebLogic Server

An unauthenticated remote code execution vulnerability exists in the Oracle WebLogic Server Console component, allowing full system takeover via craft...

2026-06-18
CVE-2026-35299
Analyzed
8.8
Oracle WebLogic Server

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console)

2026-06-18
CVE-2026-35294
Analyzed
9.9
Oracle Identity Manager Connector

A critical vulnerability in the Oracle Identity Manager Connector enables a low-privileged, network-adjacent attacker to achieve full system takeover...

2026-06-18