21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 8151-8200 of 21637 CVEs Page 164 of 433
CVE-2026-29067
Analyzed
8.1
ZITADEL ZITADEL

ZITADEL is an open source identity management platform

2026-03-08
CVE-2026-29064
Analyzed
8.2
Kubernetes Zarf

Zarf is an Airgap Native Packager Manager for Kubernetes

2026-03-07
CVE-2026-2906
8.8
Tenda HG9

A security flaw has been discovered in Tenda HG9 300001138

2026-02-22
CVE-2026-29058
Analyzed
9.8
AVideo Video-sharing Platform

AVideo is vulnerable to unauthenticated command injection via the base64Url parameter. Attackers can execute arbitrary OS commands, leading to full se...

2026-03-06
CVE-2026-29056
8.8
Unknown Multiple Products

Kanboard is project management software focused on Kanban methodology

2026-03-19
CVE-2026-29054
7.5
Traefik Multiple Products

Traefik is an HTTP reverse proxy and load balancer

2026-03-07
CVE-2026-29053
7.6
Unknown Multiple Products

Ghost is a Node

2026-03-05
CVE-2026-2905
8.8
Tenda HG9

A vulnerability was identified in Tenda HG9 300001138

2026-02-22
CVE-2026-29045
7.5
Unknown Multiple Products

Hono is a Web application framework that provides support for any JavaScript runtime

2026-03-05
CVE-2026-29041
8.8
Unknown Multiple Products

Chamilo is a learning management system

2026-03-06
CVE-2026-2904
Analyzed
8.8
UTT Multiple Products

A vulnerability was determined in UTT HiPER 810G 1

2026-02-22
CVE-2026-29023
7.3
Keygraph Multiple Products

Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network atta...

2026-03-10
CVE-2026-29022
7.3
Unknown Multiple Products

dr_libs version 0

2026-03-05
CVE-2026-29014
Analyzed
9.8
HP code injection

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary c...

2026-04-02
CVE-2026-29009
Analyzed
8.2
Boot U-Boot

U-Boot through 2026

2026-07-09
CVE-2026-29004
8.1
Unknown Multiple Products

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/ud...

2026-05-05
CVE-2026-29002
Analyzed
7.2
CouchCMS CouchCMS

CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the...

2026-04-12
CVE-2026-29000
Analyzed
10
Unknown pac4j-jwt

An authentication bypass in pac4j-jwt allows unauthenticated remote attackers to forge tokens by wrapping a PlainJWT in a JWE, bypassing signature ver...

2026-03-05
CVE-2026-28995
Analyzed
8.8
Unknown Multiple Products

A logic issue was addressed with improved restrictions

2026-05-13
CVE-2026-28982
9.8
Apple macOS

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote use...

2026-08-19
CVE-2026-28973
Analyzed
8.6
Apple iOS, iPadOS, macOS, watchOS

An integer overflow was addressed with improved input validation

2026-07-29
CVE-2026-2896
7.3
HP of the

A weakness has been identified in funadmin up to 7

2026-02-22
CVE-2026-28947
Analyzed
8.8
Unknown Multiple Products

A use-after-free issue was addressed with improved memory management

2026-05-13
CVE-2026-28945
7.1
Apple macOS

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe...

2026-08-18
CVE-2026-28931
Analyzed
8.8
Apple iOS, iPadOS, macOS, tvOS, watchOS

A buffer overflow was addressed with improved bounds checking

2026-07-29
CVE-2026-28928
9.8
Apple iOS and iPadOS

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, wa...

2026-08-16
CVE-2026-28923
Analyzed
8.8
Unknown Multiple Products

A logging issue was addressed with improved data redaction

2026-05-13
CVE-2026-2892
7.5
WordPress is vulnerable

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3

2026-05-01
CVE-2026-28911
9.8
Apple macOS

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to co...

2026-08-19
CVE-2026-2890
Analyzed
7.5
WordPress is vulnerable

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6

2026-03-14
CVE-2026-28896
7.7
Apple macOS

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to ca...

2026-08-18
CVE-2026-28891
8.1
Unknown Multiple Products

A race condition was addressed with additional validation

2026-03-26
CVE-2026-2886
8.8
Tenda A21

A weakness has been identified in Tenda A21 1

2026-02-22
CVE-2026-28858
Analyzed
9.8
Apple iOS and iPadOS

A buffer overflow vulnerability in the kernel was addressed through improved bounds checking. Remote attackers may cause system termination or corrupt...

2026-03-26
CVE-2026-2885
8.8
D-Link DWR

A security flaw has been discovered in D-Link DWR-M960 1

2026-02-22
CVE-2026-2884
8.8
D-Link DWR

A vulnerability was identified in D-Link DWR-M960 1

2026-02-22
CVE-2026-2883
8.8
D-Link DWR

A vulnerability was determined in D-Link DWR-M960 1

2026-02-22
CVE-2026-2882
8.8
D-Link DWR

A vulnerability was found in D-Link DWR-M960 1

2026-02-22
CVE-2026-28817
8.1
Unknown Multiple Products

A race condition was addressed with improved state handling

2026-03-26
CVE-2026-28815
Analyzed
7.5
HP X-Wing HPKE Implementation

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a...

2026-04-04
CVE-2026-28813
Analyzed
8.8
Apache JSPWiki

Apache JSPWiki, up to 2

2026-08-01
CVE-2026-2881
8.8
D-Link DWR

A vulnerability has been found in D-Link DWR-M960 1

2026-02-22
CVE-2026-28806
Analyzed
8.8
Unknown Multiple Products

Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update A...

2026-05-28
CVE-2026-28805
Analyzed
8.8
MySQL database

OpenSTAManager is an open source management software for technical assistance and invoicing

2026-04-03
CVE-2026-28798
Analyzed
9
Cloudflare Tunnel

ZimaOS versions prior to 1.5.3 contain a proxy endpoint vulnerability. When exposed via Cloudflare Tunnel, unauthenticated attackers can access intern...

2026-04-04
CVE-2026-28793
8.4
Unknown Multiple Products

Tina is a headless content management system

2026-03-13
CVE-2026-28792
Analyzed
9.6
TinaCMS TinaCMS CLI

TinaCMS CLI is vulnerable to a browser-based drive-by attack that allows remote attackers to read, write, or delete files on developer machines.

2026-03-13
CVE-2026-28791
7.4
Unknown Multiple Products

Tina is a headless content management system

2026-03-14
CVE-2026-28790
7.5
Unknown Multiple Products

OliveTin gives access to predefined shell commands from a web interface

2026-03-07
CVE-2026-28789
7.5
Unknown Multiple Products

OliveTin gives access to predefined shell commands from a web interface

2026-03-07