21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 801-850 of 21637 CVEs Page 17 of 433
CVE-2026-7412
8.6
Java Multiple Products

In Eclipse BaSyx Java Server SDK versions prior to 2

2026-05-06
CVE-2026-7411
Analyzed
10
Eclipse BaSyx Java Server SDK

The Eclipse BaSyx Java Server SDK is vulnerable to path traversal via the Submodel HTTP API, potentially leading to Remote Code Execution.

2026-05-06
CVE-2026-7404
7.3
Infor Multiple Products

A weakness has been identified in getsimpletool mcpo-simple-server up to 0

2026-05-01
CVE-2026-7402
8.1
MeWare Software Multiple Products

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc

2026-05-01
CVE-2026-74018
Analyzed
9.9
Unknown Warehouse Cargo

Warehouse Cargo versions 2.6.9 and earlier allow authenticated subscribers to perform arbitrary file uploads, potentially leading to remote code execu...

2026-08-21
CVE-2026-74016
Analyzed
9.9
WordPress Smart Cleaning

The Smart Cleaning WordPress theme is vulnerable to an arbitrary file upload flaw, enabling authenticated subscribers to upload malicious content to t...

2026-08-21
CVE-2026-74014
Analyzed
9.9
WordPress IT Residence

The IT Residence WordPress theme contains an arbitrary file upload vulnerability that allows authenticated subscribers to upload malicious files to th...

2026-08-21
CVE-2026-74012
Analyzed
8.8
HP TaxoPress

Editor PHP Object Injection in TaxoPress <= 3

2026-08-19
CVE-2026-7400
7.3
Unknown Multiple Products

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1

2026-05-01
CVE-2026-73992
Analyzed
9.9
WordPress Query Wrangler

A remote code execution vulnerability exists in the Query Wrangler WordPress plugin, allowing authenticated subscribers to execute arbitrary code.

2026-08-21
CVE-2026-7399
8.1
MeWare Software Multiple Products

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc

2026-05-01
CVE-2026-7398
7.3
Infor Multiple Products

A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54

2026-05-01
CVE-2026-73930
Analyzed
9.9
Oracle Helidon

An unauthenticated remote vulnerability in the Oracle Helidon Imperative Web Server allows for data manipulation and partial denial of service via HTT...

2026-08-19
CVE-2026-7389
7.3
HP Multiple Products

A security vulnerability has been detected in EyouCMS up to 1

2026-05-01
CVE-2026-7387
Analyzed
8.8
Mattermost Mattermost

Mattermost versions 11

2026-06-13
CVE-2026-7386
7.3
Unknown Multiple Products

A flaw has been found in fatbobman mail-mcp-bridge up to 1

2026-05-01
CVE-2026-73850
Analyzed
8.6
Unknown emlog

Emlog is an open source website building system

2026-08-15
CVE-2026-73849
Analyzed
9.8
HP emlog

A flaw in the emlog installation script allows unauthenticated attackers to overwrite the configuration file and create a new administrator account vi...

2026-08-15
CVE-2026-73841
Analyzed
8.8
Kubernetes openchoreo

OpenChoreo is a complete, open-source developer platform for Kubernetes

2026-08-14
CVE-2026-7384
7.3
Arch Multiple Products

A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c

2026-05-01
CVE-2026-7383
Analyzed
8.1
OpenSSL OpenSSL Library

Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer over...

2026-06-16
CVE-2026-7377
Analyzed
8.7
GitLab has remediated

GitLab has remediated an issue in GitLab EE affecting all versions from 18

2026-05-14
CVE-2026-7374
Analyzed
9.9
Red Hat KubeVirt

A flaw in KubeVirt's `virt-handler` allows an authenticated user to hijack privileged connections, potentially leading to full cluster compromise.

2026-05-27
CVE-2026-7372
Analyzed
9
GeoVision GV-VMS

A stack overflow in the GeoVision GV-VMS WebCam Server login functionality allows unauthenticated attackers to gain SYSTEM-level code execution via un...

2026-05-04
CVE-2026-7371
7.4
Unknown Multiple Products

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi

2026-05-04
CVE-2026-73683
Analyzed
8.1
Laravel Socialite

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id...

2026-08-16
CVE-2026-73682
Analyzed
8.8
Unknown semaphore

Semaphore versions prior to 2

2026-08-15
CVE-2026-73680
Analyzed
8.8
Cockpit HQ Cockpit CMS

Cockpit CMS 2

2026-08-15
CVE-2026-7368
Analyzed
8.1
Yarbo Yarbo mobile app and cloud services

The Yarbo cloud does not enforce per-device or per-user authorization

2026-06-14
CVE-2026-73679
Analyzed
7.2
HP ImpressCMS

ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute...

2026-08-16
CVE-2026-73678
Analyzed
10
HP Minds Platform

MindsDB Minds Platform versions 26.1.0 and earlier contain an unauthenticated remote code execution vulnerability via the /api/v1/responses/ endpoint...

2026-08-15
CVE-2026-73673
Analyzed
8.8
GitHub Netis NC63 Wireless AC1200 Router

Netis NC63 router firmware V3

2026-08-15
CVE-2026-73667
Analyzed
8.8
Kubernetes OpenChoreo

OpenChoreo is a complete, open-source developer platform for Kubernetes

2026-08-14
CVE-2026-73664
Analyzed
8.6
FreePBX backup

FreePBX is an open source IP PBX

2026-08-14
CVE-2026-73661
Analyzed
8.6
FreePBX framework

FreePBX is an open source IP PBX

2026-08-14
CVE-2026-73656
Analyzed
9.9
Unknown trigger.dev

Trigger.dev contains an authorization bypass vulnerability allowing authenticated users to manipulate deployments across different projects by providi...

2026-08-14
CVE-2026-7365
Analyzed
8.4
IBM Operations Analytics

IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing p...

2026-05-29
CVE-2026-73649
Analyzed
9.8
Unknown velocity.js

A code injection vulnerability in velocity.js prior to 2.1.7 allows attackers to execute arbitrary shell commands via crafted templates.

2026-08-14
CVE-2026-73646
Analyzed
7.5
PostCSS PostCSS

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree

2026-08-18
CVE-2026-73633
Analyzed
7.5
Apache Apache Struts

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts

2026-08-16
CVE-2026-7363
8.8
Google Chrome on

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147

2026-04-30
CVE-2026-73625
Analyzed
8.8
GitPython Developers GitPython

GitPython versions before 3

2026-08-14
CVE-2026-73615
Analyzed
8.8
Jovancoding Network-AI

Network-AI versions before 5

2026-08-14
CVE-2026-73614
Analyzed
8.8
Jovancoding Network-AI

Network-AI ClaudeHookBridge before 5

2026-08-14
CVE-2026-7361
8.8
Apple Chrome prior

Use after free in iOS in Google Chrome prior to 147

2026-04-30
CVE-2026-73608
Analyzed
8.6
Unknown siyuan

SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3

2026-08-15
CVE-2026-7359
8.8
Google Chrome prior

Use after free in ANGLE in Google Chrome prior to 147

2026-04-30
CVE-2026-7358
8.8
Google Chrome prior

Use after free in Animation in Google Chrome prior to 147

2026-04-30
CVE-2026-73570
Analyzed
8.9
Zimbra Collaboration

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10

2026-08-14
CVE-2026-7357
7.5
Google Chrome prior

Use after free in GPU in Google Chrome prior to 147

2026-04-30