18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 8501-8550 of 18466 CVEs Page 171 of 370
CVE-2026-1280
Analyzed
7.5
WordPress Multiple Products

The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_...

2026-01-29
CVE-2026-12795
Analyzed
7.3
BerriAI litellm

A vulnerability was determined in BerriAI litellm up to 1

2026-06-22
CVE-2026-12786
Analyzed
7.8
Ezbsystems UltraISO Premium Edition

A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9

2026-06-21
CVE-2026-12784
Analyzed
7.8
IM-Magic Partition Resizer

A weakness has been identified in IM-Magic Partition Resizer up to 7

2026-06-21
CVE-2026-12782
Analyzed
7.8
EaseUS Partition Master

A security flaw has been discovered in EaseUS Partition Master up to 14

2026-06-21
CVE-2026-12781
Analyzed
7.8
EaseUS Partition Master

A vulnerability was identified in EaseUS Partition Master up to 14

2026-06-21
CVE-2026-12780
Analyzed
7.8
AOMEI Backupper

A vulnerability was determined in AOMEI Backupper up to 8

2026-06-21
CVE-2026-12779
Analyzed
7.8
AOMEI Dynamic Disk Manager

A vulnerability was found in AOMEI Dynamic Disk Manager up to 10

2026-06-21
CVE-2026-12778
Analyzed
7.8
AOMEI Partition Assistant

A vulnerability has been found in AOMEI Partition Assistant up to 10

2026-06-21
CVE-2026-12775
Analyzed
7.3
Montodel House-Rental-Management

A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863

2026-06-22
CVE-2026-12773
Analyzed
7.3
BerriAI litellm

A weakness has been identified in BerriAI litellm up to 1

2026-06-22
CVE-2026-12761
Analyzed
9.8
WordPress miniOrange Social Login and Register

The miniOrange Social Login and Register plugin for WordPress is vulnerable to unauthenticated account takeover via flawed OAuth email validation and...

2026-07-11
CVE-2026-1273
7.2
WordPress is vulnerable

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all ver...

2026-03-04
CVE-2026-12715
Analyzed
8.5
Google Firebase Studio

Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users...

2026-07-18
CVE-2026-12694
Analyzed
9.1
Vimesoft Enterprise Video Platform

A missing authorization vulnerability in Vimesoft Enterprise Video Platform allows unauthenticated attackers to access sensitive functionality not pro...

2026-07-18
CVE-2026-12693
Analyzed
9.4
Vimesoft Enterprise Video Platform

An authorization bypass vulnerability in Vimesoft Enterprise Video Platform allows unauthenticated attackers to access restricted functions by manipul...

2026-07-18
CVE-2026-12692
Analyzed
9.8
Vimesoft Enterprise Video Platform

An unverified password change vulnerability in the Vimesoft Enterprise Video Platform allows remote, unauthenticated attackers to bypass authenticatio...

2026-07-18
CVE-2026-12691
Analyzed
7.5
Vimesoft Enterprise Video Platform

Missing authentication for critical function vulnerability in Vimesoft Inc

2026-07-19
CVE-2026-12686
Analyzed
9.3
Adiss Biloop

An authenticated cross-tenant authorization bypass in Adiss Biloop allows users to access or modify data belonging to other companies by manipulating...

2026-07-07
CVE-2026-12685
Analyzed
7.5
WordPress escortwp

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker...

2026-07-14
CVE-2026-12681
Analyzed
8.9
Google go-attestation

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation

2026-06-24
CVE-2026-12659
Analyzed
8.7
Rockwell Automation The FLEX 5000 EtherNet/IP Adapter

A denial-of-service security issue exists in the affected products

2026-07-15
CVE-2026-1264
Analyzed
7.1
IBM Sterling B2B

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6

2026-03-19
CVE-2026-12628
Analyzed
8.1
IBM Storage Protect Client

IBM Storage Protect Client 8

2026-06-23
CVE-2026-12602
Analyzed
8.8
Aruba ArubaSign

Incorrect default permissions in ArubaSign, affecting versions prior to v4

2026-06-23
CVE-2026-12598
Analyzed
8.1
WordPress LoginPress Pro

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6

2026-07-10
CVE-2026-12597
Analyzed
8.1
WordPress LoginPress Pro

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6

2026-07-10
CVE-2026-12595
Analyzed
8.1
WordPress LoginPress Pro

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6

2026-07-10
CVE-2026-12593
Analyzed
8.7
Qt Axivion

The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creat...

2026-07-10
CVE-2026-12585
Analyzed
8.1
WordPress Abandoned Cart Lite for WooCommerce

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6

2026-07-17
CVE-2026-12583
Analyzed
8.1
HP Newsletters

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauth...

2026-07-16
CVE-2026-12582
Analyzed
8.6
WordPress Library Management System

The Library Management System WordPress plugin before 3

2026-07-14
CVE-2026-12581
Analyzed
7.5
Digiwin EasyFlow .NET

EasyFlow

2026-06-23
CVE-2026-12578
Analyzed
8.4
Delta Electronics DTMSoft

The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code

2026-06-30
CVE-2026-12577
Analyzed
8.7
Delta Electronics DVP80ES3

DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability

2026-07-01
CVE-2026-12576
Analyzed
7.5
Delta Electronics DVP80ES3 PLC

DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability

2026-07-01
CVE-2026-12575
Analyzed
7.5
Delta Electronics DVP80ES3 PLC

DVP80ES3 with  Improper Resource Shutdown or Release vulnerability

2026-07-01
CVE-2026-1257
Analyzed
7.5
WordPress Multiple Products

The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0

2026-01-24
CVE-2026-12569
KEV Analyzed
9.5
PTC Windchill and FlexPLM

PTC Windchill and FlexPLM are vulnerable to improper input validation, allowing for potential exploitation. This vulnerability is confirmed as activel...

2026-06-26
CVE-2026-12537
Analyzed
10
Google Gemini CLI

An OS command injection vulnerability in Google Gemini CLI allows unprivileged attackers to achieve host-level code execution during CI/CD processes.

2026-06-25
CVE-2026-12535
Analyzed
9.8
Drupal Formatter Field

The Drupal Formatter Field module contains an object injection vulnerability due to improper control of dynamically determined object attributes.

2026-07-15
CVE-2026-12525
Analyzed
8.8
WordPress Redux Framework

The Redux Framework WordPress plugin before 4

2026-07-17
CVE-2026-12512
Analyzed
8.6
WordPress Quotes llama

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowin...

2026-07-19
CVE-2026-12511
Analyzed
8.1
WordPress AI Engine

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authentic...

2026-07-16
CVE-2026-12492
Analyzed
9.8
Happy Coders OTP Login for WooCommerce

The Happy Coders OTP Login for WooCommerce plugin fails to validate one-time passwords during the authentication process, allowing unauthorized accoun...

2026-07-17
CVE-2026-12490
Analyzed
8.2
NLnet NSD

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name

2026-06-25
CVE-2026-12486
Analyzed
9.1
GeoVision GV-I/O Box 4E

Multiple OS command injection vulnerabilities in the GeoVision GV-I/O Box 4E allow remote attackers to execute arbitrary commands via crafted network...

2026-06-24
CVE-2026-12485
Analyzed
10
GeoVision GV-I/O Box 4E

The GeoVision GV-I/O Box 4E contains a stack-based buffer overflow in the DVRSearch service, allowing unauthenticated attackers to trigger remote code...

2026-06-24
CVE-2026-12481
Analyzed
8.8
Keras Team Keras

A vulnerability in keras-team/keras version 3

2026-07-04
CVE-2026-12473
Analyzed
8.2
Open DICOM Web Viewer Framework

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation

2026-06-26