21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 8501-8550 of 21553 CVEs Page 171 of 432
CVE-2026-2754
7.5
Infor Multiple Products

Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints

2026-03-08
CVE-2026-2753
7.5
Infor Multiple Products

An Absolute Path Traversal vulnerability exists in Navtor NavBox

2026-03-08
CVE-2026-27520
7.5
Binardat Multiple Products

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded valu...

2026-02-25
CVE-2026-27519
7.5
Binardat Multiple Products

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript

2026-02-25
CVE-2026-27516
8.1
Binardat Multiple Products

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface...

2026-02-25
CVE-2026-27515
Analyzed
9.1
Binardat 10G08-0800GSM Network Switch

Binardat network switches generate predictable numeric session identifiers in their web management interface. This flaw allows attackers to guess acti...

2026-02-25
CVE-2026-2751
Analyzed
8.3
Linux Multiple Products

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion

2026-02-28
CVE-2026-27509
8
Unitree Multiple Products

Unitree Go2 firmware versions V1

2026-02-28
CVE-2026-27507
Analyzed
9.8
Binardat 10G08-0800GSM Network Switch

Binardat 10G08-0800GSM switches contain hard-coded administrative credentials in firmware. Knowledge of these static credentials allows an attacker to...

2026-02-25
CVE-2026-2750
Analyzed
9.1
Linux Centreon Open Tickets Module

An improper input validation vulnerability in Centreon Open Tickets allows attackers to submit malicious data that could compromise the Central Server...

2026-02-28
CVE-2026-2749
Analyzed
9.9
Linux Centreon Open Tickets Module

The Centreon Open Tickets module on Central Server contains a critical vulnerability that could lead to unauthorized system access or compromise.

2026-02-28
CVE-2026-27487
Analyzed
7.6
OpenClaw OpenClaw AI Assistant

OpenClaw is a personal AI assistant

2026-02-22
CVE-2026-27483
Analyzed
8.8
Intel Multiple Products

MindsDB is a platform for building artificial intelligence from enterprise data

2026-02-25
CVE-2026-27479
7.7
Unknown Multiple Products

Wallos is an open-source, self-hostable personal subscription tracker

2026-02-21
CVE-2026-27478
Analyzed
9.1
Unity Unity Catalog

Unity Catalog 0.4.0 and earlier contains a critical authentication bypass in the token exchange endpoint due to improper validation of the issuer clai...

2026-03-12
CVE-2026-27476
Analyzed
9.8
Unknown Multiple Products

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 w...

2026-02-20
CVE-2026-27475
8.1
SPIP Multiple Products

SPIP before 4

2026-02-20
CVE-2026-27470
8.8
HP file within

ZoneMinder is a free, open source closed-circuit television software application

2026-02-21
CVE-2026-27466
Analyzed
7.2
Ubuntu firewall

BigBlueButton is an open-source virtual classroom

2026-02-22
CVE-2026-27464
7.7
Infor Multiple Products

Metabase is an open-source data analytics platform

2026-02-21
CVE-2026-27449
Analyzed
7.5
Intel Multiple Products

Umbraco Engage is a business intelligence platform

2026-02-27
CVE-2026-27436
Analyzed
9.1
Rustaurius Five Star Business Profile and Schema

An arbitrary code execution vulnerability exists in Rustaurius Five Star Business Profile and Schema versions 2.3.19 and earlier, exploitable by authe...

2026-07-03
CVE-2026-27419
Analyzed
9.9
WordPress Zegen

An arbitrary file upload vulnerability in Zozothemes Zegen allows authenticated attackers to execute malicious code.

2026-07-03
CVE-2026-27414
Analyzed
8.8
HP Werkstatt

Contributor PHP Object Injection in Werkstatt <= 4

2026-07-03
CVE-2026-27413
Analyzed
9.3
Cozmoslabs Profile Profile Builder Pro

Cozmoslabs Profile Builder Pro is vulnerable to Blind SQL Injection, allowing attackers to extract sensitive information from the database by sending...

2026-03-19
CVE-2026-27412
Analyzed
8.1
StylemixThemes Pearl - Corporate Business

Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3

2026-07-03
CVE-2026-27400
Analyzed
8.6
BookPro BookPro

Unauthenticated Arbitrary File Deletion in BookPro <= 1

2026-06-18
CVE-2026-2740
Analyzed
8.4
Unknown ADSelfService Plus

Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Aut...

2026-05-22
CVE-2026-27343
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifact...

2026-02-21
CVE-2026-27333
Analyzed
8.1
Unknown Paid Videochat Turnkey Site

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7

2026-06-16
CVE-2026-27314
8.8
Apache Cassandra

Privilege escalation in Apache Cassandra 5

2026-04-08
CVE-2026-27309
7.8
Stager Multiple Products

Substance3D - Stager versions 3

2026-03-28
CVE-2026-27306
8.4
ColdFusion Multiple Products

ColdFusion versions 2023

2026-04-15
CVE-2026-27305
8.6
ColdFusion Multiple Products

ColdFusion versions 2023

2026-04-15
CVE-2026-27304
Analyzed
9.3
ColdFusion Multiple Products

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code executi...

2026-04-15
CVE-2026-27303
Analyzed
9.6
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code...

2026-04-15
CVE-2026-27302
Analyzed
10
Adobe Campaign Classic

Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that allows unauthenticated remote attackers to execute arbitrary code without...

2026-08-12
CVE-2026-27291
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27290
8.6
Adobe Framemaker versions

Adobe Framemaker versions 2022

2026-04-15
CVE-2026-27284
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27283
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27274
7.8
Stager Multiple Products

Substance3D - Stager versions 3

2026-03-11
CVE-2026-27273
7.8
Stager Multiple Products

Substance3D - Stager versions 3

2026-03-11
CVE-2026-27269
7.8
Pro Multiple Products

Premiere Pro versions 25

2026-03-11
CVE-2026-27246
Analyzed
9.3
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this...

2026-04-15
CVE-2026-27245
Analyzed
9.3
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convi...

2026-04-15
CVE-2026-27243
Analyzed
9.3
Adobe Connect versions

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convi...

2026-04-15
CVE-2026-27238
7.8
Unknown Multiple Products

InDesign Desktop versions 20

2026-04-15
CVE-2026-27208
Analyzed
9.2
Docker api-gateway-deploy

A critical attack chain involving OS command injection and privilege escalation in api-gateway-deploy allows for root-level execution and container es...

2026-02-25
CVE-2026-27206
8.1
HP variables in

Zumba Json Serializer is a library to serialize PHP variables in JSON format

2026-02-21