18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 8551-8600 of 18466 CVEs Page 172 of 370
CVE-2026-12468
Analyzed
8.3
Google Chrome

Race in Updater in Google Chrome on Mac prior to 149

2026-06-20
CVE-2026-12466
Analyzed
8.8
Microsoft Chrome

Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149

2026-06-18
CVE-2026-12454
Analyzed
8.3
Google Chrome

Race in Safe Browsing in Google Chrome on Mac prior to 149

2026-06-20
CVE-2026-12452
Analyzed
8.8
Google Chrome

Use after free in Downloads in Google Chrome on Android prior to 149

2026-06-18
CVE-2026-12448
Analyzed
8.8
Google Chrome (Android WebView)

Inappropriate implementation in WebView in Google Chrome on Android prior to 149

2026-06-18
CVE-2026-12447
Analyzed
8.8
Google Chrome

Heap buffer overflow in WebRTC in Google Chrome prior to 149

2026-06-18
CVE-2026-12443
Analyzed
8.8
Google Chrome

Use after free in Web Authentication in Google Chrome prior to 149

2026-06-18
CVE-2026-12442
Analyzed
8.8
Google Chrome

Use after free in Passwords in Google Chrome on Android prior to 149

2026-06-18
CVE-2026-12441
Analyzed
8.8
Google Chrome

Use after free in File Input in Google Chrome on Linux prior to 149

2026-06-18
CVE-2026-12439
Analyzed
8.8
Google Chrome

Use after free in Digital Credentials in Google Chrome prior to 149

2026-06-18
CVE-2026-12438
Analyzed
8.3
Google Chrome on Android

Inappropriate implementation in WebView in Google Chrome on Android prior to 149

2026-06-20
CVE-2026-12437
Analyzed
8.3
Microsoft Chrome

Use after free in WebShare in Google Chrome on Windows prior to 149

2026-06-20
CVE-2026-12417
Analyzed
9.8
WordPress SignUp & SignIn

The Pravel SignUp & SignIn WordPress plugin contains an authentication bypass vulnerability allowing unauthenticated attackers to reset any user passw...

2026-06-24
CVE-2026-12416
Analyzed
9.8
WordPress Invoice Generator

The Invoice Generator WordPress plugin contains an account takeover vulnerability via an insecure password reset function that allows unauthenticated...

2026-06-24
CVE-2026-12415
Analyzed
9.8
WordPress Invoice Generator

The Invoice Generator plugin for WordPress is vulnerable to unauthenticated privilege escalation, allowing attackers to modify arbitrary user accounts...

2026-06-27
CVE-2026-12411
Analyzed
8.4
Canonical LXD

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gue...

2026-06-27
CVE-2026-12407
Analyzed
8.8
WordPress Export Pdf Tool for WordPress

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1

2026-06-18
CVE-2026-1239
Analyzed
7.5
WordPress Ninja Forms

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing auth...

2026-07-01
CVE-2026-12382
Analyzed
8.2
Red Hat Red Hat Ansible Automation Platform

A flaw was found in the AAP Gateway Envoy proxy configuration

2026-07-17
CVE-2026-1238
7.2
WordPress is vulnerable

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, a...

2026-03-19
CVE-2026-12378
Analyzed
8.1
WordPress Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1

2026-07-09
CVE-2026-12375
Analyzed
9.8
WordPress Uncanny Automator Pro

The Uncanny Automator Pro WordPress plugin was distributed with a backdoor, allowing unauthenticated attackers to gain administrative access and exfil...

2026-07-08
CVE-2026-1233
Analyzed
7.5
WordPress is vulnerable

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and incl...

2026-04-05
CVE-2026-12291
Analyzed
8.8
Unknown Networking HTTP Component

Use-after-free in the Networking: HTTP component

2026-06-20
CVE-2026-12289
Analyzed
8.8
Mozilla Firefox/Thunderbird

Privilege escalation in the Graphics: WebRender component

2026-06-17
CVE-2026-12281
Analyzed
8.1
WordPress Shibboleth WordPress plugin

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating...

2026-07-18
CVE-2026-12277
Analyzed
8.7
WordPress Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23

2026-07-08
CVE-2026-12275
Analyzed
7.1
WordPress Tutor LMS

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private...

2026-07-16
CVE-2026-12257
Analyzed
9.3
Mura Software CMS

Mura Software CMS contains a critical remote code execution vulnerability via the “method” parameter in the “/index.cfm/_api/json/v1/default” endpoint...

2026-07-14
CVE-2026-12256
Analyzed
8.8
HP Avada

Contributor PHP Object Injection in Avada <= 3

2026-06-18
CVE-2026-12252
Analyzed
7.8
NLTK NLTK (Natural Language Toolkit)

In nltk/nltk versions 3

2026-07-04
CVE-2026-12250
Analyzed
7.9
TUBITAK BILGEM Pardus Domain Joiner

Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joine...

2026-07-06
CVE-2026-12249
Analyzed
8.3
Ubuntu ADSys

An issue was discovered in Canonical ADSys upstream versions through v0

2026-06-23
CVE-2026-12245
Analyzed
8.7
NLnet Labs NSD (Name Server Daemon)

NSD from version 4

2026-06-25
CVE-2026-12244
Analyzed
8.7
NLnet Labs NSD (Name Server Daemon)

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB...

2026-06-25
CVE-2026-12243
Analyzed
7.5
NLTK Project NLTK

NLTK version 3

2026-06-30
CVE-2026-12242
Analyzed
8.8
HP AdRotate Banner Manager

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5

2026-06-25
CVE-2026-12240
Analyzed
8
WordPress Export User Data Plugin

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize functio...

2026-06-30
CVE-2026-12228
Analyzed
8.7
Unknown lollms

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version)

2026-07-19
CVE-2026-12224
Analyzed
8.8
WordPress Dokan Pro

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5

2026-07-01
CVE-2026-12222
Analyzed
8
Yealink SIP-T46U

A vulnerability was determined in Yealink SIP-T46U 108

2026-06-15
CVE-2026-12221
Analyzed
8
Yealink SIP-T46U

A vulnerability was found in Yealink SIP-T46U 108

2026-06-15
CVE-2026-12220
Analyzed
8
Yealink SIP-T46U

A vulnerability has been found in Yealink SIP-T46U 108

2026-06-15
CVE-2026-1222
Analyzed
7.2
HP Multiple Products

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to uplo...

2026-01-20
CVE-2026-12218
Analyzed
8
Yealink SIP-T46U

A vulnerability was detected in Yealink SIP-T46U 108

2026-06-15
CVE-2026-12217
Analyzed
7.8
DVDFab Virtual Drive

A security vulnerability has been detected in DVDFab Virtual Drive 2

2026-06-15
CVE-2026-12214
Analyzed
7.8
Qihoo 360 Total Security

A security flaw has been discovered in Qihoo 360 Total Security 6

2026-06-15
CVE-2026-1221
Analyzed
9.8
PrismX Multiple Products

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote atta...

2026-01-20
CVE-2026-12204
Analyzed
7.3
HP ShopXO

A vulnerability was determined in ShopXO up to 6

2026-06-15
CVE-2026-12200
Analyzed
7.3
Ritlabs TinyWeb Server

A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1

2026-06-15