21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 8851-8900 of 21553 CVEs Page 178 of 432
CVE-2026-2579
7.5
WordPress is vulnerable

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all ve...

2026-03-17
CVE-2026-25787
Analyzed
9.1
Unknown Multiple Products

Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interf...

2026-05-13
CVE-2026-25786
Analyzed
9.1
Unknown Multiple Products

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This co...

2026-05-13
CVE-2026-25785
Analyzed
9.8
Path Lanscope Endpoint Manager (On-Premises)

A path traversal vulnerability in Lanscope Endpoint Manager allows attackers to tamper with arbitrary files. This flaw can be leveraged to execute arb...

2026-02-25
CVE-2026-25781
Analyzed
8.4
Unknown Multiple Products

in OpenHarmony v6

2026-05-19
CVE-2026-25778
7.3
Unknown Multiple Products

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sessi...

2026-02-28
CVE-2026-25776
Analyzed
9.8
Movable Type Movable Type

Six Apart Movable Type contains a code injection vulnerability that allows an authenticated attacker to execute arbitrary Perl scripts on the server.

2026-04-09
CVE-2026-25775
Analyzed
9.8
SenseLive X3050 Multiple Products

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication...

2026-04-24
CVE-2026-25773
Analyzed
8.1
Focalboard Focalboard

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8

2026-04-04
CVE-2026-25770
Analyzed
9.1
Wazuh Wazuh Manager

Wazuh Manager is vulnerable to privilege escalation where an authenticated node can overwrite the manager's configuration file to achieve Root Remote...

2026-03-18
CVE-2026-2577
Analyzed
10
SAP WhatsApp bridge

The Nanobot WhatsApp bridge component exposes an unauthenticated WebSocket server on all network interfaces, allowing remote attackers to hijack sessi...

2026-02-17
CVE-2026-25769
Analyzed
9.1
Arch Wazuh Manager

Wazuh deployments in cluster mode are vulnerable to Remote Code Execution via deserialization of untrusted data if a worker node is compromised.

2026-03-18
CVE-2026-25762
Analyzed
7.5
Unknown Multiple Products

AdonisJS is a TypeScript-first web framework

2026-02-07
CVE-2026-25761
8.8
GitHub Action or

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone

2026-02-10
CVE-2026-2576
7.5
WordPress plugin for

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment...

2026-02-18
CVE-2026-25759
8.7
Unknown Multiple Products

Statmatic is a Laravel and Git powered content management system (CMS)

2026-02-12
CVE-2026-25755
8.1
Unknown Multiple Products

jsPDF is a library to generate PDFs in JavaScript

2026-02-20
CVE-2026-25754
7.2
AdonisJS Multiple Products

AdonisJS is a TypeScript-first web framework

2026-02-07
CVE-2026-25748
Analyzed
8.6
Unknown Multiple Products

authentik is an open-source identity provider

2026-02-13
CVE-2026-25746
8.8
Unknown Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-02-26
CVE-2026-25741
7.1
Unknown Multiple Products

Zulip is an open-source team collaboration tool

2026-02-28
CVE-2026-25737
Analyzed
8.9
Budibase Budibase Platform

Budibase is a low code platform for creating internal tools, workflows, and admin panels

2026-03-10
CVE-2026-25733
7.3
Custom Multiple Products

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies

2026-02-26
CVE-2026-25732
Analyzed
7.5
Unknown Multiple Products

NiceGUI is a Python-based UI framework

2026-02-07
CVE-2026-25731
7.8
Unknown Multiple Products

calibre is an e-book manager

2026-02-07
CVE-2026-25726
Analyzed
8.1
Arch window for

Cloudreve is a self-hosted file management and sharing system

2026-04-04
CVE-2026-25721
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-25718
Analyzed
9.1
Gitea Open Source Git Server

Gitea versions before 1.25.5 improperly handle path resolution during template repository generation, allowing reads or writes through symlinks or non...

2026-07-08
CVE-2026-25715
Analyzed
9.8
Unknown (Network Device) Web Management Interface

The web management interface of an unidentified network device allows administrators to set blank passwords, enabling unauthenticated administrative a...

2026-02-21
CVE-2026-25712
Analyzed
7.5
Intel Open Source Git Server

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

2026-07-08
CVE-2026-25711
7.3
Unknown Multiple Products

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sessi...

2026-02-28
CVE-2026-25707
Analyzed
8.8
Unknown libzypp

A relative path traversal bug problem when processing repository metadata in libzypp before 17

2026-06-30
CVE-2026-25705
Analyzed
8.4
Rancher through

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager

2026-05-14
CVE-2026-25702
7.3
Linux Enterprise Server

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via...

2026-03-05
CVE-2026-2568
7.2
WordPress is vulnerable

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...

2026-03-04
CVE-2026-25676
7.8
Arch path

The installer of M-Track Duo HD version 1

2026-02-13
CVE-2026-25673
7.5
Unknown Multiple Products

An issue was discovered in 6

2026-03-04
CVE-2026-2567
Analyzed
7.2
Wavlink WL-NU516U1

A vulnerability was detected in Wavlink WL-NU516U1 20251208

2026-02-17
CVE-2026-2566
Analyzed
7.2
Wavlink WL-NU516U1

A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260

2026-02-17
CVE-2026-25656
7.8
Unknown Multiple Products

A vulnerability has been identified in SINEC NMS (All versions), User Management Component (UMC) (All versions < V2

2026-02-11
CVE-2026-25655
7.8
Unknown Multiple Products

A vulnerability has been identified in SINEC NMS (All versions < V4

2026-02-11
CVE-2026-25654
8.8
Unknown Multiple Products

A vulnerability has been identified in SINEC NMS (All versions < V4

2026-04-15
CVE-2026-25649
7.3
Unknown Multiple Products

Versions of the Traccar open-source GPS tracking system up to and including 6

2026-02-24
CVE-2026-25648
8.7
Unknown Multiple Products

Versions of the Traccar open-source GPS tracking system starting with 6

2026-02-24
CVE-2026-25644
Analyzed
7.5
Unknown Multiple Products

DataHub is an open-source metadata platform

2026-02-07
CVE-2026-25643
Analyzed
9.1
Frigate Frigate NVR

Critical RCE in Frigate NVR via unsanitized input in the go2rtc video stream configuration allows command injection via the exec: directive.

2026-02-07
CVE-2026-25641
Analyzed
10
SandboxJS SandboxJS

SandboxJS is vulnerable to an escape due to a key validation mismatch. Attackers can use malicious objects that coerce to different strings during san...

2026-02-07
CVE-2026-25640
7.1
Pydantic Multiple Products

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI

2026-02-07
CVE-2026-2564
Analyzed
8.1
Intel VIP 3260 Z IA 2

A security flaw has been discovered in Intelbras VIP 3260 Z IA 2

2026-02-17
CVE-2026-25639
7.5
HTTP Multiple Products

Axios is a promise based HTTP client for the browser and Node

2026-02-10