21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 8951-9000 of 21553 CVEs Page 180 of 432
CVE-2026-25414
8.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation

2026-03-27
CVE-2026-25406
8.8
Themeum Tutor LMS Pro Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse

2026-03-27
CVE-2026-25405
Analyzed
8.5
WordPress eRoom

Contributor SQL Injection in eRoom <= 1

2026-07-24
CVE-2026-25400
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection

2026-03-27
CVE-2026-2538
Analyzed
7
Arch path

A security flaw has been discovered in Flos Freeware Notepad2 4

2026-02-16
CVE-2026-25378
7.6
Nelio Software Nelio Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing...

2026-02-20
CVE-2026-25369
7.1
Flexmls Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flexmls Flexmls® IDX allows Reflected XSS

2026-03-17
CVE-2026-25366
Analyzed
9.9
HP allows Code

The Woody ad snippets plugin for WordPress is vulnerable to code injection. Attackers can exploit the insert-php component to execute arbitrary code o...

2026-03-26
CVE-2026-25360
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection

2026-03-27
CVE-2026-25359
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection

2026-03-27
CVE-2026-25358
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection

2026-03-27
CVE-2026-2533
Analyzed
7.3
HP Self-service Washing Machine 4

A flaw has been found in Tosei Self-service Washing Machine 4

2026-02-16
CVE-2026-25312
7.5
EventPrime Multiple Products

Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels

2026-03-19
CVE-2026-25293
Analyzed
9.6
Unknown Multiple Products

Buffer overflow due to incorrect authorization in PLC FW

2026-05-05
CVE-2026-25289
Analyzed
9.6
Qualcomm Snapdragon

A stack-based buffer overflow in Qualcomm Snapdragon occurs when processing Device Capability Extended attributes in NAN Service Discovery Frames with...

2026-08-05
CVE-2026-25277
Analyzed
8.8
Unknown Strongbox

Memory corruption while using Strongbox due to buffer overflow

2026-06-02
CVE-2026-25276
Analyzed
8.8
Unknown Strongbox

Memory corruption while using Strongbox due to missing bounds check

2026-06-02
CVE-2026-25271
Analyzed
7.8
Qualcomm Snapdragon

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use

2026-07-07
CVE-2026-25268
Analyzed
8.8
Qualcomm Snapdragon

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations

2026-07-07
CVE-2026-25253
Analyzed
8.8
OpenClaw Multiple Products

OpenClaw (aka clawdbot or Moltbot) before 2026

2026-02-02
CVE-2026-25244
Analyzed
9.8
WebdriverIO WebdriverIO

WebdriverIO versions below 9.24.0 are vulnerable to command injection via unsanitized branch names, leading to remote code execution in test orchestra...

2026-05-19
CVE-2026-25243
8.8
Redis is an

Redis is an in-memory data structure store

2026-05-07
CVE-2026-25242
Analyzed
9.8
Gogs Gogs Git Service

Gogs Git service exposes unauthenticated file upload endpoints by default, allowing remote users to upload arbitrary files and potentially exhaust dis...

2026-02-20
CVE-2026-25232
8.8
HP Multiple Products

Gogs is an open source self-hosted Git service

2026-02-20
CVE-2026-25231
7.5
Unknown Multiple Products

FileRise is a self-hosted web file manager / WebDAV server

2026-02-10
CVE-2026-25227
Analyzed
9.1
Unknown authentik

A privilege escalation vulnerability in authentik allows authenticated users with specific viewing permissions to execute arbitrary code via the prope...

2026-02-13
CVE-2026-25223
Analyzed
7.5
Unknown Multiple Products

Fastify is a fast and low overhead web framework, for Node

2026-02-04
CVE-2026-25212
Analyzed
9.9
Percona Percona Monitoring and Management (PMM)

A privilege escalation vulnerability in Percona PMM allows authenticated users with pmm-admin rights to execute arbitrary shell commands on the underl...

2026-04-03
CVE-2026-25208
8.1
Samsung Open Source

Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers

2026-04-13
CVE-2026-25207
7.4
Samsung Open Source

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers

2026-04-13
CVE-2026-25205
7.4
Samsung Open Source

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write

2026-04-13
CVE-2026-25203
7.8
Samsung MagicINFO

Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 2...

2026-04-10
CVE-2026-25202
Analyzed
9.8
Samsung Multiple Products

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects Ma...

2026-02-02
CVE-2026-25201
Analyzed
8.8
Samsung Multiple Products

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server

2026-02-02
CVE-2026-25200
Analyzed
9.8
Samsung Multiple Products

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in a...

2026-02-02
CVE-2026-25199
Analyzed
9.1
Apache CloudStack

The Proxmox extension for Apache CloudStack allows unauthorized cross-tenant access to virtual machines due to improper validation of the proxmox_vmid...

2026-05-09
CVE-2026-25197
Analyzed
9.1
Unknown Multiple Products

A specific API endpoint in the affected software allows authenticated users to pivot to other user profiles. By modifying the ID number in API calls,...

2026-04-04
CVE-2026-25196
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-25195
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-25192
Analyzed
9.4
OCPP Infrastructure WebSocket Endpoint

WebSocket endpoints in OCPP-compliant charging infrastructure lack authentication, allowing unauthenticated attackers to impersonate charging stations...

2026-03-21
CVE-2026-25191
7.8
FinalCode path

The installer of FinalCode Client provided by Digital Arts Inc

2026-02-26
CVE-2026-25190
7.8
Microsoft path in

Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally

2026-03-11
CVE-2026-25189
7.8
Microsoft Multiple Products

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-25188
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network

2026-03-11
CVE-2026-25187
7.8
Unknown Multiple Products

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-25177
8.8
Unknown Multiple Products

Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges ov...

2026-03-11
CVE-2026-25176
7.8
Microsoft Multiple Products

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-25175
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-25174
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-25173
8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2026-03-11