21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 9001-9050 of 21553 CVEs Page 181 of 432
CVE-2026-25172
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2026-03-11
CVE-2026-25166
7.8
Microsoft Multiple Products

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally

2026-03-11
CVE-2026-25165
7.8
Microsoft Multiple Products

Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-25164
8.1
HP Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-02-26
CVE-2026-25161
Analyzed
8.8
Unknown Alist

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs

2026-02-05
CVE-2026-25160
Analyzed
9.1
Alist Alist

Alist versions prior to 3.57.0 disable TLS certificate verification by default, exposing all outgoing storage driver communications to Man-in-the-Midd...

2026-02-05
CVE-2026-2516
Analyzed
7
Unknown path

A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2

2026-02-16
CVE-2026-25157
Analyzed
7.7
OpenClaw OpenClaw

OpenClaw is a personal AI assistant

2026-02-05
CVE-2026-25156
7.3
HotCRP Multiple Products

HotCRP is conference review software

2026-01-31
CVE-2026-25153
7.7
Unknown Multiple Products

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node

2026-01-31
CVE-2026-25150
Analyzed
9.3
Builder.io Qwik City

A prototype pollution vulnerability in the Qwik City middleware's formToObj() function allows unauthenticated attackers to manipulate Object.prototype...

2026-02-04
CVE-2026-25147
Analyzed
7.1
HP Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-02-28
CVE-2026-25146
Analyzed
9.6
OpenEMR OpenEMR

OpenEMR leaks gateway_api_key secrets in plaintext to the client, enabling unauthorized financial transactions and account takeovers of payment gatewa...

2026-03-04
CVE-2026-25143
Analyzed
7.8
Chainguard melange

melange allows users to build apk packages using declarative pipelines

2026-02-05
CVE-2026-25142
Analyzed
10
Docker Multiple Products

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain protot...

2026-02-03
CVE-2026-25140
Analyzed
7.5
Chainguard apko

apko allows users to build and publish OCI container images built from apk packages

2026-02-05
CVE-2026-25137
Analyzed
9.1
Unknown Multiple Products

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the d...

2026-02-03
CVE-2026-25136
8.1
Unknown Multiple Products

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies

2026-02-26
CVE-2026-25131
8.8
HP endpoint

OpenEMR is a free and open source electronic health records and medical practice management application

2026-02-25
CVE-2026-25130
Analyzed
9.6
F5 Multiple Products

Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple...

2026-01-31
CVE-2026-25128
7.5
Unknown Multiple Products

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

2026-01-31
CVE-2026-25126
7.1
PolarLearn Multiple Products

PolarLearn is a free and open-source learning program

2026-01-30
CVE-2026-25121
Analyzed
7.5
Chainguard apko

apko allows users to build and publish OCI container images built from apk packages

2026-02-05
CVE-2026-25116
7.6
Runtipi Multiple Products

Runtipi is a personal homeserver orchestrator

2026-01-30
CVE-2026-25114
7.5
Unknown Multiple Products

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests

2026-02-27
CVE-2026-25113
7.5
Unknown Multiple Products

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests

2026-02-27
CVE-2026-25111
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-2511
7.5
WordPress is vulnerable

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `s...

2026-03-28
CVE-2026-25109
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-25108
KEV Analyzed
8.8
Unknown Multiple Products

FileZen contains an OS command injection vulnerability

2026-02-13
CVE-2026-25105
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-25089
KEV Analyzed
9.8
Fortinet FortiSandbox

An OS command injection vulnerability in FortiSandbox allows unauthenticated attackers to execute unauthorized commands via specifically crafted HTTP...

2026-06-10
CVE-2026-25087
7
Apache Arrow

Use After Free vulnerability in Apache Arrow C++

2026-02-18
CVE-2026-25086
7.7
Under Multiple Products

Under certain conditions, an attacker could bind to the same port used by WebCTRL

2026-03-21
CVE-2026-25085
8.6
Pro Multiple Products

A vulnerability exists in Copeland XWEB Pro version 1

2026-02-27
CVE-2026-25084
Analyzed
9.8
ZLAN ZLAN5143D

The ZLAN5143D device is vulnerable to authentication bypass, allowing attackers to access internal URLs directly and gain unauthorized administrative...

2026-02-12
CVE-2026-25083
8.3
Unknown Multiple Products

GROWI OpenAI thread/message API endpoints do not perform authorization

2026-03-17
CVE-2026-25076
7.3
Unknown Multiple Products

Anchore Enterprise versions before 5

2026-03-15
CVE-2026-25075
7.5
Unknown Multiple Products

strongSwan versions 4

2026-03-24
CVE-2026-2507
7.5
Unknown Multiple Products

When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate

2026-02-19
CVE-2026-25060
Analyzed
8.1
OpenList Multiple Products

OpenList Frontend is a UI component for OpenList

2026-02-03
CVE-2026-25059
Analyzed
8.8
OpenList Multiple Products

OpenList Frontend is a UI component for OpenList

2026-02-03
CVE-2026-25058
7.5
Unknown Multiple Products

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API

2026-04-21
CVE-2026-25057
Analyzed
9.1
MarkUs MarkUs

MarkUs versions before 2.9.1 allow instructors to perform path traversal via malicious zip file uploads, enabling arbitrary file writes to the server...

2026-02-10
CVE-2026-25056
8.8
Merge Multiple Products

n8n is an open source workflow automation platform

2026-02-06
CVE-2026-25055
8.1
Unknown Multiple Products

n8n is an open source workflow automation platform

2026-02-06
CVE-2026-25039
Analyzed
8.8
Scille parsec-cloud

Parsec is a cloud-based application for simple and cryptographically secure file sharing

2026-07-21
CVE-2026-25038
Analyzed
7.5
Gitea Open Source Git Server

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

2026-07-08
CVE-2026-25037
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-25027
Analyzed
7.5
HP Program

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp all...

2026-02-05