21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 9051-9100 of 21553 CVEs Page 182 of 432
CVE-2026-25022
Analyzed
8.5
Iqonic Design Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-managemen...

2026-02-04
CVE-2026-25007
8.5
Element Invader Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elemen...

2026-03-27
CVE-2026-25001
8.5
Unknown Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion

2026-03-26
CVE-2026-24981
8.8
NooTheme Visionary Multiple Products

Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection

2026-03-27
CVE-2026-24978
8.8
NooTheme Jobica Core Multiple Products

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection

2026-03-27
CVE-2026-24977
8.5
NooTheme Organici Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library a...

2026-03-27
CVE-2026-24976
8.8
NooTheme Organici Multiple Products

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection

2026-03-27
CVE-2026-24974
8.8
NooTheme CitiLights Multiple Products

Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection

2026-03-27
CVE-2026-2497
Analyzed
7.2
WordPress Gallery by BestWebSoft

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions...

2026-08-16
CVE-2026-24959
8.5
JoomSky JS Help Desk Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Bl...

2026-02-21
CVE-2026-24954
Analyzed
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection

2026-02-04
CVE-2026-24950
7.5
Unknown Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in themeplugs Authorsy authorsy allows Exploiting Incorrectly Configured Access Control...

2026-02-21
CVE-2026-2495
7.5
WordPress is vulnerable

The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable to SQL Injection via the 'orde...

2026-02-18
CVE-2026-24941
7.5
Job Multiple Products

Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels

2026-02-21
CVE-2026-24930
8.4
Unknown Multiple Products

UAF concurrency vulnerability in the graphics module

2026-02-06
CVE-2026-2493
7.5
Infor Multiple Products

IceWarp collaboration Directory Traversal Information Disclosure Vulnerability

2026-03-17
CVE-2026-24926
8.4
Unknown Multiple Products

Out-of-bounds write vulnerability in the camera module

2026-02-06
CVE-2026-24925
7.3
Unknown Multiple Products

Heap-based buffer overflow vulnerability in the image module

2026-02-06
CVE-2026-24913
8.8
MATCHA Multiple Products

SQL Injection vulnerability exists in MATCHA INVOICE 2

2026-04-08
CVE-2026-24908
Analyzed
9.9
Infor OpenEMR

An SQL injection vulnerability in the OpenEMR Patient REST API allows authenticated users to execute arbitrary queries and access protected health inf...

2026-02-26
CVE-2026-24902
Analyzed
7.1
Unknown Multiple Products

TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0

2026-01-30
CVE-2026-24901
8.1
Infor Multiple Products

Outline is a service that allows for collaborative documentation

2026-03-18
CVE-2026-24898
Analyzed
10
Unknown OpenEMR (MedEx Module)

An unauthenticated token disclosure in OpenEMR's MedEx callback endpoint leaks API tokens, leading to PHI exfiltration and HIPAA violations.

2026-03-04
CVE-2026-24897
Analyzed
10
HP Multiple Products

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files...

2026-01-29
CVE-2026-24893
8.8
Unknown Multiple Products

openITCOCKPIT is an open source monitoring tool built for different monitoring engines

2026-04-15
CVE-2026-24892
7.5
HP deserialization pattern

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus

2026-02-21
CVE-2026-24891
7.5
HP Object Injection

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus

2026-02-21
CVE-2026-24890
8.1
Unknown Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-02-26
CVE-2026-24884
Analyzed
8.4
Arch Compressing

Compressing is a compressing and uncompressing lib for node

2026-02-05
CVE-2026-24882
8.4
GnuPG Multiple Products

In GnuPG before 2

2026-01-28
CVE-2026-24881
8.1
GnuPG Multiple Products

In GnuPG before 2

2026-01-28
CVE-2026-24880
7.5
Apache Tomcat via

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension

2026-04-11
CVE-2026-24875
7.8
Unknown Multiple Products

Integer Overflow or Wraparound vulnerability in yoyofr modizer

2026-01-28
CVE-2026-24874
Analyzed
9.1
Unknown Multiple Products

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2...

2026-01-28
CVE-2026-24873
7.8
Rinnegatamante Multiple Products

Out-of-bounds Read vulnerability in Rinnegatamante lpp-vita

2026-01-28
CVE-2026-24872
Analyzed
9.8
Unknown Multiple Products

improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.

2026-01-28
CVE-2026-24869
8.1
Unknown Multiple Products

Use-after-free in the Layout: Scrolling and Overflow component

2026-01-28
CVE-2026-24868
7.5
Mitigation Multiple Products

Mitigation bypass in the Privacy: Anti-Tracking component

2026-01-29
CVE-2026-24858
KEV Analyzed
9.8
Apple Multiple Products

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Forti...

2026-01-28
CVE-2026-24856
7.8
Unknown Multiple Products

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles

2026-01-29
CVE-2026-24854
Analyzed
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2026-01-31
CVE-2026-24853
Analyzed
8.1
Caido Caido

Caido is a web security auditing toolkit

2026-02-14
CVE-2026-24849
Analyzed
9.9
HP OpenEMR

An arbitrary file read vulnerability in OpenEMR allows any authenticated user to access sensitive files on the server filesystem via the EtherFax comp...

2026-02-25
CVE-2026-24844
Analyzed
7.9
Chainguard Melange

melange allows users to build apk packages using declarative pipelines

2026-02-05
CVE-2026-24843
Analyzed
8.2
Chainguard Melange

melange allows users to build apk packages using declarative pipelines

2026-02-05
CVE-2026-24842
8.2
Unknown Multiple Products

node-tar,a Tar for Node

2026-01-28
CVE-2026-24841
Analyzed
9.9
Docker Multiple Products

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokpl...

2026-01-28
CVE-2026-24840
8
Dokploy Multiple Products

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-01-28
CVE-2026-24838
Analyzed
9.1
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, m...

2026-01-28
CVE-2026-24837
Analyzed
7.6
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-01-28