18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 9151-9200 of 18466 CVEs Page 184 of 370
CVE-2026-0661
Analyzed
7.8
Intel 3ds Max

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability

2026-02-05
CVE-2026-0660
Analyzed
7.8
Intel 3ds Max

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability

2026-02-05
CVE-2026-0659
Analyzed
7.8
Intel Arnold and 3ds Max

A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability

2026-02-05
CVE-2026-0656
Analyzed
8.2
WordPress Multiple Products

The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2

2026-01-08
CVE-2026-0648
7.8
Unknown Multiple Products

The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_o...

2026-01-28
CVE-2026-0643
7.3
Property Multiple Products

A flaw has been found in projectworlds House Rental and Property Listing 1

2026-01-08
CVE-2026-0640
8.8
Tenda Multiple Products

A weakness has been identified in Tenda AC23 16

2026-01-07
CVE-2026-0634
7.8
Google Multiple Products

Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection

2026-04-03
CVE-2026-0628
Analyzed
8.8
Google Multiple Products

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143

2026-01-08
CVE-2026-0617
Analyzed
7.2
WordPress Multiple Products

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer...

2026-02-03
CVE-2026-0616
7.5
TheLibrarians Multiple Products

TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into the internal TheLibrarian backe...

2026-01-18
CVE-2026-0615
7.3
Librarian Multiple Products

The Librarian `supervisord` status page can be retrieved by the `web_fetch` tool, which can be used to retrieve running processes within TheLibrarian...

2026-01-18
CVE-2026-0613
7.5
Librarian Multiple Products

The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to per...

2026-01-18
CVE-2026-0612
Analyzed
7.5
Librarian Multiple Products

The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content prov...

2026-01-18
CVE-2026-0611
Analyzed
9.8
Spacelabs Healthcare Sentinel

Spacelabs Healthcare Sentinel contains an unauthenticated RCE vulnerability via a deprecated .NET Remoting HTTP channel, allowing attackers to write w...

2026-06-03
CVE-2026-0607
7.3
Unknown Multiple Products

A flaw has been found in code-projects Online Music Site 1

2026-01-06
CVE-2026-0606
7.3
Unknown Multiple Products

A vulnerability was detected in code-projects Online Music Site 1

2026-01-06
CVE-2026-0605
7.3
Unknown Multiple Products

A security vulnerability has been detected in code-projects Online Music Site 1

2026-01-06
CVE-2026-0603
8.3
Unknown Multiple Products

A flaw was found in Hibernate

2026-01-23
CVE-2026-0599
Analyzed
7.5
Unknown Multiple Products

A vulnerability in huggingface/text-generation-inference version 3

2026-02-02
CVE-2026-0596
Analyzed
9.6
MLflow MLflow

MLflow is vulnerable to command injection when serving models with `enable_mlserver=True`. Shell metacharacters in the `model_uri` allow for arbitrary...

2026-04-01
CVE-2026-0592
7.3
Unknown Multiple Products

A security flaw has been discovered in code-projects Online Product Reservation System 1

2026-01-06
CVE-2026-0589
7.3
Unknown Multiple Products

A vulnerability was found in code-projects Online Product Reservation System 1

2026-01-06
CVE-2026-0585
7.3
Unknown Multiple Products

A security vulnerability has been detected in code-projects Online Product Reservation System 1

2026-01-06
CVE-2026-0583
7.3
Unknown Multiple Products

A security flaw has been discovered in code-projects Online Product Reservation System 1

2026-01-06
CVE-2026-0579
Analyzed
7.3
Unknown Multiple Products

A vulnerability was found in code-projects Online Product Reservation System 1

2026-01-05
CVE-2026-0578
Analyzed
7.3
Unknown Multiple Products

A vulnerability has been found in code-projects Online Product Reservation System 1

2026-01-05
CVE-2026-0576
Analyzed
7.3
Unknown Multiple Products

A vulnerability was detected in code-projects Online Product Reservation System 1

2026-01-04
CVE-2026-0575
Analyzed
7.3
Unknown Multiple Products

A security vulnerability has been detected in code-projects Online Product Reservation System 1

2026-01-04
CVE-2026-0570
Analyzed
7.3
Unknown Multiple Products

A vulnerability was found in code-projects Online Music Site 1

2026-01-03
CVE-2026-0569
Analyzed
7.3
Unknown Multiple Products

A vulnerability has been found in code-projects Online Music Site 1

2026-01-03
CVE-2026-0568
Analyzed
7.3
Unknown Multiple Products

A flaw has been found in code-projects Online Music Site 1

2026-01-03
CVE-2026-0567
Analyzed
7.3
Unknown Multiple Products

A vulnerability was detected in code-projects Content Management System 1

2026-01-03
CVE-2026-0565
Analyzed
7.3
Unknown Multiple Products

A weakness has been identified in code-projects Content Management System 1

2026-01-03
CVE-2026-0562
8.3
Unknown Multiple Products

A critical security vulnerability in parisneo/lollms versions up to 2

2026-03-30
CVE-2026-0560
7.5
Unknown Multiple Products

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2

2026-03-30
CVE-2026-0558
7.5
Unknown Multiple Products

A vulnerability in parisneo/lollms, up to and including version 2

2026-03-30
CVE-2026-0546
7.3
Unknown Multiple Products

A vulnerability was determined in code-projects Content Management System 1

2026-01-02
CVE-2026-0545
Analyzed
9.1
Arch MLflow

An authentication bypass in MLflow's FastAPI job endpoints allows unauthenticated attackers to submit and execute jobs, potentially leading to remote...

2026-04-04
CVE-2026-0544
7.3
Unknown Multiple Products

A security flaw has been discovered in itsourcecode School Management System 1

2026-01-01
CVE-2026-0538
Analyzed
7.8
Intel 3ds Max

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability

2026-02-05
CVE-2026-0537
Analyzed
7.8
Intel 3ds Max

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability

2026-02-05
CVE-2026-0536
Analyzed
7.8
Unknown 3ds Max

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability

2026-02-05
CVE-2026-0532
Analyzed
8.6
Google Multiple Products

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file discl...

2026-01-15
CVE-2026-0511
8.1
SAP Multiple Products

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation o...

2026-01-13
CVE-2026-0509
Analyzed
9.6
SAP NetWeaver Application

SAP NetWeaver AS ABAP allows low-privileged authenticated users to execute Remote Function Calls (RFC) without proper S_RFC authorization, impacting s...

2026-02-10
CVE-2026-0508
Analyzed
7.3
Intel BusinessObjects Business Intelligence Platform

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the applic...

2026-02-10
CVE-2026-0507
Analyzed
8.4
SAP Multiple Products

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrativ...

2026-01-13
CVE-2026-0506
8.1
Unknown Multiple Products

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC functio...

2026-01-13
CVE-2026-0501
Analyzed
9.9
SAP Multiple Products

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute craf...

2026-01-13