21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 9151-9200 of 21553 CVEs Page 184 of 432
CVE-2026-24624
7.2
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforum neoforum allows Blind SQL In...

2026-01-24
CVE-2026-24609
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent...

2026-01-24
CVE-2026-24608
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core la...

2026-01-24
CVE-2026-24572
Analyzed
8.8
Nelio Software Nelio Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio Content nelio-content allow...

2026-01-24
CVE-2026-24552
Analyzed
8.5
WordPress Create by Mediavine

Contributor SQL Injection in Create by Mediavine <= 2

2026-07-24
CVE-2026-24517
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-24516
8.8
Agent Droplet Agent

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1

2026-03-25
CVE-2026-24512
Analyzed
8.8
Nginx cthe

A security issue was discovered in ingress-nginx cthe `rules

2026-02-04
CVE-2026-24506
7.2
Dell PowerProtect Data

Dell PowerProtect Data Domain, versions 7

2026-04-21
CVE-2026-24505
7.2
Dell PowerProtect Data

Dell PowerProtect Data Domain, versions 8

2026-04-21
CVE-2026-24504
7.2
Dell PowerProtect Data

Dell PowerProtect Data Domain, versions 7

2026-04-21
CVE-2026-24502
Analyzed
8.8
Dell vPro Out

Dell Command | Intel vPro Out of Band, versions prior to 4

2026-03-04
CVE-2026-24494
Analyzed
9.8
Unknown Online Ordering System

An unauthenticated SQL injection vulnerability exists in the Order Up Online Ordering System 1.0 via the store_id parameter in the /api/integrations/g...

2026-02-23
CVE-2026-24491
7.5
Unknown Multiple Products

FreeRDP is a free implementation of the Remote Desktop Protocol

2026-02-11
CVE-2026-24490
8.1
MobSF Multiple Products

MobSF is a mobile application security testing tool used

2026-01-27
CVE-2026-24486
Analyzed
8.6
Unknown Multiple Products

Python-Multipart is a streaming multipart parser for Python

2026-01-27
CVE-2026-24485
7.5
Arch Multiple Products

ImageMagick is free and open-source software used for editing and manipulating digital images

2026-02-24
CVE-2026-24481
Analyzed
7.5
Adobe Photoshop

ImageMagick is free and open-source software used for editing and manipulating digital images

2026-02-24
CVE-2026-2448
8.8
WordPress is vulnerable

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2

2026-03-03
CVE-2026-24478
7.2
AnythingLLM Multiple Products

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting

2026-01-27
CVE-2026-24470
Analyzed
8.1
Skipper Multiple Products

Skipper is an HTTP router and reverse proxy for service composition

2026-01-27
CVE-2026-2447
8.8
Unknown Multiple Products

Heap buffer overflow in libvpx

2026-02-18
CVE-2026-24469
7.5
HTTP Multiple Products

C++ HTTP Server is an HTTP/1

2026-01-24
CVE-2026-24467
Analyzed
9
AWS Multiple Products

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in ver...

2026-04-21
CVE-2026-24465
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.

2026-02-03
CVE-2026-2446
Analyzed
9.8
WordPress plugin before

The PowerPack for LearnDash WordPress plugin before 1.3.0 lacks authorization and CSRF checks in an AJAX action, allowing unauthenticated users to cre...

2026-03-07
CVE-2026-24458
7.5
Mattermost Multiple Products

Mattermost versions 11

2026-03-17
CVE-2026-24455
Analyzed
7.5
Unknown Multiple Products

The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication

2026-02-21
CVE-2026-24452
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-24451
Analyzed
9.1
Intel Gitea Open Source Git Server

A vulnerability in Gitea 1.26.2 allows unauthorized data access by failing to terminate fork synchronization when a parent repository transitions from...

2026-07-07
CVE-2026-24450
8.1
LibRaw Multiple Products

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2

2026-04-08
CVE-2026-24448
Analyzed
9.8
Mitsubishi Electric MR-GM Series Routers (MR-GM5L-S1, MR-GM5A-L1)

The use of hard-coded credentials in Mitsubishi Electric MR-GM series routers allows attackers to gain unauthorized administrative access to the devic...

2026-03-11
CVE-2026-24445
7.5
Unknown Multiple Products

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests

2026-02-27
CVE-2026-24444
Analyzed
9.8
HP Multiple Products

SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interfac...

2026-05-29
CVE-2026-24443
8.8
Unknown Multiple Products

EventSentry versions prior to 6

2026-02-26
CVE-2026-24425
Analyzed
8.8
HP callables to

Twig versions 2

2026-05-21
CVE-2026-24423
KEV
9.5
SmarterTools SmarterMail

SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.

2026-02-06
CVE-2026-24412
8.8
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-24
CVE-2026-24411
7.1
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-25
CVE-2026-24410
7.1
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-25
CVE-2026-2441
KEV Analyzed
8.8
Google Chrome prior

Use after free in CSS in Google Chrome prior to 145

2026-02-14
CVE-2026-24409
7.1
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-25
CVE-2026-24407
7.1
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-25
CVE-2026-24406
8.8
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-24
CVE-2026-24405
8.8
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-24
CVE-2026-24404
7.1
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-25
CVE-2026-24403
7.1
Unknown Multiple Products

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles

2026-01-25
CVE-2026-2440
7.2
WordPress is vulnerable

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2

2026-03-22
CVE-2026-24399
Analyzed
9.3
Unknown Multiple Products

ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malicious HTML/JavaScript payloads...

2026-01-24
CVE-2026-24367
8.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL In...

2026-01-24