21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 9351-9400 of 21553 CVEs Page 188 of 432
CVE-2026-23750
8.1
Pouch Multiple Products

Golioth Pouch version 0

2026-02-27
CVE-2026-23744
Analyzed
9.8
Unknown Multiple Products

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vul...

2026-01-17
CVE-2026-23742
Analyzed
8.8
Skipper Multiple Products

Skipper is an HTTP router and reverse proxy for service composition

2026-01-17
CVE-2026-23737
7.5
Unknown Multiple Products

seroval facilitates JS value stringification, including complex structures beyond JSON

2026-01-22
CVE-2026-23736
7.3
Unknown Multiple Products

seroval facilitates JS value stringification, including complex structures beyond JSON

2026-01-22
CVE-2026-23723
7.2
Unknown Multiple Products

WeGIA is a web manager for charitable institutions

2026-01-18
CVE-2026-23722
Analyzed
9.1
HP Multiple Products

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA s...

2026-01-17
CVE-2026-23720
7.8
Unknown Multiple Products

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)

2026-02-11
CVE-2026-23719
7.8
Unknown Multiple Products

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)

2026-02-11
CVE-2026-23718
7.8
Unknown Multiple Products

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)

2026-02-11
CVE-2026-23717
7.8
Unknown Multiple Products

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)

2026-02-11
CVE-2026-23716
7.8
Unknown Multiple Products

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)

2026-02-11
CVE-2026-23715
7.8
Unknown Multiple Products

A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512)

2026-02-11
CVE-2026-23703
7.8
FinalCode Multiple Products

The installer of FinalCode Client provided by Digital Arts Inc

2026-02-26
CVE-2026-23702
8
Pro Multiple Products

An OS command injection vulnerability exists in XWEB Pro version 1

2026-02-27
CVE-2026-2370
8.1
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14

2026-03-30
CVE-2026-23699
7.2
Unknown Multiple Products

AP180 series with firmware versions prior to AP_RGOS 11

2026-01-22
CVE-2026-23697
Analyzed
8.8
HP Vtiger CRM

Vtiger CRM before 8

2026-07-08
CVE-2026-23696
Analyzed
9.9
Unknown Multiple Products

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allow...

2026-04-08
CVE-2026-23693
Analyzed
10
WordPress plugin versions

The ElementsKit Lite plugin for WordPress exposes a REST endpoint without authentication, allowing unauthenticated attackers to use the site as an ope...

2026-02-24
CVE-2026-23689
Analyzed
7.7
SAP SAP NetWeaver

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network acce...

2026-02-10
CVE-2026-23687
Analyzed
8.8
SAP NetWeaver Application

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and s...

2026-02-10
CVE-2026-23678
8.8
Unknown Multiple Products

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic...

2026-02-25
CVE-2026-23673
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-23672
7.8
Microsoft Multiple Products

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

2026-03-11
CVE-2026-23669
8.8
Microsoft Multiple Products

Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network

2026-03-11
CVE-2026-23665
7.8
Microsoft Virtual Machines

Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-23660
7.8
Microsoft Portal Windows

Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-23659
8.6
Microsoft Data Factory

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a networ...

2026-03-20
CVE-2026-23658
8.6
Microsoft DevOps allows

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network

2026-03-20
CVE-2026-23657
7.8
Microsoft Office Word

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2026-04-15
CVE-2026-23654
8.8
GitHub Repo

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network

2026-03-11
CVE-2026-2365
7.2
WordPress is vulnerable

The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all ver...

2026-03-05
CVE-2026-23648
7.8
Glory Multiple Products

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions

2026-02-18
CVE-2026-23647
Analyzed
9.8
Linux system

Glory RBG-100 recycler systems use hardcoded OS credentials in the ISPK-08 software, allowing unauthenticated remote access and full system compromise...

2026-02-18
CVE-2026-23631
8.1
Redis is an

Redis is an in-memory data structure store

2026-05-07
CVE-2026-23625
Analyzed
8.7
Intel Multiple Products

OpenProject is an open-source, web-based project management software

2026-01-20
CVE-2026-2361
8
PostgreSQL Anonymizer contains

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function contai...

2026-02-12
CVE-2026-2360
8
Arch Multiple Products

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and...

2026-02-12
CVE-2026-23599
7.8
HP Multiple Products

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux

2026-02-18
CVE-2026-23595
Analyzed
8.8
Unknown Application API

An authentication bypass in the application API allows an unauthorized administrative account to be created

2026-02-18
CVE-2026-23593
Analyzed
7.5
HP Multiple Products

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view s...

2026-01-28
CVE-2026-23592
Analyzed
7.2
HP Multiple Products

Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code e...

2026-01-28
CVE-2026-23572
7.2
Apple Multiple Products

Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15

2026-02-06
CVE-2026-23562
Analyzed
9.4
Xen XAPI

Xen XAPI fails to perform necessary authorization checks for PCI passthrough configuration, allowing lower-privileged administrators to access uninten...

2026-07-10
CVE-2026-23561
Analyzed
9.4
Xen XAPI

A vulnerability in Xen XAPI allows a vm-admin to manipulate storage domain configurations, potentially causing host storage connections to be erroneou...

2026-07-10
CVE-2026-23560
Analyzed
9.4
Xen XAPI

A vulnerability in Xen XAPI allows a vm-admin to mark a VM as a system domain, which can cause the domain to be hidden from management tooling and per...

2026-07-10
CVE-2026-23559
Analyzed
9.4
Xen XAPI

A privilege escalation vulnerability in Xen XAPI allows a vm-admin to manipulate arbitrary files in dom0 by misconfiguring VBD settings, leading to un...

2026-07-10
CVE-2026-23558
Analyzed
7.8
Unknown Multiple Products

The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table v...

2026-05-20
CVE-2026-23556
Analyzed
9.4
Xen oxenstored

A resource leak in Xen oxenstored allows for improper node usage tracking during domain teardown, resulting in potential denial-of-service conditions...

2026-07-10