21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 901-950 of 21637 CVEs Page 19 of 433
CVE-2026-73222
Analyzed
8.8
Unknown claude-code-templates

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code

2026-08-12
CVE-2026-73211
Analyzed
9.8
Chocobozzz PeerTube

An SQL injection vulnerability in the PeerTube ActorFollowModel allows unauthenticated remote servers to execute arbitrary database queries and take o...

2026-08-12
CVE-2026-7321
Analyzed
9.6
Mozilla Firefox, Thunderbird

A sandbox escape vulnerability in the WebRTC networking component allows attackers to bypass security boundaries.

2026-04-29
CVE-2026-7320
7.5
Infor Multiple Products

Information disclosure due to incorrect boundary conditions in the Audio/Video component

2026-04-29
CVE-2026-73160
Analyzed
8.7
MISP cti-transmute

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints

2026-08-12
CVE-2026-7313
Analyzed
8.7
Progress Sitefinity

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8

2026-06-04
CVE-2026-7312
Analyzed
10
Progress Sitefinity

Progress Sitefinity web services contain a vulnerability that allows unauthenticated remote attackers to retrieve plain-text credentials for the Sitef...

2026-06-03
CVE-2026-7311
Analyzed
8.1
WordPress JPEG, PNG & WebP image compression plugin

The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio...

2026-07-03
CVE-2026-73081
Analyzed
8.7
Activepieces Activepieces

Activepieces is an open source AI workflow automation platform

2026-08-12
CVE-2026-7307
Analyzed
7.5
Unknown Multiple Products

A flaw was found in Keycloak

2026-05-20
CVE-2026-73062
Analyzed
7.5
Scriban Scriban

Scriban versions 3

2026-08-17
CVE-2026-73061
Analyzed
9.8
Unknown scriban

The Scriban template engine contains an access-modifier bypass vulnerability in TypedObjectAccessor, allowing unauthenticated attackers to perform una...

2026-08-17
CVE-2026-73060
Analyzed
7.5
Scriban Scriban

Scriban versions from 3

2026-08-17
CVE-2026-73057
Analyzed
7.5
Unknown stoatchat

stoatchat before 0

2026-08-17
CVE-2026-73056
Analyzed
9.8
Unknown siyuan

The SiYuan kernel before 3.7.4 fails to restrict excessive authentication attempts, allowing unauthenticated attackers to brute-force API tokens and g...

2026-08-17
CVE-2026-73054
Analyzed
7.5
SiYuan SiYuan

SiYuan versions before v3

2026-08-16
CVE-2026-73053
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 are susceptible to cross-site scripting in the unicode2Emoji function, allowing arbitrary code execution in the renderer.

2026-08-16
CVE-2026-73052
Analyzed
9
Unknown siyuan

A stored cross-site scripting vulnerability in SiYuan allows authenticated attackers to execute arbitrary JavaScript by injecting malicious markup int...

2026-08-16
CVE-2026-73050
Analyzed
9
Unknown siyuan

SiYuan before v3.7.4 contains a stored Cross-site Scripting vulnerability in the attribute-view select option color field, allowing arbitrary JavaScri...

2026-08-16
CVE-2026-73046
Analyzed
9.8
Unknown siyuan

The SiYuan CheckAuth middleware fails to enforce rate limiting or account lockout for HTTP Basic Authentication, allowing unauthenticated attackers to...

2026-08-16
CVE-2026-73045
Analyzed
7.5
SiYuan SiYuan

SiYuan before 3

2026-08-16
CVE-2026-73044
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 are vulnerable to stored cross-site scripting via the setAttrViewColWidth API, which can lead to arbitrary code execution...

2026-08-16
CVE-2026-73043
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 contain a remote code execution vulnerability in the Template calculation operator, allowing execution of arbitrary code...

2026-08-16
CVE-2026-73042
Analyzed
9
Unknown siyuan

SiYuan before v3.7.4 is vulnerable to stored Cross-site Scripting via improperly escaped database menu metadata, allowing execution of arbitrary code...

2026-08-16
CVE-2026-73041
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 allow arbitrary code execution via malicious PDF annotations that trigger script execution in the PDF renderer with Node....

2026-08-16
CVE-2026-73040
Analyzed
8.8
Unknown dockge

Dockge validates a stack name only on the write path

2026-08-21
CVE-2026-7304
Analyzed
9.8
SGLangs Multimodal Generation Runtime

The SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when custom logit processing is enabled, due to unsaf...

2026-05-19
CVE-2026-73034
Analyzed
9.8
Unknown DB-GPT

DB-GPT v0.8.1 is vulnerable to an unauthenticated path traversal attack that allows remote attackers to write arbitrary files to the server via the us...

2026-08-12
CVE-2026-73031
Analyzed
8.7
GramSearch telegram-search

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers...

2026-08-12
CVE-2026-73030
Analyzed
8.1
Unknown unearth

unearth through 0

2026-08-11
CVE-2026-7302
Analyzed
9.1
SGLangs Multimodal Generation Runtime

The SGLangs runtime is vulnerable to an unauthenticated path traversal attack, allowing remote attackers to write arbitrary files to the server's file...

2026-05-19
CVE-2026-7301
Analyzed
9.8
SGLangs Multimodal Generation Runtime

The SGLangs scheduler binds its ROUTER socket to 0.0.0.0 and performs unsafe pickle deserialization on incoming messages, enabling unauthenticated rem...

2026-05-19
CVE-2026-72970
Analyzed
8.3
Microsoft Microsoft Edge (Chromium-based)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-08-16
CVE-2026-72920
Analyzed
9.8
Unknown seaweedfs

SeaweedFS prior to 4.24 fails to enforce authentication on the gRPC IdentityAccessManagement service when the signing key is unset, allowing unauthori...

2026-08-12
CVE-2026-72915
Analyzed
7.5
Mastodon Mastodon

Mastodon is a free, open-source social network server based on ActivityPub

2026-08-11
CVE-2026-72914
Analyzed
7.5
Mastodon Mastodon

Mastodon is a free, open-source social network server based on ActivityPub

2026-08-11
CVE-2026-72913
Analyzed
7.3
Unknown kitty

Kitty is a cross-platform GPU based terminal

2026-08-11
CVE-2026-72911
Analyzed
9.9
Unknown erpnext

ERPNext contains a template injection vulnerability that allows authenticated users to execute arbitrary server-side code by manipulating template par...

2026-08-11
CVE-2026-72904
Analyzed
9.3
Unknown firecrawl

An arbitrary file read and SSRF vulnerability in Firecrawl prior to 2.11.32 allows unauthenticated attackers to read local files via malicious JSON sc...

2026-08-11
CVE-2026-72903
Analyzed
8.1
Eugeny tabby

Tabby (formerly Terminus) is a highly configurable terminal emulator

2026-08-11
CVE-2026-72902
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection via the registry testing functions, allowing authenticated users to execute arb...

2026-08-11
CVE-2026-72901
Analyzed
9.9
Docker dokploy

Dokploy versions prior to 0.29.13 are susceptible to OS command injection via the volume backup functionality, allowing authenticated low-privilege us...

2026-08-11
CVE-2026-72899
Analyzed
10
Metabase Metabase

Metabase contains an SQL injection vulnerability allowing unauthenticated attackers to execute arbitrary SQL commands via manipulated field-filter par...

2026-08-11
CVE-2026-72898
KEV Analyzed
10
Metabase Metabase

Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full admi...

2026-08-11
CVE-2026-7289
8.8
D-Link DIR

A vulnerability was found in D-Link DIR-825M 1

2026-04-29
CVE-2026-72886
Analyzed
9.9
Dokploy dokploy

An improper privilege management vulnerability in Dokploy allows authenticated users to escalate privileges and execute arbitrary scripts as root on t...

2026-08-11
CVE-2026-72884
Analyzed
8.7
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72883
Analyzed
8.8
Dokploy Dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72882
Analyzed
9.9
Dokploy dokploy

Dokploy versions 0.28.8 and earlier are vulnerable to OS command injection via the filePath parameter, allowing authenticated users to execute arbitra...

2026-08-11
CVE-2026-72880
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 contain an arbitrary file write and deletion vulnerability due to improper input validation in the certificate managem...

2026-08-11