20685 Total CVEs
11938 AI Analyzed
298 CISA KEV
4466 Critical
All Vendors
Showing 9651-9700 of 20685 CVEs Page 194 of 414
CVE-2026-18642
Analyzed
7.8
TUBITAK BILGEM eta-otp-lock

Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection

2026-08-04
CVE-2026-18621
Analyzed
7.6
Red Hat OpenShift AI

A flaw was found in Data Science Pipelines (DSP)

2026-08-11
CVE-2026-1862
Analyzed
8.8
Google Chrome prior

Type Confusion in V8 in Google Chrome prior to 144

2026-02-04
CVE-2026-18618
Analyzed
7.5
Red Hat OpenShift AI

A flaw was found in ml-metadata

2026-08-11
CVE-2026-18617
Analyzed
8.8
Red Hat OpenShift AI

A flaw was found in the Data Science Pipelines Operator (DSPO)

2026-08-11
CVE-2026-18616
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attacker...

2026-08-04
CVE-2026-18615
Analyzed
9.8
GitHub GL-MT3000

An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.ge...

2026-08-04
CVE-2026-18614
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands...

2026-08-04
CVE-2026-18613
Analyzed
9.8
GitHub GL-MT3000

A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attacker...

2026-08-04
CVE-2026-18612
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary co...

2026-08-04
CVE-2026-18611
Analyzed
7.5
Red Hat OpenShift AI

A flaw was found in the Data Science Pipelines Operator

2026-08-11
CVE-2026-1861
Analyzed
8.8
Google Chrome prior

Heap buffer overflow in libvpx in Google Chrome prior to 144

2026-02-04
CVE-2026-18608
Analyzed
8.7
Red Hat OpenShift AI

A flaw was found in the Data Science Pipelines Operator (DSPO)

2026-08-11
CVE-2026-18607
Analyzed
8.8
Wavlink WN572, WN570H, WN573, WN529, WN530, WN531

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc

2026-08-04
CVE-2026-18606
Analyzed
7.8
Razer RzUpdateService

A weakness has been identified in Razer RzUpdateService 1

2026-08-04
CVE-2026-18602
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attacker...

2026-08-04
CVE-2026-18601
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the GL.iNet GL-MT3000 ovpn-client.so plugin allows unauthenticated remote attackers to execute arbitrary code via...

2026-08-04
CVE-2026-18600
Analyzed
8.8
GL.iNet GL-MT3000

A vulnerability has been found in GL

2026-08-04
CVE-2026-18599
Analyzed
8
GitHub GL-MT3000

A flaw has been found in GL

2026-08-04
CVE-2026-18598
Analyzed
8.8
GL.iNet GL-MT3000

A vulnerability was detected in GL

2026-08-04
CVE-2026-18597
Analyzed
8.5
Foxit Foxit PDF Services API

The PDF creation feature of Foxit PDF Services API supports referencing external files

2026-08-06
CVE-2026-18589
Analyzed
9.8
GitHub WL-NU516U1

A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the...

2026-08-03
CVE-2026-18588
Analyzed
9.8
GitHub WL-NU516U1

The Wavlink WL-NU516U1 router contains a stack-based buffer overflow vulnerability in the nas.cgi file, which can be triggered by manipulating the CON...

2026-08-03
CVE-2026-18587
Analyzed
7.5
GitHub WL-NU516U1

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628

2026-08-03
CVE-2026-18577
KEV Analyzed
8.2
N-able N-central

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026

2026-08-03
CVE-2026-18574
Analyzed
9.3
Check Point Security Management Server and Multi-Domain Security Management Server

An authentication bypass vulnerability in Check Point Security Management Server allows unauthenticated remote attackers to execute arbitrary commands...

2026-08-04
CVE-2026-18568
Analyzed
7.5
TIMLEGGE XML::Sig

XML::Sig versions from 0

2026-08-04
CVE-2026-18556
KEV Analyzed
8.2
N-able N-central

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass

2026-08-02
CVE-2026-18481
Analyzed
7.3
AWS AWS Ops Wheel

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal sessio...

2026-08-02
CVE-2026-18470
Analyzed
7.5
WordPress Login & Register Forms

The Login & Register Forms WordPress plugin before 4

2026-08-11
CVE-2026-18452
Analyzed
10
Rich Source DMS+ (Non-Mobile)

DMS+ (Non-Mobile) contains hardcoded credentials that allow unauthenticated remote attackers to gain full administrative control over the device.

2026-07-31
CVE-2026-18446
Analyzed
7.5
Unknown fast-uri

fast-uri before 4

2026-08-01
CVE-2026-1844
Analyzed
7.2
Google is vulnerable

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page...

2026-02-14
CVE-2026-1843
Analyzed
7.2
WordPress is vulnerable

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5

2026-02-14
CVE-2026-18411
Analyzed
8.1
Acrisure KARR BT and DR-100

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices

2026-08-06
CVE-2026-1841
Analyzed
7.2
Google is vulnerable

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource'...

2026-02-14
CVE-2026-18394
Analyzed
7.4
AWS Strands Agents Tools

Incorrect authorization in the http_request tool in Strands Agents Tools before 0

2026-08-02
CVE-2026-18381
Analyzed
7.6
Red Hat Cost Management Metrics Operator

A flaw was found in the koku-metrics-operator for Red Hat OpenShift

2026-08-01
CVE-2026-18378
Analyzed
7.6
Red Hat Cost Management Metrics Operator

A flaw was found in koku-metrics-operator

2026-08-01
CVE-2026-18361
Analyzed
7.6
Unknown iris-web

The IRIS web application in version 2

2026-08-01
CVE-2026-18360
Analyzed
7.6
GitHub iris-web

The IRIS web application in version 2

2026-08-01
CVE-2026-18359
Analyzed
8.5
Scripta eScriptorium

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26

2026-08-06
CVE-2026-18358
Analyzed
7.5
Red Hat gnome-remote-desktop

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux

2026-08-01
CVE-2026-18353
Analyzed
8.8
Eclipse Eclipse CSI - PIA

PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlpa...

2026-07-30
CVE-2026-18352
Analyzed
7.5
WordPress User Access Manager

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2

2026-08-02
CVE-2026-18322
Analyzed
8.8
WordPress Smart Popup by Supsystic

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-08-05
CVE-2026-1830
Analyzed
9.8
WordPress is vulnerable

The Quick Playground plugin for WordPress contains an RCE vulnerability due to insufficient authorization on REST API endpoints, allowing unauthentica...

2026-04-09
CVE-2026-1829
Analyzed
8.8
WordPress Content Visibility for Divi Builder

The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4

2026-06-03
CVE-2026-18258
Analyzed
8.8
Scripta eScriptorium

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26

2026-08-06
CVE-2026-18248
Analyzed
9.1
Unknown aws-lambda

The @fastify/aws-lambda package in version 6.4.0 allows unauthenticated attackers to forge API Gateway proxy events, leading to a complete authenticat...

2026-08-04