23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 51-100 of 23391 CVEs Page 2 of 468
CVE-2026-9843
Analyzed
8.1
WordPress Database for Contact Form 7, WPforms, Elementor forms plugin

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path...

2026-06-21
CVE-2026-9833
Analyzed
7.1
WordPress Tag Groups is the Advanced Way to Display Your Taxonomy Terms

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters be...

2026-07-23
CVE-2026-9830
Analyzed
8.2
WordPress BookingPress Appointment Booking Pro

The bookingpress-appointment-booking-pro WordPress plugin before 5

2026-07-28
CVE-2026-9816
Analyzed
8.3
Mattermost Mattermost

Mattermost versions 11

2026-08-18
CVE-2026-9810
Analyzed
9.8
WordPress AI Copilot (WordPress Plugin)

The AI Copilot WordPress plugin fails to bind OAuth tokens to specific users, allowing unauthenticated attackers to impersonate administrators and exe...

2026-07-18
CVE-2026-9800
Analyzed
8.1
Red Hat Keycloak

A flaw was found in Keycloak Policy Enforcer

2026-06-27
CVE-2026-9787
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9786
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9785
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9784
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9783
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9782
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9781
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9780
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability

2026-06-25
CVE-2026-9773
Analyzed
8.8
Unraid Unraid Web Server

Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9772
Analyzed
8.8
Unraid Unraid Web Server

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9771
Analyzed
8.8
Unknown zephyr

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util

2026-08-18
CVE-2026-9770
Analyzed
8.6
TP-Link Kasa EC71 v4 and EC70 v4

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices

2026-07-15
CVE-2026-9769
Analyzed
7.5
EmilStenstrom justhtml

justhtml through 1

2026-08-24
CVE-2026-9765
Analyzed
7.1
Grafana Grafana IRM

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue

2026-07-26
CVE-2026-9762
Analyzed
7.8
IBM Db2

IBM Db2 11

2026-07-18
CVE-2026-9733
Analyzed
9.1
HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2

The HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2 Perl module uses a predictable state parameter, enabling CSRF-based session hijacking.

2026-06-24
CVE-2026-9726
Analyzed
9.8
Drupal Drupal AlternativeCommerce (Basket)

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Obje...

2026-07-16
CVE-2026-9725
Analyzed
9.1
WordPress Printcart Web to Print Product Designer for WooCommerce

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion via improper...

2026-07-03
CVE-2026-9717
Analyzed
8.6
Schneider Electric PowerLogic P7

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution...

2026-06-26
CVE-2026-9716
Analyzed
8.7
Schneider Electric PowerLogic™ P7

CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration fun...

2026-06-26
CVE-2026-9711
Analyzed
9.8
WordPress EventON (Pro) - WordPress Virtual Event Calendar Plugin

The EventON WordPress plugin is vulnerable to unauthenticated SQL injection via the search parameter due to insufficient input escaping and lack of pa...

2026-07-01
CVE-2026-9701
Analyzed
9.8
WordPress Eventer

The Eventer WordPress plugin stores password reset keys in plaintext, allowing unauthenticated attackers to hijack user accounts.

2026-07-08
CVE-2026-9698
Analyzed
9.8
DBI (Perl) DBI

A buffer overflow vulnerability in the Perl DBI module occurs when error messages are written to a fixed-size 200-byte buffer without length validatio...

2026-06-10
CVE-2026-9695
Analyzed
9.8
Dassault Systèmes DELMIA Apriso

An improper authentication vulnerability in Dassault Systèmes DELMIA Apriso (2020-2026) allows remote, unauthenticated attackers to gain privileged ac...

2026-07-08
CVE-2026-9691
Analyzed
9.8
HP Contact Form 7, WPForms, Elementor, Ninja Forms Integration

An unauthenticated PHP Object Injection vulnerability (CWE-502) affects the Integration for ActiveCampaign and various form plugins, potentially allow...

2026-06-16
CVE-2026-9662
Analyzed
8.1
WordPress Recover Exit For WooCommerce Plugin

The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1

2026-06-09
CVE-2026-9653
Analyzed
8.7
Rockwell Automation 1756-EN2, 1756-EN3, 1756-ENBT

A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Conne...

2026-07-15
CVE-2026-9650
Analyzed
8.7
Schneider Electric EasyLogic T150

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthentic...

2026-06-26
CVE-2026-9645
Analyzed
9.9
Exposed Multiple Products

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enablin...

2026-05-29
CVE-2026-9642
Analyzed
9.8
Delta Electronics DIAView

A mitigation bypass vulnerability in Delta Electronics DIAView V4.4 allows unauthenticated remote attackers to access configured databases.

2026-05-27
CVE-2026-9637
Analyzed
8.7
Rockwell Automation CompactLogix 5380 / ControlLogix 5580

A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation...

2026-09-02
CVE-2026-9632
Analyzed
8.8
UTT HiPER 1250GW

A flaw has been found in UTT HiPER 1250GW up to 3

2026-05-27
CVE-2026-9631
Analyzed
8.8
UTT HiPER 1250GW

A vulnerability was detected in UTT HiPER 1250GW up to 3

2026-05-27
CVE-2026-9628
Analyzed
8.8
UTT HiPER 1200GW

A weakness has been identified in UTT HiPER 1200GW up to 2

2026-05-27
CVE-2026-9627
Analyzed
8.8
UTT HiPER 1200GW

A security flaw has been discovered in UTT HiPER 1200GW up to 2

2026-05-27
CVE-2026-9625
Analyzed
8.7
Rockwell Automation RSLinx Classic

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx...

2026-09-02
CVE-2026-9624
Analyzed
8.7
Rockwell Automation RSLinx Classic

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insuffici...

2026-09-02
CVE-2026-9622
Analyzed
8.7
Rockwell RSLinx Classic

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Class...

2026-09-02
CVE-2026-9621
Analyzed
9.2
Rockwell Automation RSLinx Classic

A denial of service vulnerability in Rockwell Automation RSLinx Classic allows unauthenticated attackers to crash the service via a malformed CIP pack...

2026-09-02
CVE-2026-9614
Analyzed
8.8
Ivanti Neurons for ITSM

An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrat...

2026-06-02
CVE-2026-9592
Analyzed
7.5
SEPPmail SEPPmail Secure Email Gateway & SEPPmail Cloud

SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15

2026-07-19
CVE-2026-9588
Analyzed
7
Sangoma Switchvox SMB Edition

A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8

2026-07-19
CVE-2026-9587
Analyzed
7.1
Sangoma Switchvox SMB Edition

An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8

2026-07-19
CVE-2026-9586
KEV Analyzed
9.3
Sangoma Switchvox SMB Edition

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database comm...

2026-07-18