21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 51-100 of 21637 CVEs Page 2 of 433
CVE-2026-9830
Analyzed
8.2
WordPress BookingPress Appointment Booking Pro

The bookingpress-appointment-booking-pro WordPress plugin before 5

2026-07-28
CVE-2026-9816
Analyzed
8.3
Mattermost Mattermost

Mattermost versions 11

2026-08-18
CVE-2026-9810
Analyzed
9.8
WordPress AI Copilot (WordPress Plugin)

The AI Copilot WordPress plugin fails to bind OAuth tokens to specific users, allowing unauthenticated attackers to impersonate administrators and exe...

2026-07-18
CVE-2026-9800
Analyzed
8.1
Red Hat Keycloak

A flaw was found in Keycloak Policy Enforcer

2026-06-27
CVE-2026-9787
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9786
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9785
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9784
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9783
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9782
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9781
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9780
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability

2026-06-25
CVE-2026-9773
Analyzed
8.8
Unraid Unraid Web Server

Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9772
Analyzed
8.8
Unraid Unraid Web Server

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-9771
Analyzed
8.8
Unknown zephyr

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util

2026-08-18
CVE-2026-9770
Analyzed
8.6
TP-Link Kasa EC71 v4 and EC70 v4

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices

2026-07-15
CVE-2026-9765
Analyzed
7.1
Grafana Grafana IRM

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue

2026-07-26
CVE-2026-9762
Analyzed
7.8
IBM Db2

IBM Db2 11

2026-07-18
CVE-2026-9733
Analyzed
9.1
HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2

The HAYAJO Mojolicious::Plugin::Web::Auth::OAuth2 Perl module uses a predictable state parameter, enabling CSRF-based session hijacking.

2026-06-24
CVE-2026-9726
9.8
Drupal Drupal AlternativeCommerce (Basket)

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Obje...

2026-07-16
CVE-2026-9725
Analyzed
9.1
WordPress Printcart Web to Print Product Designer for WooCommerce

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion via improper...

2026-07-03
CVE-2026-9717
Analyzed
8.6
Schneider Electric PowerLogic P7

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution...

2026-06-26
CVE-2026-9716
Analyzed
8.7
Schneider Electric PowerLogicâ„¢ P7

CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration fun...

2026-06-26
CVE-2026-9711
Analyzed
9.8
WordPress EventON (Pro) - WordPress Virtual Event Calendar Plugin

The EventON WordPress plugin is vulnerable to unauthenticated SQL injection via the search parameter due to insufficient input escaping and lack of pa...

2026-07-01
CVE-2026-9701
Analyzed
9.8
WordPress Eventer

The Eventer WordPress plugin stores password reset keys in plaintext, allowing unauthenticated attackers to hijack user accounts.

2026-07-08
CVE-2026-9698
Analyzed
9.8
DBI (Perl) DBI

A buffer overflow vulnerability in the Perl DBI module occurs when error messages are written to a fixed-size 200-byte buffer without length validatio...

2026-06-10
CVE-2026-9695
Analyzed
9.8
Dassault Systèmes DELMIA Apriso

An improper authentication vulnerability in Dassault Systèmes DELMIA Apriso (2020-2026) allows remote, unauthenticated attackers to gain privileged ac...

2026-07-08
CVE-2026-9691
Analyzed
9.8
HP Contact Form 7, WPForms, Elementor, Ninja Forms Integration

An unauthenticated PHP Object Injection vulnerability (CWE-502) affects the Integration for ActiveCampaign and various form plugins, potentially allow...

2026-06-16
CVE-2026-9662
Analyzed
8.1
WordPress Recover Exit For WooCommerce Plugin

The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1

2026-06-09
CVE-2026-9653
Analyzed
8.7
Rockwell Automation 1756-EN2, 1756-EN3, 1756-ENBT

A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Conne...

2026-07-15
CVE-2026-9650
Analyzed
8.7
Schneider Electric EasyLogic T150

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthentic...

2026-06-26
CVE-2026-9645
Analyzed
9.9
Exposed Multiple Products

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enablin...

2026-05-29
CVE-2026-9642
Analyzed
9.8
Delta Electronics DIAView

A mitigation bypass vulnerability in Delta Electronics DIAView V4.4 allows unauthenticated remote attackers to access configured databases.

2026-05-27
CVE-2026-9632
Analyzed
8.8
UTT HiPER 1250GW

A flaw has been found in UTT HiPER 1250GW up to 3

2026-05-27
CVE-2026-9631
Analyzed
8.8
UTT HiPER 1250GW

A vulnerability was detected in UTT HiPER 1250GW up to 3

2026-05-27
CVE-2026-9628
Analyzed
8.8
UTT HiPER 1200GW

A weakness has been identified in UTT HiPER 1200GW up to 2

2026-05-27
CVE-2026-9627
Analyzed
8.8
UTT HiPER 1200GW

A security flaw has been discovered in UTT HiPER 1200GW up to 2

2026-05-27
CVE-2026-9614
Analyzed
8.8
Ivanti Neurons for ITSM

An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrat...

2026-06-02
CVE-2026-9592
Analyzed
7.5
SEPPmail SEPPmail Secure Email Gateway & SEPPmail Cloud

SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15

2026-07-19
CVE-2026-9588
Analyzed
7
Sangoma Switchvox SMB Edition

A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8

2026-07-19
CVE-2026-9587
Analyzed
7.1
Sangoma Switchvox SMB Edition

An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8

2026-07-19
CVE-2026-9586
Analyzed
9.3
Sangoma Switchvox SMB Edition

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database comm...

2026-07-18
CVE-2026-9585
Analyzed
8.6
Sangoma Switchvox SMB Edition

An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8

2026-07-18
CVE-2026-9561
Analyzed
8.8
Eclipse Foundation Eclipse Kura

Eclipse Kura versions prior to 5

2026-07-14
CVE-2026-9559
Analyzed
9.9
HP files to

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw i...

2026-05-30
CVE-2026-9558
Analyzed
9.9
Mautic Mautic

A Server-Side Template Injection (SSTI) vulnerability in the Mautic theme engine allows authenticated users with theme upload permissions to execute a...

2026-05-30
CVE-2026-9545
Analyzed
7.5
Unknown curl

A flaw in libcurl's HTTP/3 implementation allows for potential information leakage when an attacker replaces a legitimate server with an impostor duri...

2026-07-05
CVE-2026-9543
Analyzed
9.8
TOTOLINK N300RH

The Totolink N300RH web management interface contains an OS command injection vulnerability in the `setPasswordCfg` function.

2026-05-27
CVE-2026-9537
9.8
JBERGER Mojo::JWT

Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied...

2026-07-23
CVE-2026-9492
Analyzed
7.8
GIGABYTE MBStorage

The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulner...

2026-07-13