21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 951-1000 of 21637 CVEs Page 20 of 433
CVE-2026-7288
8.8
D-Link DIR

A vulnerability has been found in D-Link DIR-825M 1

2026-04-29
CVE-2026-72879
Analyzed
9.4
Dokploy dokploy

Dokploy versions prior to 0.29.8 are vulnerable to OS command injection via the getRegistryCommands function, allowing authenticated users to execute...

2026-08-11
CVE-2026-72878
Analyzed
9.6
Dokploy dokploy

Dokploy prior to 0.29.13 is vulnerable to OS command injection via the backup and restore pipeline, allowing authenticated admins to execute arbitrary...

2026-08-11
CVE-2026-72877
Analyzed
9.6
Docker dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection via the dockerImage field, allowing authenticated users to execute arbitrary co...

2026-08-11
CVE-2026-72876
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 contain an authorization bypass and OS command injection flaw, allowing authenticated users to manipulate server IDs a...

2026-08-11
CVE-2026-72875
Analyzed
8.8
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72874
Analyzed
8.7
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72872
Analyzed
9.9
Dokploy dokploy

Dokploy improperly validates Bitbucket repository fields, allowing authenticated users to inject arbitrary OS commands into git clone operations.

2026-08-11
CVE-2026-72871
Analyzed
7.5
Dokploy Dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72870
Analyzed
8.7
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-7287
Analyzed
7.5
Zyxel NWA1100

** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert(...

2026-05-12
CVE-2026-72869
Analyzed
9.9
Docker dokploy

An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with backup permissions to execute arbitrary commands in...

2026-08-11
CVE-2026-72868
Analyzed
9.9
Docker dokploy

Dokploy allows a low-privileged member to execute arbitrary OS commands as root by injecting malicious input into the rclone configuration fields duri...

2026-08-11
CVE-2026-72867
Analyzed
9.9
Dokploy dokploy

Dokploy versions 0.29.3 through 0.29.12 are susceptible to OS command injection due to insufficient server-side validation of git branch fields during...

2026-08-11
CVE-2026-72866
Analyzed
8.8
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72865
Analyzed
9.9
Dokploy dokploy

Dokploy versions prior to 0.29.13 contain an OS command injection vulnerability in the compose update process, allowing authenticated users to execute...

2026-08-11
CVE-2026-72864
Analyzed
9.9
Docker dokploy

Dokploy versions before 0.29.13 are vulnerable to a missing authorization flaw in the docker-container-terminal component, allowing authenticated user...

2026-08-11
CVE-2026-72863
Analyzed
9.9
Docker dokploy

Dokploy versions prior to 0.29.13 fail to enforce authorization checks on WebSocket handlers, allowing authenticated users to access interactive shell...

2026-08-11
CVE-2026-72862
Analyzed
9.9
Docker dokploy

Dokploy contains an OS command injection vulnerability in its database service deployment functions, allowing authenticated users to execute arbitrary...

2026-08-11
CVE-2026-72859
Analyzed
7.7
Budibase server

Budibase versions 3

2026-08-16
CVE-2026-72851
Analyzed
10
Budibase Server

Budibase server versions before 3.40.0 contain an unauthenticated SQL injection vulnerability in webhook-triggered automations, allowing remote attack...

2026-08-14
CVE-2026-72848
Analyzed
8.6
Unknown langchain-community

SitemapLoader

2026-08-21
CVE-2026-72842
Analyzed
9.9
Unknown luci

An ACL inconsistency in the OpenWrt LuCI LXC application allows authenticated users with low privileges to bypass authorization and execute arbitrary...

2026-08-14
CVE-2026-72841
Analyzed
9.9
Unknown luci

The luci-app-openvpn package for OpenWrt is vulnerable to path traversal during file uploads, enabling authenticated users to write arbitrary files an...

2026-08-14
CVE-2026-72840
Analyzed
8.8
OpenWrt LuCI

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended o...

2026-08-15
CVE-2026-7284
Analyzed
9.8
WordPress is vulnerable

The Easy Elements for Elementor plugin is vulnerable to privilege escalation, allowing unauthenticated users to register as administrators.

2026-05-20
CVE-2026-72839
Analyzed
9.8
Unknown filebrowser

Filebrowser through 2.63.16 contains an incorrect privilege assignment vulnerability that allows unauthenticated attackers to register accounts with f...

2026-08-14
CVE-2026-72837
Analyzed
8.8
Unknown filebrowser

File Browser versions before 2

2026-08-15
CVE-2026-72836
Analyzed
8.1
FileBrowser filebrowser

FileBrowser before 2

2026-08-16
CVE-2026-72833
Analyzed
8.8
Unknown Grav

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1

2026-08-15
CVE-2026-72831
Analyzed
8.8
Unknown grav

The Flex Objects plugin (through 1

2026-08-15
CVE-2026-72830
Analyzed
9.8
Unknown grav

The Grav API plugin fails to enforce API key scopes in the ConfigController, allowing attackers to inject and execute arbitrary OS commands via the sc...

2026-08-15
CVE-2026-72829
Analyzed
9.8
Unknown grav

The Grav API plugin contains a flaw in UsersController that allows attackers to bypass scope caps and promote accounts to super-user status.

2026-08-15
CVE-2026-72828
Analyzed
7.2
Unknown grav

Grav Plugin API (getgrav/grav-plugin-api) before 1

2026-08-16
CVE-2026-72827
Analyzed
8.8
Grav Grav CMS

Grav CMS before 2

2026-08-15
CVE-2026-72826
Analyzed
9.8
Unknown grav

The getgrav grav-plugin-api fails to validate API key scopes during creation, allowing attackers to mint unauthorized, full-access super keys.

2026-08-15
CVE-2026-72825
Analyzed
7.6
Unknown grav

The getgrav/grav-plugin-api plugin before 1

2026-08-16
CVE-2026-72824
Analyzed
9.8
Unknown grav

The Grav API plugin contains an authorization bypass in PagesController that allows unauthenticated attackers to achieve server-side template injectio...

2026-08-15
CVE-2026-72822
Analyzed
9.8
Unknown grav

A critical authentication bypass vulnerability in the getgrav/grav-plugin-api package allows unauthorized users to disable two-factor authentication o...

2026-08-15
CVE-2026-72819
Analyzed
8.8
Grav Grav CMS

Grav CMS before 2

2026-08-15
CVE-2026-72811
Analyzed
10
Unknown siyuan

SiYuan versions up to v3.7.2 are vulnerable to SQL injection via the backlink/mention search query due to improper sanitization of single quotes in cl...

2026-08-15
CVE-2026-72810
Analyzed
8.6
Unknown siyuan

SiYuan versions before v3

2026-08-15
CVE-2026-7279
7.8
Unknown Multiple Products

AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specifi...

2026-04-29
CVE-2026-72781
Analyzed
8.8
Craft CMS CMS

Craft CMS versions >= 5

2026-08-12
CVE-2026-72778
Analyzed
8.8
Craft CMS CMS

Craft CMS versions from 4

2026-08-12
CVE-2026-72777
Analyzed
8.6
DayuanJiang next-ai-draw-io

Next AI Draw

2026-08-15
CVE-2026-72776
Analyzed
9.8
Fosowl AgenticSeek

Fosowl AgenticSeek suffers from an unauthenticated remote code execution vulnerability in its query API, allowing attackers to execute arbitrary comma...

2026-08-14
CVE-2026-72772
Analyzed
8.9
Unknown n8n

n8n before 2

2026-08-12
CVE-2026-72767
Analyzed
8.7
Unknown n8n

n8n before 1

2026-08-12
CVE-2026-72765
Analyzed
8.7
Unknown n8n

n8n before 2

2026-08-12