20419 Total CVEs
11692 AI Analyzed
295 CISA KEV
4388 Critical
All Vendors
Showing 10001-10050 of 20419 CVEs Page 201 of 409
CVE-2026-1459
7.2
Zyxel VMG3625

A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions throu...

2026-02-24
CVE-2026-14570
Analyzed
7.5
TIMLEGGE Crypt::DSA

Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery....

2026-07-10
CVE-2026-14553
Analyzed
8.1
HP zportals

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the ori...

2026-08-09
CVE-2026-14551
Analyzed
8.8
Unknown servereye Windows Agent (Sensorhub)

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20

2026-07-23
CVE-2026-14545
Analyzed
9.8
WordPress TrueBooker WordPress Plugin

The TrueBooker WordPress plugin fails to validate account ownership during password resets, allowing unauthenticated attackers to hijack any user acco...

2026-07-29
CVE-2026-14544
Analyzed
9.8
HP Red Hat Enterprise Linux 10

An integer overflow in the HPLIP hpcups processing path allows a remote attacker to escalate privileges or execute arbitrary code via specially crafte...

2026-07-03
CVE-2026-14541
Analyzed
8
Google mcp-toolbox

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1

2026-08-01
CVE-2026-14540
Analyzed
8
Google mcp-toolbox

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0

2026-08-01
CVE-2026-14537
Analyzed
8.1
Google mcp-toolbox

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1

2026-08-01
CVE-2026-14536
Analyzed
9.8
Devolutions Server

Devolutions Server 2026.2.4.0 through 2026.2.9.0 fails to enforce mandatory multi-factor authentication (MFA) policies when encountering invalid defau...

2026-07-11
CVE-2026-14535
Analyzed
8.8
Unknown fickling

In Trail of Bits fickling versions up to and including 0

2026-07-05
CVE-2026-14534
Analyzed
8.8
Unknown fickling

Trail of Bits fickling versions up to and including 0

2026-07-05
CVE-2026-1453
Analyzed
9.8
Unknown Multiple Products

A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete ad...

2026-01-30
CVE-2026-14529
Analyzed
9.4
IBM WebSphere Application Server

IBM WebSphere Application Server is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled, poten...

2026-07-30
CVE-2026-14526
Analyzed
9.8
WordPress AI Copilot – Content Generator

An authorization bypass in the AI Copilot WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site tak...

2026-08-08
CVE-2026-14522
Analyzed
8.8
IBM App Connect Enterprise

IBM App Connect Enterprise 13

2026-07-31
CVE-2026-14512
Analyzed
9.8
IBM WebSphere Application Server

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to pre-authentication unsafe deserialization, enabling remote attackers to bypas...

2026-07-29
CVE-2026-14499
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-07-18
CVE-2026-14495
Analyzed
8.8
WordPress DoLogin Security

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4

2026-07-08
CVE-2026-14490
Analyzed
7.5
WordPress Demi – One Click Demo Import, Backup & Site Migration

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to,...

2026-07-28
CVE-2026-1449
7.3
Unknown Multiple Products

A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113

2026-01-27
CVE-2026-14489
Analyzed
8.8
WordPress WHMCS Bridge

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ver...

2026-07-08
CVE-2026-14487
Analyzed
9.1
WordPress Simple Coherent Form

The Simple Coherent Form WordPress plugin contains a path traversal vulnerability allowing unauthenticated remote file deletion and potential code exe...

2026-07-08
CVE-2026-14483
Analyzed
9.8
WordPress Realtyna Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin + WPL Real Estate for WordPress is vulnerable to unauthenticated arbitrary file uploads due to missing validation and...

2026-07-31
CVE-2026-14482
Analyzed
8.8
WordPress 多说社会化评论框 (Duoshuo Social Comment Box)

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-07-08
CVE-2026-14480
Analyzed
9.9
OpenPLC OpenPLC

An authenticated arbitrary file write vulnerability in the OpenPLC Runtime v3 web UI allows attackers to achieve native code execution by uploading ma...

2026-07-11
CVE-2026-1448
7.2
D-Link Multiple Products

A vulnerability was detected in D-Link DIR-615 up to 4

2026-01-27
CVE-2026-14476
Analyzed
8
Red Hat Red Hat Enterprise Linux (SSSD)

A path traversal flaw was found in SSSD's AD GPO provider

2026-07-08
CVE-2026-14474
Analyzed
8.8
Red Hat Red Hat Enterprise Linux (RHEL) / OpenShift

A flaw was found in SSSD's LDAP sudo provider

2026-07-08
CVE-2026-14471
Analyzed
8.1
Amazon MCP Gateway & Registry

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1

2026-07-07
CVE-2026-14468
Analyzed
7.7
HashiCorp Terraform Enterprise

HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the...

2026-07-07
CVE-2026-14460
Analyzed
8.8
TUBITAK BILGEM pardus-software

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection

2026-07-03
CVE-2026-14459
Analyzed
8.8
TUBITAK BILGEM pardus-software

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Inst...

2026-07-03
CVE-2026-14454
Analyzed
9.8
TONYC Imager

Imager for Perl mishandles large EXIF IFD entry counts, leading to excessive memory allocation attempts and process termination.

2026-07-12
CVE-2026-14453
Analyzed
9.6
Centreon Infra Monitoring

Centreon Infra Monitoring is vulnerable to Server-Side Template Injection (SSTI) in the open-tickets module, allowing authenticated users to execute a...

2026-07-13
CVE-2026-14446
Analyzed
9.8
IBM WebSphere Application Server

IBM WebSphere Application Server versions 9.0 and 8.5 contain a broken access control vulnerability in the administrative console that allows for priv...

2026-07-29
CVE-2026-14432
Analyzed
8.8
Google Chrome

Use after free in V8 in Google Chrome prior to 150

2026-07-02
CVE-2026-14431
Analyzed
8.8
Google Chrome

Type Confusion in V8 in Google Chrome prior to 150

2026-07-02
CVE-2026-14430
Analyzed
8.8
Google Chrome

Integer overflow in V8 in Google Chrome prior to 150

2026-07-02
CVE-2026-1443
7.3
Unknown Multiple Products

A flaw has been found in code-projects Online Music Site 1

2026-01-27
CVE-2026-14429
Analyzed
8.3
Google Chrome

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150

2026-07-03
CVE-2026-14428
Analyzed
8.3
Google Chrome for Android

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150

2026-07-03
CVE-2026-14427
Analyzed
8.3
Google Chrome

Heap buffer overflow in Skia in Google Chrome prior to 150

2026-07-03
CVE-2026-14422
Analyzed
8.8
Google Chrome

Out of bounds read and write in Tint in Google Chrome prior to 150

2026-07-03
CVE-2026-1442
7.8
LG Multiple Products

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying atte...

2026-02-27
CVE-2026-14415
Analyzed
8.8
Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150

2026-07-03
CVE-2026-14413
Analyzed
8.3
Google Chrome

Uninitialized Use in ANGLE in Google Chrome prior to 150

2026-07-03
CVE-2026-14412
Analyzed
8.3
Google Chrome

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150

2026-07-03
CVE-2026-14407
Analyzed
8.8
Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150

2026-07-02
CVE-2026-14403
Analyzed
8.8
Google Chrome

Use after free in V8 in Google Chrome prior to 150

2026-07-02