21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10201-10250 of 21553 CVEs Page 205 of 432
CVE-2026-19811
Analyzed
8.8
TOTOLINK A800R

A security flaw has been discovered in TOTOLINK A800R 4

2026-08-14
CVE-2026-19792
Analyzed
8.8
Tenda G0

A security flaw has been discovered in Tenda G0 up to 20260625

2026-08-14
CVE-2026-19791
Analyzed
8.8
Tenda G0

A weakness has been identified in Tenda G0 up to 20260625

2026-08-14
CVE-2026-19790
Analyzed
8.8
Tenda G0

A vulnerability was identified in Tenda G0 up to 20260625

2026-08-14
CVE-2026-19789
Analyzed
8.8
Tenda AC1206

A vulnerability was determined in Tenda AC1206 15

2026-08-14
CVE-2026-19788
Analyzed
8.8
Tenda AC1206

A vulnerability was found in Tenda AC1206 15

2026-08-14
CVE-2026-19768
Analyzed
8.1
Devolutions PowerShell Universal

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026

2026-08-16
CVE-2026-19747
Analyzed
9.8
Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7

A command injection vulnerability in the ATE Module of various Tenda devices allows unauthenticated remote attackers to execute arbitrary system comma...

2026-08-14
CVE-2026-19734
Analyzed
8.6
Intel Prospero Flow CRM

Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5

2026-08-15
CVE-2026-19693
Analyzed
8.1
Unknown extract-zip

extract-zip through 2

2026-08-18
CVE-2026-19682
Analyzed
9.9
Tenable Security Center

A command injection vulnerability exists in Tenable Security Center, allowing remote authenticated attackers to execute arbitrary system commands via...

2026-08-15
CVE-2026-19681
Analyzed
9.9
Tenable Security Center

An authenticated command injection vulnerability exists in Tenable Security Center during file upload processing, allowing arbitrary command execution...

2026-08-15
CVE-2026-19680
Analyzed
7.1
Tenable Security Center

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database

2026-08-16
CVE-2026-19679
Analyzed
8.8
Tenable Security Center

An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contri...

2026-08-15
CVE-2026-19656
Analyzed
9.9
SCADA-LTS ScadaLTS

ScadaLTS 2.7.8.1 contains an authorization bypass vulnerability that allows authenticated users with low privileges to execute arbitrary operating sys...

2026-08-13
CVE-2026-19635
Analyzed
8.8
Tenable Security Center

A local privilege escalation vulnerability exists in Security Center

2026-08-15
CVE-2026-19629
Analyzed
8.1
Tenable Security Center

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on...

2026-08-16
CVE-2026-19628
Analyzed
7.2
Tenable Security Center

A command injection vulnerability exists in Tenable Security Center

2026-08-16
CVE-2026-19626
Analyzed
9.9
Tenable Security Center

Tenable Security Center is vulnerable to remote code execution during report generation, allowing an authenticated, non-administrative user to execute...

2026-08-15
CVE-2026-1961
8
Foreman Multiple Products

A flaw was found in Foreman

2026-03-28
CVE-2026-19598
Analyzed
9.8
WordPress Pods – Custom Content Types and Fields

The Pods WordPress plugin is vulnerable to unauthenticated privilege escalation due to an authorization bypass in the AJAX router.

2026-08-16
CVE-2026-19560
Analyzed
8.8
Google Chrome

Use after free in Blink in Google Chrome prior to 151

2026-08-13
CVE-2026-19559
Analyzed
8.8
Google Chrome

Use after free in HTML in Google Chrome prior to 151

2026-08-13
CVE-2026-19556
Analyzed
8.8
Google Chrome

Use after free in V8 in Google Chrome prior to 151

2026-08-13
CVE-2026-19546
Analyzed
8.8
Red Hat Red Hat Enterprise Linux

A flaw was found in DBI

2026-08-12
CVE-2026-1952
Analyzed
9.8
Delta Electronics AS320T

Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

2026-04-24
CVE-2026-1951
Analyzed
9.8
Delta Electronics AS320T

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

2026-04-24
CVE-2026-1950
Analyzed
9.8
Delta Electronics AS320T

Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.

2026-04-24
CVE-2026-1949
Analyzed
9.8
Delta Electronics AS320T

Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.

2026-04-24
CVE-2026-19489
Analyzed
8.8
NetScaler ADC and Gateway

Vulnerability in NetScaler ADC and NetScaler Gateway

2026-08-20
CVE-2026-19478
Analyzed
9.4
GitLab GitLab

A code injection vulnerability in GitLab allows unauthenticated remote attackers to modify or delete public projects and user data via a malicious Gra...

2026-08-18
CVE-2026-19474
Analyzed
7.5
Fastify @fastify/multipart

@fastify/multipart is a multipart form-data parser for Fastify

2026-08-16
CVE-2026-1947
7.5
WordPress plugin for

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and...

2026-03-17
CVE-2026-1945
7.2
WordPress is vulnerable

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions...

2026-03-04
CVE-2026-19433
Analyzed
8.6
Roskus Prospero Flow CRM

Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5

2026-08-11
CVE-2026-19429
Analyzed
8.8
Jenkins Jenkins

Jenkins FilePath

2026-08-11
CVE-2026-19425
Analyzed
9.8
Win Men Intermational Travel Agency Management System

The Win Men Intermational Travel Agency Management System is vulnerable to SQL injection, allowing unauthenticated remote attackers to manipulate data...

2026-08-11
CVE-2026-19424
Analyzed
7.5
Inventec Chiline Cloud

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability

2026-08-11
CVE-2026-19418
Analyzed
7.3
TYPO3 TYPO3 CMS

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13

2026-08-11
CVE-2026-19389
Analyzed
7.1
Red Hat Red Hat Enterprise Linux

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header object...

2026-08-10
CVE-2026-19387
Analyzed
7.6
Red Hat Red Hat Enterprise Linux

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio

2026-08-10
CVE-2026-19385
Analyzed
8.8
PostgreSQL PostgreSQL

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system...

2026-08-14
CVE-2026-19384
Analyzed
7.3
SourceCodester Simple Doctors Appointment System

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1

2026-08-10
CVE-2026-19381
Analyzed
7.8
Kingston FURY CTRL RGB Control Software

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2

2026-08-10
CVE-2026-19379
Analyzed
7.3
EFM ipTIME AX8004M

A vulnerability was determined in EFM ipTIME AX8004M 15

2026-08-10
CVE-2026-19376
Analyzed
7.3
Uasoft Badaso

A vulnerability has been found in Uasoft Badaso 3

2026-08-10
CVE-2026-19374
Analyzed
7.3
GitHub api-mcp

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06

2026-08-10
CVE-2026-1937
Analyzed
9.8
WordPress is vulnerable

The YayMail plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on an AJAX action, allowing authenticated att...

2026-02-18
CVE-2026-19355
Analyzed
7.3
MingSoft MCMS

A vulnerability was determined in MingSoft MCMS up to 3

2026-08-10
CVE-2026-19351
Analyzed
7.3
Unknown node-sql-query

A vulnerability was found in dresende node-sql-query 0

2026-08-10