20685 Total CVEs
11938 AI Analyzed
298 CISA KEV
4466 Critical
All Vendors
Showing 10301-10350 of 20685 CVEs Page 207 of 414
CVE-2026-14389
Analyzed
8.3
Google Chrome

Integer overflow in Skia in Google Chrome prior to 150

2026-07-03
CVE-2026-14385
Analyzed
8.8
Google Chrome

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150

2026-07-03
CVE-2026-14383
Analyzed
8.8
Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150

2026-07-02
CVE-2026-14371
Analyzed
8.8
Microsoft XClarity Integrator for Microsoft Windows Admin Center

The Lenovo XClarity Integrator for Windows Admin Center plugin version 5

2026-07-17
CVE-2026-14365
Analyzed
9.8
WordPress TrueBooker – Appointment Booking and Scheduler System

The TrueBooker WordPress plugin is vulnerable to authorization bypass, allowing unauthenticated attackers to perform unauthorized actions such as chan...

2026-08-07
CVE-2026-14364
Analyzed
9.8
WordPress TrueBooker – Appointment Booking and Scheduler System

The TrueBooker WordPress plugin is vulnerable to account takeover due to improper password reset validation, allowing unauthenticated attackers to res...

2026-08-07
CVE-2026-14356
Analyzed
8.8
WordPress FleekDash V2

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2

2026-07-30
CVE-2026-14354
Analyzed
8.7
Schneider Electric EcoStruxure Cybersecurity Admin Expert

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, pot...

2026-07-30
CVE-2026-1435
Analyzed
9.8
Graylog Web Graylog Web Interface

Graylog Web Interface 2.2.3 fails to invalidate old session identifiers upon new logins, allowing attackers with a leaked sessionId to maintain unauth...

2026-02-19
CVE-2026-14345
Analyzed
9.8
WordPress WPFunnels – Funnel Builder for WooCommerce

The WPFunnels WordPress plugin is vulnerable to unauthenticated remote code execution due to improper sanitization of log data combined with unsafe fi...

2026-07-07
CVE-2026-14336
Analyzed
8.2
Jenkins PIA (OIDC issuer allowlist)

PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer

2026-07-03
CVE-2026-14333
Analyzed
7.5
WordPress Demi

The Demi WordPress plugin before 0

2026-08-01
CVE-2026-14328
Analyzed
8.8
WordPress Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions...

2026-07-29
CVE-2026-14319
Analyzed
7.5
WordPress GiveWP

The GiveWP WordPress plugin before 4

2026-08-01
CVE-2026-14291
7.5
WordPress security-ninja-premium

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code...

2026-08-12
CVE-2026-14289
Analyzed
9
FacturaONE FacturaONE para WooCommerce con VeriFactu

A code injection vulnerability in FacturaONE para WooCommerce con VeriFactu allows unauthenticated attackers to write arbitrary files to the server vi...

2026-07-28
CVE-2026-14282
Analyzed
9.8
WordPress GoDAM – Organize WordPress Media Library & File Manager

The GoDAM WordPress plugin suffers from an unrestricted arbitrary file upload vulnerability allowing unauthenticated remote code execution via insuffi...

2026-07-24
CVE-2026-1428
Analyzed
8.8
Unknown Multiple Products

Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbit...

2026-01-26
CVE-2026-14270
Analyzed
8.8
WordPress Extra Checkout Options - addon for Extra Product Options plugin

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in...

2026-07-30
CVE-2026-1427
Analyzed
8.8
Unknown Multiple Products

Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbit...

2026-01-26
CVE-2026-14262
Analyzed
8.8
WordPress Simple JWT Login

The Simple JWT Login – Allows you to use JWT on REST endpoints

2026-07-11
CVE-2026-14261
Analyzed
9.1
Intel Xerte Online Tools

Xerte Online Tools is vulnerable to an authentication bypass and remote code execution flaw via the /setup/ folder, allowing attackers to force a serv...

2026-07-10
CVE-2026-1426
8.8
HP is vulnerable

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3

2026-02-19
CVE-2026-14254
Analyzed
8.3
Perforce Delphix Continuous Data

A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentica...

2026-07-17
CVE-2026-14245
Analyzed
9.8
WordPress miniOrange OTP Login, Verification and SMS Notifications

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to an authentication bypass that allows unauthenticate...

2026-07-09
CVE-2026-14235
Analyzed
7.5
WordPress Download Manager

The Download Manager WordPress plugin before 3

2026-07-28
CVE-2026-1422
Analyzed
7.3
Examination Multiple Products

A vulnerability was found in code-projects Online Examination System 1

2026-01-26
CVE-2026-14206
Analyzed
7.5
WordPress HT Contact Form

The HT Contact Form WordPress plugin before 2

2026-08-11
CVE-2026-14205
Analyzed
9.8
WordPress WP Events Manager

The WP Events Manager WordPress plugin contains a vulnerability that allows authenticated users to bypass payment requirements when registering for pa...

2026-08-08
CVE-2026-1420
Analyzed
8.8
Tenda Multiple Products

A flaw has been found in Tenda AC23 16

2026-01-26
CVE-2026-14193
Analyzed
7.5
Delta Electronics DVP80ES300T

DVP80ES300T with Improper Validation of Array Index Vulnerability

2026-07-01
CVE-2026-14191
Analyzed
7.8
RARLAB WinRAR

An out-of-bounds heap write exists in the RAR5 recovery-volume (

2026-07-01
CVE-2026-14175
Analyzed
9.8
Unknown HUMANIST Digital Human Resources

An unrestricted file upload vulnerability in HUMANIST Digital Human Resources allows remote, unauthenticated attackers to upload and execute malicious...

2026-08-04
CVE-2026-14172
Analyzed
7.8
Rapid7 InsightVM, Nexpose, and Insight Agent

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, all...

2026-07-24
CVE-2026-14169
Analyzed
8.1
Unknown DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing us...

2026-07-30
CVE-2026-14168
Analyzed
8.8
Unknown Industrial IT DVG-IRF series

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resultin...

2026-07-29
CVE-2026-14167
Analyzed
8.8
Unknown DVG-IRF1401

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due...

2026-07-29
CVE-2026-14165
Analyzed
7.5
Dassault Systèmes Tuleap Enterprise Edition

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17

2026-07-13
CVE-2026-14164
Analyzed
7.5
Red Hat Red Hat Enterprise Linux 10

A double free issue has been identified in libarchive's RAR5 reader

2026-06-30
CVE-2026-14162
Analyzed
9.8
Advantech Hospital Queuing Management

Advantech Hospital Queuing Management contains a sensitive data exposure vulnerability that allows unauthenticated remote attackers to access API docu...

2026-07-01
CVE-2026-14158
Analyzed
8.8
WordPress Widget Logic Visual

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1

2026-07-08
CVE-2026-14149
Analyzed
8.8
Google Chrome

Use after free in Audio in Google Chrome on Linux prior to 150

2026-07-02
CVE-2026-1412
Analyzed
7.3
Unknown Multiple Products

A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3

2026-01-26
CVE-2026-14108
Analyzed
8.8
Google Chrome

Use after free in PDFium in Google Chrome prior to 150

2026-07-02
CVE-2026-14107
Analyzed
8.8
Google Chrome

Use after free in Scheduling in Google Chrome prior to 150

2026-07-02
CVE-2026-14104
Analyzed
8.8
Google Chrome

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150

2026-07-02
CVE-2026-14102
Analyzed
8.8
Google Chrome

Use after free in Passwords in Google Chrome prior to 150

2026-07-02
CVE-2026-14099
Analyzed
8.8
Apple Chrome for iOS

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150

2026-07-02
CVE-2026-14091
Analyzed
8.8
Google Chrome

Use after free in DevTools in Google Chrome prior to 150

2026-07-02
CVE-2026-14087
Analyzed
8.8
Microsoft Chrome for Windows

Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150

2026-07-02