21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10351-10400 of 21553 CVEs Page 208 of 432
CVE-2026-18597
Analyzed
8.5
Foxit Foxit PDF Services API

The PDF creation feature of Foxit PDF Services API supports referencing external files

2026-08-06
CVE-2026-18589
Analyzed
9.8
GitHub WL-NU516U1

A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the...

2026-08-03
CVE-2026-18588
Analyzed
9.8
GitHub WL-NU516U1

The Wavlink WL-NU516U1 router contains a stack-based buffer overflow vulnerability in the nas.cgi file, which can be triggered by manipulating the CON...

2026-08-03
CVE-2026-18587
Analyzed
7.5
GitHub WL-NU516U1

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628

2026-08-03
CVE-2026-18577
KEV Analyzed
8.2
N-able N-central

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026

2026-08-03
CVE-2026-18574
Analyzed
9.3
Check Point Security Management Server and Multi-Domain Security Management Server

An authentication bypass vulnerability in Check Point Security Management Server allows unauthenticated remote attackers to execute arbitrary commands...

2026-08-04
CVE-2026-18568
Analyzed
7.5
TIMLEGGE XML::Sig

XML::Sig versions from 0

2026-08-04
CVE-2026-18556
KEV Analyzed
8.2
N-able N-central

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass

2026-08-02
CVE-2026-18554
Analyzed
7.5
IBM Db2 Mirror for i

IBM Db2 Mirror for i 7

2026-08-16
CVE-2026-18549
Analyzed
7.5
Fastify @fastify/multipart

@fastify/multipart is a multipart form-data parser for Fastify

2026-08-16
CVE-2026-18500
Analyzed
8.1
Fastify @fastify/jwt

@fastify/jwt is a JSON Web Token plugin for Fastify

2026-08-16
CVE-2026-18497
Analyzed
7.1
Sean Barrett (nothings) nothings stb

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. Th...

2026-08-17
CVE-2026-18481
Analyzed
7.3
AWS AWS Ops Wheel

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal sessio...

2026-08-02
CVE-2026-18473
Analyzed
9.1
WordPress WP Directory Kit

The WP Directory Kit WordPress plugin before 1.5.5 contains a SQL injection vulnerability that allows unauthenticated users to execute arbitrary datab...

2026-08-17
CVE-2026-18470
Analyzed
7.5
WordPress Login & Register Forms

The Login & Register Forms WordPress plugin before 4

2026-08-11
CVE-2026-18469
Analyzed
8.1
WordPress Login & Register Forms

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying bot...

2026-08-19
CVE-2026-18468
Analyzed
8.1
WordPress Login & Register Forms

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the par...

2026-08-16
CVE-2026-18464
Analyzed
7.5
WordPress WP MAPS PRO

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticat...

2026-08-16
CVE-2026-18452
Analyzed
10
Rich Source DMS+ (Non-Mobile)

DMS+ (Non-Mobile) contains hardcoded credentials that allow unauthenticated remote attackers to gain full administrative control over the device.

2026-07-31
CVE-2026-18446
Analyzed
7.5
Unknown fast-uri

fast-uri before 4

2026-08-01
CVE-2026-1844
Analyzed
7.2
Google is vulnerable

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page...

2026-02-14
CVE-2026-18438
Analyzed
8.8
WordPress Templately – Elementor & Gutenberg Template Library

The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code...

2026-08-16
CVE-2026-18432
Analyzed
9.8
WordPress Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress contains a privilege escalation vulnerability due to an improper authorization check, allowing u...

2026-08-16
CVE-2026-1843
Analyzed
7.2
WordPress is vulnerable

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5

2026-02-14
CVE-2026-18428
Analyzed
8.8
Apache Opensearch

A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query a...

2026-08-14
CVE-2026-18411
Analyzed
8.1
Acrisure KARR BT and DR-100

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices

2026-08-06
CVE-2026-1841
Analyzed
7.2
Google is vulnerable

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource'...

2026-02-14
CVE-2026-18408
Analyzed
8.8
PostgreSQL PostgreSQL

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time executio...

2026-08-14
CVE-2026-18394
Analyzed
7.4
AWS Strands Agents Tools

Incorrect authorization in the http_request tool in Strands Agents Tools before 0

2026-08-02
CVE-2026-18391
Analyzed
9.8
HP Subscriptions

The WooCommerce Subscriptions plugin is vulnerable to PHP Object Injection due to insecure unserialization of user input, enabling unauthenticated rem...

2026-08-13
CVE-2026-18381
Analyzed
7.6
Red Hat Cost Management Metrics Operator

A flaw was found in the koku-metrics-operator for Red Hat OpenShift

2026-08-01
CVE-2026-18378
Analyzed
7.6
Red Hat Cost Management Metrics Operator

A flaw was found in koku-metrics-operator

2026-08-01
CVE-2026-18366
Analyzed
9.8
WordPress Events Manager

The Events Manager WordPress plugin fails to properly scope capability checks, allowing unauthenticated users to perform privileged account actions if...

2026-08-13
CVE-2026-18361
Analyzed
7.6
Unknown iris-web

The IRIS web application in version 2

2026-08-01
CVE-2026-18360
Analyzed
7.6
GitHub iris-web

The IRIS web application in version 2

2026-08-01
CVE-2026-18359
Analyzed
8.5
Scripta eScriptorium

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26

2026-08-06
CVE-2026-18358
Analyzed
7.5
Red Hat gnome-remote-desktop

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux

2026-08-01
CVE-2026-18357
Analyzed
7.5
WordPress WPC Order Tip for WooCommerce

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allow...

2026-08-17
CVE-2026-18353
Analyzed
8.8
Eclipse Eclipse CSI - PIA

PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlpa...

2026-07-30
CVE-2026-18352
Analyzed
7.5
WordPress User Access Manager

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2

2026-08-02
CVE-2026-18322
Analyzed
8.8
WordPress Smart Popup by Supsystic

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-08-05
CVE-2026-18316
Analyzed
9.1
WordPress Solace Extra

The Solace Extra plugin for WordPress is vulnerable to unauthorized data modification and loss due to a missing capability check on the import_zip() f...

2026-08-16
CVE-2026-1830
Analyzed
9.8
WordPress is vulnerable

The Quick Playground plugin for WordPress contains an RCE vulnerability due to insufficient authorization on REST API endpoints, allowing unauthentica...

2026-04-09
CVE-2026-1829
Analyzed
8.8
WordPress Content Visibility for Divi Builder

The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4

2026-06-03
CVE-2026-18258
Analyzed
8.8
Scripta eScriptorium

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26

2026-08-06
CVE-2026-18248
Analyzed
9.1
Unknown aws-lambda

The @fastify/aws-lambda package in version 6.4.0 allows unauthenticated attackers to forge API Gateway proxy events, leading to a complete authenticat...

2026-08-04
CVE-2026-18236
Analyzed
9.3
Google ADK (Agent Development Kit)

A continuation forgery vulnerability in Google ADK allows unauthenticated attackers to forge tool confirmations and execute unauthorized tools.

2026-07-30
CVE-2026-18193
Analyzed
8.9
IBM i

IBM i 7

2026-08-14
CVE-2026-18191
Analyzed
9.8
Vacron VIN-DS783E-E6

The Vacron VIN-DS783E-E6 device contains hidden functionality that allows unauthenticated remote attackers to retrieve administrator credentials.

2026-07-29
CVE-2026-1819
Analyzed
8.8
Karel Electronics Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc

2026-02-04