21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10501-10550 of 21553 CVEs Page 211 of 432
CVE-2026-1756
Analyzed
8.8
WordPress is vulnerable

The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::fi...

2026-02-04
CVE-2026-17556
Analyzed
8.8
GitHub Enterprise Server

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and direc...

2026-08-06
CVE-2026-17544
Analyzed
8.1
HP PHP

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8

2026-08-01
CVE-2026-17543
Analyzed
8.1
HP PHP

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8

2026-08-01
CVE-2026-17542
Analyzed
7.5
WordPress File Manager

The File Manager WordPress plugin before 6

2026-08-11
CVE-2026-17541
Analyzed
7.5
WordPress File Manager

The File Manager WordPress plugin before 6

2026-08-11
CVE-2026-17540
Analyzed
8.8
WordPress File Manager plugin

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a su...

2026-08-18
CVE-2026-17527
Analyzed
7.7
Red Hat OpenShift Virtualization 4

In containerized-data-importer (CDI), the aggregated cdi

2026-07-28
CVE-2026-17524
Analyzed
7.5
Unknown zip-lib

Versions of the package zip-lib before 1

2026-07-28
CVE-2026-17523
Analyzed
7.8
Red Hat Red Hat Enterprise Linux

A flaw was found in the kernel

2026-07-28
CVE-2026-17510
Analyzed
7.5
JONASBN Crypt::OpenSSL::PKCS12

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print...

2026-08-17
CVE-2026-17502
Analyzed
8.6
IBM i

IBM i 7

2026-08-14
CVE-2026-1750
Analyzed
8.8
WordPress is vulnerable

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7

2026-02-15
CVE-2026-17497
Analyzed
8.3
NoteGen NoteGen

NoteGen before 0

2026-07-27
CVE-2026-17496
Analyzed
8.1
AMD NoteGen

NoteGen before 0

2026-07-27
CVE-2026-17482
Analyzed
9.8
IBM Documentation Offline

IBM Documentation Offline 1.0.0 through 1.4.1 contains a path traversal vulnerability that permits unauthenticated remote attackers to execute arbitra...

2026-08-14
CVE-2026-17481
Analyzed
8.8
IBM Documentation Offline

IBM Documentation Offline 1

2026-08-14
CVE-2026-17417
Analyzed
8.8
IBM i

IBM i 7

2026-08-13
CVE-2026-1740
Analyzed
7.3
Unknown Multiple Products

A vulnerability was found in EFM ipTIME A8004T 14

2026-02-02
CVE-2026-17351
Analyzed
9
Unknown pgAdmin 4

A flawed fix in pgAdmin 4 allows for SQL injection via AI Assistant tool calls, enabling attackers to execute arbitrary multi-statement SQL commands.

2026-08-01
CVE-2026-17349
Analyzed
9.6
Unknown pgAdmin 4

A vulnerability in the pgAdmin 4 Workspaces feature allows authenticated users to clone and inherit sensitive database credentials from other users, l...

2026-08-01
CVE-2026-17347
Analyzed
7.5
Unknown pgAdmin 4

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7

2026-08-01
CVE-2026-17346
Analyzed
8.8
Unknown pgAdmin 4

The fix for CVE-2026-12044 in pgAdmin 4 9

2026-08-01
CVE-2026-1731
KEV
9.5
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability - Active in CISA KEV catalog.

2026-02-14
CVE-2026-1730
Analyzed
8.8
WordPress Multiple Products

The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::...

2026-02-03
CVE-2026-1729
Analyzed
9.8
WordPress is vulnerable

The AdForest WordPress theme (<= 6.0.12) is vulnerable to authentication bypass via the sb_login_user_with_otp_fun function, allowing attackers to log...

2026-02-12
CVE-2026-1728
Analyzed
9.8
WSO2 WSO2 API Manager

WSO2 API Manager suffers from improper privilege management where low-privileged tokens can access administrative REST APIs, potentially leading to fu...

2026-08-06
CVE-2026-17223
Analyzed
8.8
IBM i

IBM i 7

2026-08-14
CVE-2026-17218
Analyzed
9.8
IBM i

IBM i versions 7.3 through 7.6 are affected by an out-of-bounds write vulnerability that allows a remote, unauthenticated attacker to execute arbitrar...

2026-08-13
CVE-2026-1720
8.8
WordPress is vulnerable

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrar...

2026-03-06
CVE-2026-17192
Analyzed
8.5
Arista VeloCloud Orchestrator On-Prem

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to interna...

2026-07-28
CVE-2026-17191
Analyzed
9.1
Arista Networks VeloCloud Orchestrator On-Prem

An authenticated SQL injection vulnerability in the Arista VeloCloud Orchestrator API allows for unauthorized data access and unintended outbound netw...

2026-07-28
CVE-2026-1719
Analyzed
7.5
WordPress is vulnerable

The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2

2026-05-06
CVE-2026-17186
Analyzed
9.9
IBM Db2 Mirror for i

IBM Db2 Mirror for i is vulnerable to remote command injection, allowing unauthenticated attackers to execute arbitrary CL commands via improper neutr...

2026-08-15
CVE-2026-17184
Analyzed
9.8
IBM Db2 Mirror for i

IBM Db2 Mirror for i contains a path traversal vulnerability that allows remote, unauthenticated attackers to execute arbitrary code through external...

2026-08-15
CVE-2026-17182
Analyzed
9.8
IBM Db2 Mirror for i

An authentication bypass vulnerability in IBM Db2 Mirror for i allows unauthenticated remote attackers to access or modify sensitive data by manipulat...

2026-08-15
CVE-2026-17179
Analyzed
8.5
IBM Db2 Mirror for i

IBM Db2 Mirror for i 7

2026-08-15
CVE-2026-17177
Analyzed
7.5
IBM Db2 Mirror for i

IBM Db2 Mirror for i 7

2026-08-16
CVE-2026-17175
Analyzed
7.5
IBM Db2 Mirror for i

IBM Db2 Mirror for i 7

2026-08-16
CVE-2026-1714
8.6
WordPress is vulnerable

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abu...

2026-02-18
CVE-2026-17123
Analyzed
8.8
WordPress Royal Addons for Elementor

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1

2026-08-16
CVE-2026-17110
Analyzed
8.8
IBM i

IBM i 7

2026-08-13
CVE-2026-17107
Analyzed
8.5
Kubernetes Multicluster Engine for Kubernetes

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engi...

2026-07-25
CVE-2026-1709
Analyzed
9.4
Keylime Keylime Registrar

The Keylime registrar fails to enforce client-side TLS authentication. This allows unauthenticated attackers to perform administrative operations, inc...

2026-02-07
CVE-2026-17087
Analyzed
7.5
WordPress WP Travel Engine – Tour Booking Plugin – Tour Operator Software

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to,...

2026-08-16
CVE-2026-17083
Analyzed
9.8
IBM i

IBM i versions 7.3 through 7.6 are affected by a stack-based buffer overflow vulnerability that allows remote, unauthenticated attackers to execute ar...

2026-08-13
CVE-2026-17082
Analyzed
8.8
IBM i

IBM i 7

2026-08-13
CVE-2026-17081
Analyzed
8.2
IBM Db2 Mirror for i

IBM Db2 Mirror for i 7

2026-08-16
CVE-2026-17070
Analyzed
8.8
HAVELSAN Liman MYS

Missing Authorization vulnerability in HAVELSAN Inc

2026-08-05
CVE-2026-1707
7.4
Unknown Multiple Products

pgAdmin versions 9

2026-02-06