21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10601-10650 of 21553 CVEs Page 213 of 432
CVE-2026-1679
7.3
Unknown Multiple Products

The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi-...

2026-03-29
CVE-2026-1678
Analyzed
9.4
Zephyr Project Zephyr RTOS

A buffer management flaw in dns_unpack_name() allows unauthenticated attackers to trigger an out-of-bounds write via malicious DNS responses when CONF...

2026-03-05
CVE-2026-16772
Analyzed
8.1
Akaunting Akaunting

In Akaunting versions <= 3

2026-08-16
CVE-2026-16771
Analyzed
8.8
AT&T / Arris BGW210-700

In firmware versions 2

2026-07-29
CVE-2026-16745
Analyzed
8.8
Red Hat Red Hat OpenShift AI (RHOAI)

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI)

2026-07-24
CVE-2026-16736
Analyzed
7.5
WordPress User Registration & Membership

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registrati...

2026-08-14
CVE-2026-16731
Analyzed
8.3
OMICRON electronics GmbH StationScout

OMICRON StationScout before version 3

2026-08-06
CVE-2026-16722
Analyzed
8.8
IBM i

IBM i 7

2026-08-14
CVE-2026-16708
Analyzed
8.3
IBM Db2 Mirror for i

IBM Db2 Mirror for i 7

2026-08-16
CVE-2026-1670
Analyzed
9.8
Unknown Multiple Products

An unauthenticated API endpoint exposure allows remote attackers to modify the "forgot password" recovery email address, facilitating account takeover...

2026-02-18
CVE-2026-16674
Analyzed
8.8
IBM i

IBM i 7

2026-08-14
CVE-2026-1667
Analyzed
7.2
WordPress GEO Plugin by Squirrly SEO

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, an...

2026-07-12
CVE-2026-16635
Analyzed
8.8
WordPress Pronamic Pay

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10

2026-08-02
CVE-2026-16634
9.8
FELIPE TOML::XS

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has...

2026-08-16
CVE-2026-16626
Analyzed
9.3
Jaspersoft JasperReports Server

An unauthenticated XML external entity (XXE) vulnerability in Jaspersoft JasperReports Server allows remote attackers to read sensitive files or poten...

2026-08-11
CVE-2026-16623
Analyzed
8
WordPress Create Block Theme

The Create Block WordPress plugin before 2

2026-08-05
CVE-2026-1662
7.5
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14

2026-02-26
CVE-2026-16618
Analyzed
9.8
HP Improve SEO

The Improve SEO WordPress plugin fails to validate file extensions during uploads, allowing unauthenticated attackers to upload executable PHP files a...

2026-08-05
CVE-2026-16617
Analyzed
8.8
WordPress Simple File List

The Simple File List WordPress plugin through 6

2026-08-20
CVE-2026-16610
Analyzed
9.8
WordPress Admin and Site Enhancements (ASE) Pro

The ASE Pro WordPress plugin is vulnerable to remote code execution due to improper input sanitization and a lack of authentication checks in its fron...

2026-07-30
CVE-2026-16607
Analyzed
7.8
Oracle Linux openFT and Oracle Solaris openFT

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12

2026-07-24
CVE-2026-16605
Analyzed
7.2
WordPress MultiVendorX

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowi...

2026-08-14
CVE-2026-16604
Analyzed
7.5
WordPress Passster WordPress Plugin

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowi...

2026-08-10
CVE-2026-16603
Analyzed
7.5
WordPress Passster WordPress plugin

The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated...

2026-08-10
CVE-2026-16602
Analyzed
7.5
WordPress Passster WordPress plugin

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint,...

2026-08-10
CVE-2026-16589
Analyzed
7.7
WordPress WP Directory Kit

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its auth...

2026-08-16
CVE-2026-16585
Analyzed
7.2
WordPress Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to ins...

2026-07-28
CVE-2026-16573
Analyzed
7.5
WordPress Bit Form WordPress plugin

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upl...

2026-08-10
CVE-2026-16572
Analyzed
8.6
WordPress LogMyTrip

The LogMyTrip WordPress plugin through 1

2026-08-04
CVE-2026-16561
Analyzed
7.5
WordPress Sunshine Photo Cart

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated us...

2026-08-10
CVE-2026-16540
Analyzed
7.5
WordPress Simply Schedule Appointments

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own reco...

2026-08-09
CVE-2026-16539
Analyzed
8.1
WordPress sm page duplicator

The sm page duplicator WordPress plugin through 1

2026-08-04
CVE-2026-16526
Analyzed
8.8
Red Hat Red Hat Enterprise Linux

A flaw in the PCP linux_sockets module exposes an unsecured internal connection

2026-07-30
CVE-2026-16498
Analyzed
10
HashiCorp Terraform MCP Server

A cross-tenant credential reuse vulnerability in HashiCorp terraform-mcp-server before 1.1.0 allows unauthorized access to tool calls by using a previ...

2026-07-29
CVE-2026-16496
Analyzed
8.9
HashiCorp Terraform MCP Server

The terraform-mcp-server before version 1

2026-07-29
CVE-2026-16481
Analyzed
8.4
Google MCP Toolbox for Databases

A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-t...

2026-07-28
CVE-2026-1648
7.2
WordPress is vulnerable

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1

2026-03-22
CVE-2026-16471
Analyzed
7.5
Dolusoft Software Sonlogger

Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs

2026-08-18
CVE-2026-16467
Analyzed
7.5
Dolusoft Software Fortilogger

Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs

2026-08-18
CVE-2026-16462
Analyzed
9.8
Weidmueller Interface PROCON-WEB SCADA

An unauthenticated SQL injection vulnerability in the GetGridData endpoint of PROCON-WEB SCADA allows remote attackers to execute arbitrary SQL comman...

2026-07-29
CVE-2026-16424
Analyzed
9.6
Google Chrome

A use after free vulnerability in the GPU component of Google Chrome on Android allows a remote attacker to achieve a sandbox escape via a crafted HTM...

2026-07-30
CVE-2026-16423
Analyzed
8.8
Google Chrome

Use after free in UI in Google Chrome prior to 150

2026-07-23
CVE-2026-16422
Analyzed
7.5
Google Chrome

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged networ...

2026-07-30
CVE-2026-16421
Analyzed
8.8
Google Chrome

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox...

2026-07-31
CVE-2026-16420
Analyzed
8.8
Google Chrome

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...

2026-07-31
CVE-2026-16419
Analyzed
9.6
Google Chrome

An out of bounds read and write in ANGLE in Google Chrome on Android allows a remote attacker to potentially perform a sandbox escape via a crafted HT...

2026-07-30
CVE-2026-16418
Analyzed
8.8
Google Chrome

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafte...

2026-07-31
CVE-2026-16416
Analyzed
8.3
Google Chrome

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious...

2026-07-30
CVE-2026-16414
Analyzed
8.3
Google Chrome

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sa...

2026-07-30
CVE-2026-16413
Analyzed
8.3
Google Chrome

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentiall...

2026-07-30