21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10701-10750 of 21553 CVEs Page 215 of 432
CVE-2026-16280
9.8
Imagination Technologies Graphics DDK

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 G...

2026-08-13
CVE-2026-16268
Analyzed
8.2
WordPress Newsletters

The Newsletters WordPress plugin before 4

2026-08-06
CVE-2026-16267
Analyzed
8.1
HP Newsletters (newsletters-lite)

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, all...

2026-08-16
CVE-2026-16263
Analyzed
8.8
WordPress WP Maps

The WP Maps WordPress plugin before 4

2026-08-08
CVE-2026-16262
Analyzed
7.5
WordPress Estatik Real Estate Plugin

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an una...

2026-08-15
CVE-2026-16258
Analyzed
9.8
HP Ajax Search Lite

The Ajax Search Lite WordPress plugin is vulnerable to PHP object injection due to improper deserialization of untrusted input, which can lead to remo...

2026-08-08
CVE-2026-16257
Analyzed
8.2
WordPress AI SEO Writer

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be...

2026-08-17
CVE-2026-16248
Analyzed
8.8
Tenda AC10

A vulnerability was found in Tenda AC10 16

2026-07-21
CVE-2026-16242
Analyzed
9.4
Red Hat Logging Subsystem for Red Hat OpenShift

A flaw in the Konnectivity proxy-server configuration for hosted control planes allows unauthenticated remote attackers to connect as an agent and man...

2026-07-20
CVE-2026-16239
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via...

2026-08-14
CVE-2026-16238
Analyzed
8.8
PostgreSQL PostgreSQL

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the...

2026-08-14
CVE-2026-16236
Analyzed
8.8
WordPress Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5

2026-07-31
CVE-2026-16235
Analyzed
9.8
DRSTEVE Crypt::Password

Crypt::Password versions 0.28 and earlier utilize a cryptographically weak pseudo-random number generator, leading to predictable salt generation.

2026-07-21
CVE-2026-16232
KEV Analyzed
9.5
GitHub SmartConsole

An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.

2026-07-23
CVE-2026-16230
Analyzed
9.8
WordPress Formidable Digital Signatures

The Formidable Digital Signatures plugin for WordPress up to 3.0.6 contains a path traversal vulnerability that allows unauthenticated attackers to de...

2026-08-12
CVE-2026-16228
Analyzed
7.3
SourceCodester Class and Exam Timetabling System

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1

2026-07-20
CVE-2026-16227
Analyzed
7.3
SourceCodester Class and Exam Timetabling System

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1

2026-07-20
CVE-2026-16221
Analyzed
7.5
Unknown fast-uri

Impact: fast-uri versions from 2

2026-07-20
CVE-2026-16210
Analyzed
7.3
Unknown simpleui

A vulnerability was found in newpanjing simpleui 2026

2026-07-19
CVE-2026-16209
Analyzed
7.3
GitHub Gerapy

A vulnerability has been found in Gerapy up to 0

2026-07-19
CVE-2026-16200
Analyzed
7.3
Unknown rt-claw

A vulnerability has been found in zevorn rt-claw up to 0

2026-07-19
CVE-2026-1620
8.8
WordPress is vulnerable

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9

2026-04-16
CVE-2026-1619
8.3
Universal Software Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc

2026-02-14
CVE-2026-1618
Analyzed
8.8
Universal Software Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc

2026-02-14
CVE-2026-1616
Analyzed
7.5
Nginx Multiple Products

The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025

2026-01-30
CVE-2026-16158
Analyzed
8.7
Fastify @fastify/reply-from

Impact: @fastify/reply-from versions from 8

2026-07-19
CVE-2026-16154
Analyzed
7.3
HP Class and Exam Timetabling System

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1

2026-07-19
CVE-2026-16152
Analyzed
7.3
HP Class and Exam Timetabling System

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1

2026-07-19
CVE-2026-1615
Analyzed
9.8
All jsonpath (Node.js/Browser Package)

All versions of the jsonpath library are vulnerable to arbitrary code injection via unsafe evaluation of user-supplied JSON Path expressions.

2026-02-09
CVE-2026-16145
Analyzed
7.2
WordPress Invisible Anti-Spam & CAPTCHA

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'act...

2026-08-16
CVE-2026-16144
Analyzed
8.1
WordPress Kali Forms

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...

2026-08-01
CVE-2026-16142
Analyzed
9.8
WordPress TrueBooker – Appointment Booking and Scheduler System

The TrueBooker WordPress plugin is vulnerable to account takeover due to an insecure AJAX handler that allows unauthenticated users to modify any acco...

2026-08-15
CVE-2026-16138
Analyzed
8
Progress ShareFile Storage Zones Controller

In Progress ShareFile Storage Zones Controller v5

2026-08-18
CVE-2026-16128
Analyzed
7.3
Unknown rt-claw

A security flaw has been discovered in zevorn rt-claw up to 0

2026-07-19
CVE-2026-16127
Analyzed
7.3
Unknown rt-claw

A vulnerability was identified in zevorn rt-claw up to 0

2026-07-19
CVE-2026-16126
Analyzed
7.3
Unknown rt-claw

A vulnerability was determined in zevorn rt-claw up to 0

2026-07-19
CVE-2026-16125
Analyzed
7.3
Unknown rt-claw

A vulnerability was found in zevorn rt-claw up to 0

2026-07-19
CVE-2026-16118
Analyzed
7.1
Red Hat Red Hat Enterprise Linux

A flaw was found in xdgmime

2026-07-19
CVE-2026-16117
Analyzed
10
Unknown http-proxy

The @fastify/http-proxy package fails to correctly rewrite request prefixes when URL-encoded, allowing attackers to bypass configured path restriction...

2026-07-19
CVE-2026-16101
Analyzed
8.8
Silicon Labs WiseConnect

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device

2026-08-14
CVE-2026-1610
8.1
Tenda Multiple Products

A vulnerability was found in Tenda AX12 Pro V2 16

2026-01-30
CVE-2026-16099
Analyzed
8.8
WordPress Podlove Podcast Publisher

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_lin...

2026-08-16
CVE-2026-16098
Analyzed
9.8
WordPress ProSolution WP Client

The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to insufficient validation of file extensions an...

2026-08-16
CVE-2026-16097
Analyzed
8.8
Shibby Tomato

A vulnerability was found in Shibby Tomato 1

2026-07-19
CVE-2026-16096
Analyzed
8.8
Shibby Tomato

A vulnerability has been found in Shibby Tomato 1

2026-07-19
CVE-2026-16095
Analyzed
8.8
Shibby Tomato

A flaw has been found in Shibby Tomato 1

2026-07-19
CVE-2026-1609
Analyzed
8.1
Keycloak Keycloak

A flaw was found in Keycloak

2026-07-17
CVE-2026-16084
Analyzed
7.3
Sipeed PicoClaw

A weakness has been identified in Sipeed PicoClaw up to 0

2026-07-19
CVE-2026-16060
Analyzed
9.8
WordPress Insert or Embed Articulate Content into WordPress

The Insert or Embed Articulate Content into WordPress plugin fails to properly validate uploaded archives, allowing malicious file uploads and potenti...

2026-08-11
CVE-2026-16055
Analyzed
7.5
WordPress Contest Gallery

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an...

2026-08-10