21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10751-10800 of 21553 CVEs Page 216 of 432
CVE-2026-16053
Analyzed
8.5
Microsoft ManageEngine M365 Manager Plus and M365 Security Plus

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Excha...

2026-08-11
CVE-2026-16051
Analyzed
9.8
WordPress wpmudev-updates

The wpmudev-updates WordPress plugin fails to verify the integrity of installed packages and lacks replay protection, enabling unauthenticated remote...

2026-08-13
CVE-2026-1605
7.5
Unknown Multiple Products

In Eclipse Jetty, versions 12

2026-03-07
CVE-2026-16038
Analyzed
9.1
WordPress MStore API

The MStore API WordPress plugin fails to validate payments with the gateway before marking orders as paid, allowing unauthenticated attackers to obtai...

2026-08-15
CVE-2026-16036
Analyzed
7.5
WordPress 2FA

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the ta...

2026-08-10
CVE-2026-16030
Analyzed
8.1
WordPress MStore API

The MStore API WordPress plugin before 4

2026-08-08
CVE-2026-1603
KEV
8.6
Endpoint Endpoint Manager

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credentia...

2026-02-11
CVE-2026-16016
Analyzed
7.3
Unknown poco-claw

A vulnerability was identified in poco-ai poco-claw up to 0

2026-07-19
CVE-2026-16014
Analyzed
7.3
Unknown Hospital Bed Management System

A vulnerability was found in code-projects Hospital Bed Management System 1

2026-07-19
CVE-2026-16007
Analyzed
7.1
AppFlowy-IO AppFlowy-Cloud

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability

2026-08-16
CVE-2026-16002
Analyzed
8.2
MZ Automation lib60870

The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service

2026-07-24
CVE-2026-15992
Analyzed
8.8
WordPress WP Password Policy

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3

2026-07-29
CVE-2026-15991
Analyzed
8.8
WordPress File Manager

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in a...

2026-08-06
CVE-2026-15988
Analyzed
8.8
WordPress AI Engine – The Chatbot, AI Framework & MCP for WordPress

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...

2026-08-01
CVE-2026-15982
Analyzed
9.8
HP Aimogen Pro

The Aimogen Pro WordPress plugin is vulnerable to unauthenticated privilege escalation, allowing attackers to execute arbitrary PHP functions and crea...

2026-07-17
CVE-2026-15981
Analyzed
9.8
WordPress SAML Single Sign On – SSO Login

The SAML Single Sign On plugin for WordPress contains an authentication bypass flaw that allows unauthenticated users to gain access to any account, i...

2026-07-24
CVE-2026-15972
Analyzed
7.5
HashiCorp Consul

Consul Community Edition and Consul Enterprise 1

2026-08-09
CVE-2026-15965
Analyzed
8.8
WordPress MaxUpload – Big File Uploads – Increase Maximum File Upload Size

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to...

2026-08-15
CVE-2026-15964
Analyzed
9.8
WordPress Single Sign On For TNG

The Single Sign On For TNG WordPress plugin suffers from an unauthenticated password reset vulnerability due to insufficient validation of AJAX reques...

2026-08-02
CVE-2026-15962
Analyzed
8.8
HP Fluent Forms Pro Add On Pack

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6

2026-07-26
CVE-2026-1595
7.3
Unknown Multiple Products

A vulnerability was detected in itsourcecode Society Management System 1

2026-01-30
CVE-2026-1594
7.3
Unknown Multiple Products

A security vulnerability has been detected in itsourcecode Society Management System 1

2026-01-30
CVE-2026-15930
Analyzed
9.4
WordPress Simple Membership WordPress plugin

The Simple Membership WordPress plugin contains an authorization bypass vulnerability allowing unauthenticated attackers to overwrite administrator ac...

2026-08-04
CVE-2026-1593
7.3
Unknown Multiple Products

A weakness has been identified in itsourcecode Society Management System 1

2026-01-30
CVE-2026-15928
Analyzed
8.2
XMLRPC-C XMLRPC-C Library

XMLRPC-C Library versions 1

2026-07-27
CVE-2026-15925
Analyzed
9.2
Snowflake Snowflake Connector for Python

The Snowflake Connector for Python fails to properly verify TLS hostnames, allowing a network-positioned attacker to intercept traffic or execute arbi...

2026-07-17
CVE-2026-15905
Analyzed
7.8
Google Chrome

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file....

2026-07-27
CVE-2026-15904
Analyzed
8.8
Google Chrome

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gest...

2026-07-27
CVE-2026-15903
Analyzed
8.8
Google Chrome

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a...

2026-07-26
CVE-2026-15902
Analyzed
9.6
Google Chrome

A use-after-free vulnerability in the Cast component of Google Chrome allows a remote attacker to execute arbitrary code inside a sandbox via a crafte...

2026-07-26
CVE-2026-15901
Analyzed
9.6
Google Chrome

A critical use-after-free vulnerability exists in the Network component of Google Chrome, which could allow a remote attacker to exploit heap corrupti...

2026-07-26
CVE-2026-15900
Analyzed
9.6
Google Chrome

A critical use-after-free vulnerability in the GPU component of Google Chrome on Android allows remote attackers to trigger a sandbox escape via a cra...

2026-07-26
CVE-2026-1590
7.3
Unknown Multiple Products

A vulnerability was identified in itsourcecode School Management System 1

2026-01-30
CVE-2026-15899
Analyzed
9.6
Google Chrome

A critical use-after-free vulnerability in the CameraCapture component of Google Chrome on Mac permits remote attackers to achieve a sandbox escape th...

2026-07-26
CVE-2026-1589
7.3
Unknown Multiple Products

A vulnerability was determined in itsourcecode School Management System 1

2026-01-30
CVE-2026-1584
7.5
Unknown Multiple Products

A flaw was found in gnutls

2026-04-10
CVE-2026-15826
Analyzed
9.8
WordPress User Profile Builder

The User Profile Builder plugin for WordPress is vulnerable to an authentication bypass via type confusion, allowing unauthenticated attackers to log...

2026-08-15
CVE-2026-15816
Analyzed
7.5
Red Hat Enterprise Linux

A flaw was found in dracut

2026-08-09
CVE-2026-15810
Analyzed
8.7
Google Cloud Looker

A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25

2026-07-25
CVE-2026-1581
7.5
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2

2026-02-20
CVE-2026-15804
Analyzed
8.8
MetaGuru HCM

The HCM developed by MetaGuru has a SQL Injection vulnerability

2026-07-15
CVE-2026-15803
Analyzed
8.7
Eclipse Eclipse RDF4J

In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data...

2026-08-14
CVE-2026-1580
Analyzed
8.8
Nginx where the

A security issue was discovered in ingress-nginx where the `nginx

2026-02-04
CVE-2026-1579
Analyzed
9.8
PX4 MAVLink

The MAVLink protocol used in PX4 systems lacks default cryptographic authentication. Unauthenticated attackers can send `SERIAL_CONTROL` messages to g...

2026-04-01
CVE-2026-15776
Analyzed
8.8
Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150

2026-07-15
CVE-2026-15773
Analyzed
9.6
Google Chrome

A use-after-free vulnerability in the Google Chrome Core component allows a remote attacker to achieve sandbox escape via a crafted HTML page.

2026-07-15
CVE-2026-15767
Analyzed
8.8
Microsoft Chrome

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150

2026-07-15
CVE-2026-15748
Analyzed
9.8
WordPress Forminator Forms

The Forminator Forms plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the handle_file_upload function, potentially lea...

2026-08-18
CVE-2026-15747
9.1
Oracle Mojolicious

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_to...

2026-07-20
CVE-2026-15742
Analyzed
8.8
PostgreSQL PostgreSQL

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating...

2026-08-14