21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10851-10900 of 21553 CVEs Page 218 of 432
CVE-2026-15497
Analyzed
7.3
GitHub sonic-agent

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2

2026-07-13
CVE-2026-15491
Analyzed
7.3
RafyMrX TOKO-ONLINE-ROTI

A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99

2026-07-13
CVE-2026-15490
Analyzed
7.3
HP TOKO-ONLINE-ROTI

A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99

2026-07-13
CVE-2026-15489
Analyzed
7.3
RafyMrX TOKO-ONLINE-ROTI

A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99

2026-07-13
CVE-2026-15488
Analyzed
7.3
Unknown shiroiAdmin

A vulnerability was determined in hcr707305003 shiroiAdmin 1

2026-07-13
CVE-2026-15484
Analyzed
8.8
TRENDnet TEW-821DAP

A vulnerability was detected in TRENDnet TEW-821DAP 1

2026-07-12
CVE-2026-15483
Analyzed
8.8
TRENDnet TEW-821DAP

A security vulnerability has been detected in TRENDnet TEW-821DAP 1

2026-07-12
CVE-2026-15482
Analyzed
7.3
Aster Telecom Azcall

A weakness has been identified in Aster Telecom Azcall 10/11

2026-07-12
CVE-2026-15481
Analyzed
8.8
GitHub TEW-635BRM

A security flaw has been discovered in Trendnet TEW-635BRM up to 1

2026-07-12
CVE-2026-15480
Analyzed
8.8
Trendnet TEW-635BRM

A vulnerability was identified in Trendnet TEW-635BRM up to 1

2026-07-12
CVE-2026-15479
Analyzed
7.3
H3C NX15

A vulnerability was found in H3C NX15 V100R017

2026-07-12
CVE-2026-15467
Analyzed
8.1
Red Hat OpenShift AI

A flaw was found in the trustyai-service-operator's LMEvalJob controller

2026-08-11
CVE-2026-15459
Analyzed
8.1
WordPress WPMU DEV Dashboard

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5

2026-08-06
CVE-2026-15450
Analyzed
8.1
WordPress NEX-Forms – Ultimate Forms Plugin for WordPress

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and i...

2026-08-01
CVE-2026-1545
7.3
Unknown Multiple Products

A weakness has been identified in itsourcecode School Management System 1

2026-01-29
CVE-2026-15435
Analyzed
9.8
IBM App Connect Enterprise

IBM App Connect Enterprise is vulnerable to path traversal, allowing unauthenticated remote attackers to write arbitrary files to the system via speci...

2026-07-31
CVE-2026-15426
Analyzed
8.8
WordPress AcyMailing

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization byp...

2026-08-12
CVE-2026-15422
Analyzed
9.1
Unknown illumos-gate

A heap-based buffer overflow in the illumos SCTP inbound path allows an unauthenticated attacker to trigger remote code execution via a crafted INIT A...

2026-07-17
CVE-2026-15416
Analyzed
8.9
Red Hat argo-helm / Argo CD

A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access...

2026-07-15
CVE-2026-15414
Analyzed
8.8
WordPress Subscriptions for WooCommerce

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2

2026-08-01
CVE-2026-15413
Analyzed
10
WordPress Link Factory

The Link Factory WordPress plugin is a malicious backdoor that exposes a hardcoded REST API, allowing unauthorized operators to interact with the site...

2026-08-13
CVE-2026-15410
KEV Analyzed
9.5
SonicWall SMA1000 Appliances

SonicWall SMA1000 appliances are vulnerable to code injection, which can be exploited by an authenticated administrator to execute arbitrary code.

2026-07-15
CVE-2026-15409
KEV Analyzed
10
SonicWall SMA1000

A Server-side request forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to force the...

2026-07-15
CVE-2026-15401
Analyzed
7.2
WordPress VikBooking Hotel Booking Engine & PMS

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions u...

2026-07-26
CVE-2026-15392
7.7
HMBRAND DBD::File

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method build...

2026-07-20
CVE-2026-15389
Analyzed
8.7
Sesame Sesame Time

A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST...

2026-07-15
CVE-2026-15378
Analyzed
9.3
Red Hat OpenShift AI (RHOAI)

A blind SSRF vulnerability in the Red Hat OpenShift AI guardrails-detectors component allows remote attackers to access sensitive internal metadata an...

2026-07-11
CVE-2026-15372
Analyzed
7.5
WordPress WP 2FA

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, a...

2026-08-10
CVE-2026-15371
Analyzed
8.1
Rapid7 Velociraptor

Velociraptor's web GUI allows specifying a custom type for columns in tables

2026-08-18
CVE-2026-15361
Analyzed
8.1
WordPress Content Views

The Content Views WordPress plugin before 4

2026-08-08
CVE-2026-15360
Analyzed
9.1
WordPress Ajax Load More

The Ajax Load More WordPress plugin before 8.0.1 contains a SQL injection vulnerability allowing unauthenticated attackers to extract sensitive databa...

2026-08-10
CVE-2026-1535
7.3
Unknown Multiple Products

A security vulnerability has been detected in code-projects Online Music Site 1

2026-01-29
CVE-2026-15343
Analyzed
8.6
GitHub Enterprise Server

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot update...

2026-07-18
CVE-2026-15341
Analyzed
9.8
WordPress User Session Synchronizer

The User Session Synchronizer plugin for WordPress is vulnerable to an authentication bypass via improper cryptographic validation, allowing unauthent...

2026-08-15
CVE-2026-1534
7.3
Unknown Multiple Products

A weakness has been identified in code-projects Online Music Site 1

2026-01-29
CVE-2026-15338
Analyzed
7.5
WordPress LA-Studio Element Kit for Elementor

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2026-07-11
CVE-2026-15335
Analyzed
7.5
WordPress Booking Package

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and includ...

2026-07-11
CVE-2026-15325
Analyzed
8.7
IBM WebSphere Application Server

IBM WebSphere Application Server 9

2026-07-29
CVE-2026-15322
Analyzed
7.5
IBM Engineering AI Hub

IBM Engineering AI Hub 1

2026-07-19
CVE-2026-15312
Analyzed
8.8
WordPress Propovoice: All-in-One Client Management System

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-08-15
CVE-2026-1531
Analyzed
8.1
Kubernetes Multiple Products

A flaw was found in foreman_kubevirt

2026-02-02
CVE-2026-15308
Analyzed
8.7
Python CPython

The incremental HTML parser (html

2026-07-10
CVE-2026-15307
Analyzed
8.8
Unknown Django

An issue was discovered in Django 5

2026-08-05
CVE-2026-15303
Analyzed
9.8
WordPress 6Storage Rentals

The 6Storage Rentals plugin for WordPress contains an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user,...

2026-08-15
CVE-2026-15300
Analyzed
9.1
WordPress GEO my WP

The GEO my WP WordPress plugin is vulnerable to unauthenticated SQL injection via the 'distance', 'lat', and 'lng' parameters due to improper sanitiza...

2026-07-10
CVE-2026-1530
Analyzed
8.1
Kubernetes Multiple Products

A flaw was found in fog-kubevirt

2026-02-02
CVE-2026-15293
Analyzed
8
Intel WP Business Intelligence Lite

The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3

2026-07-10
CVE-2026-1529
8.1
Unknown Multiple Products

A flaw was found in Keycloak

2026-02-10
CVE-2026-15282
Analyzed
9.8
WordPress Instant Appointment

The Instant Appointment WordPress plugin is vulnerable to unauthenticated arbitrary file uploads, potentially leading to remote code execution.

2026-07-10
CVE-2026-1528
7.5
ImpactA Multiple Products

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length

2026-03-14