21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10901-10950 of 21553 CVEs Page 219 of 432
CVE-2026-1526
7.5
WebSocket Multiple Products

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression

2026-03-14
CVE-2026-15258
Analyzed
8.1
WordPress Product Feed Manager For WooCommerce

The Product Feed Manager For WooCommerce WordPress plugin before 7

2026-08-01
CVE-2026-15243
Analyzed
7.4
Apereo Java Apereo CAS Client

Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or rege...

2026-07-26
CVE-2026-15230
Analyzed
8.1
WordPress YayPricing

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, al...

2026-08-09
CVE-2026-15218
Analyzed
7.9
Red Hat OpenShift AI

A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI

2026-08-18
CVE-2026-15217
Analyzed
8.7
GitLab GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2026-08-14
CVE-2026-15216
Analyzed
8.7
GitLab GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2026-08-14
CVE-2026-15215
Analyzed
8.8
WordPress Subscriptions for WooCommerce

The Subscriptions for WooCommerce WordPress plugin before 2

2026-08-08
CVE-2026-15212
Analyzed
8.8
WordPress WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43

2026-07-24
CVE-2026-15210
Analyzed
9.1
WordPress OTP Login With Phone Number, OTP Verification

The OTP Login With Phone Number, OTP Verification plugin fails to limit verification attempts, allowing unauthenticated attackers to bypass authentica...

2026-08-09
CVE-2026-15205
Analyzed
8.6
WordPress Paymob for WooCommerce

The Paymob for WooCommerce WordPress plugin before 4

2026-08-15
CVE-2026-15162
Analyzed
7.5
Salesforce Object Sync for Salesforce

The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sy...

2026-08-16
CVE-2026-15158
Analyzed
9.8
HP Blocksy Companion

A flaw in the Blocksy Companion plugin's file validation allows unauthenticated attackers to upload malicious files, leading to remote code execution...

2026-07-10
CVE-2026-15155
Analyzed
8.8
WordPress Essential Addons for Elementor

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Em...

2026-07-11
CVE-2026-15143
Analyzed
9.3
Red Hat OpenShift AI (RHOAI)

A Server-Side Request Forgery vulnerability in the Red Hat OpenShift AI guardrails-detectors component permits unauthorized internal network requests...

2026-07-11
CVE-2026-15142
Analyzed
7.5
WordPress Real Estate Manager Pro

The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12

2026-08-16
CVE-2026-15133
Analyzed
8.8
Google Chrome

Use after free in InterestGroups in Google Chrome prior to 150

2026-07-10
CVE-2026-15132
Analyzed
8.8
Google Chrome

Uninitialized Use in V8 in Google Chrome prior to 150

2026-07-10
CVE-2026-1513
7.1
Unknown Multiple Products

billboard

2026-01-29
CVE-2026-15129
Analyzed
8.8
Google Chrome

Use after free in Views in Google Chrome prior to 150

2026-07-10
CVE-2026-15126
Analyzed
8.8
Google Chrome

Use after free in Forms in Google Chrome prior to 150

2026-07-10
CVE-2026-15125
Analyzed
8.8
Google Chrome

Inappropriate implementation in Forms in Google Chrome prior to 150

2026-07-10
CVE-2026-15123
Analyzed
8.8
Google Chrome

Inappropriate implementation in DOM in Google Chrome prior to 150

2026-07-10
CVE-2026-15122
Analyzed
8.3
Microsoft Chrome

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150

2026-07-10
CVE-2026-15121
Analyzed
8.8
Google Chrome

Use after free in WebRTC in Google Chrome prior to 150

2026-07-10
CVE-2026-15120
Analyzed
8.3
Microsoft Chrome

Use after free in Core in Google Chrome on Windows prior to 150

2026-07-10
CVE-2026-15119
Analyzed
8.3
Google Chrome

Race in GetUserMedia in Google Chrome prior to 150

2026-07-10
CVE-2026-15118
Analyzed
8.8
Google Chrome

Use after free in Input in Google Chrome prior to 150

2026-07-10
CVE-2026-15117
Analyzed
7.5
Google Chrome

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures t...

2026-07-12
CVE-2026-15116
Analyzed
8.8
Google Chrome

Use after free in Actor in Google Chrome prior to 150

2026-07-10
CVE-2026-15115
Analyzed
9.1
Google Chrome

Google Chrome on Android contains a vulnerability in WebAppInstalls that allows local attackers to bypass the same origin policy via crafted HTML page...

2026-07-11
CVE-2026-15114
Analyzed
8.8
Google Chrome

Out of bounds read and write in Codecs in Google Chrome prior to 150

2026-07-10
CVE-2026-15113
Analyzed
9.6
Google Chrome

A use-after-free vulnerability in the Google Chrome Autofill component on Android allows remote attackers to trigger a sandbox escape through a crafte...

2026-07-11
CVE-2026-15112
Analyzed
8.8
Google Chrome

Use after free in Ozone in Google Chrome prior to 150

2026-07-10
CVE-2026-15111
Analyzed
7.5
Google Chrome

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to p...

2026-07-13
CVE-2026-15110
Analyzed
8.8
Google Chrome

Use after free in Extensions in Google Chrome prior to 150

2026-07-10
CVE-2026-15107
Analyzed
8.8
Google Chrome

Use after free in IndexedDB in Google Chrome prior to 150

2026-07-10
CVE-2026-15103
Analyzed
8.8
WordPress WPFunnels – Funnel Builder for WooCommerce

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitra...

2026-07-16
CVE-2026-15091
Analyzed
9.3
IBM Engineering AI Hub

IBM Engineering AI Hub versions 1.0.0 through 1.2.0 are vulnerable to stored cross-site scripting due to improper input sanitization, allowing remote...

2026-07-18
CVE-2026-15089
Analyzed
9.1
Drupal Commerce guest registration

A critical security vulnerability exists in the Drupal Commerce guest registration module, which is now unmaintained and obsolete.

2026-07-15
CVE-2026-15081
Analyzed
9.8
Drupal Location Selector

A critical SQL injection vulnerability in the Drupal Location Selector module allows unauthenticated attackers to execute arbitrary SQL commands via u...

2026-07-15
CVE-2026-15079
Analyzed
9.8
Drupal Login Disable

The Drupal Login Disable module fails to properly restrict excessive authentication attempts, creating a vulnerability that facilitates brute force at...

2026-07-15
CVE-2026-15076
Analyzed
8.2
Eclipse Eclipse Vert.x

In versions up to and including 4

2026-07-14
CVE-2026-15075
Analyzed
8.2
Intel Eclipse Vert.x

In Eclipse Vert

2026-07-14
CVE-2026-15070
Analyzed
8.8
WordPress Salon Booking System – Free Version

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10

2026-07-10
CVE-2026-15068
Analyzed
9.9
IBM AIX

A command injection vulnerability exists within the NIM component of IBM AIX and PowerVM VIOS, allowing authenticated remote attackers to execute arbi...

2026-08-20
CVE-2026-15067
Analyzed
8.8
Snowflake Terraform Provider for Snowflake

Snowflake Terraform Provider versions prior to 2

2026-07-09
CVE-2026-15064
Analyzed
8.7
IBM WebSphere Application Server

IBM WebSphere Application Server 9

2026-07-29
CVE-2026-15062
Analyzed
9.6
Snowflake Snowpark Python SDK

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK allow authenticated low-privilege users to execute unauthorized SQL queries and pot...

2026-07-09
CVE-2026-1506
7.2
D-Link Multiple Products

A vulnerability was determined in D-Link DIR-615 4

2026-01-28