18005 Total CVEs
9537 AI Analyzed
271 CISA KEV
3678 Critical
All Vendors
Showing 1051-1100 of 18005 CVEs Page 22 of 361
CVE-2026-59874
Analyzed
8.7
Unknown node-tar

node-tar is a tar archive manipulation library for Node

2026-07-09
CVE-2026-59873
Analyzed
9.2
Unknown node-tar

The node-tar library for Node.js fails to enforce resource limits during archive extraction, allowing attackers to trigger denial-of-service via craft...

2026-07-09
CVE-2026-59858
Analyzed
8.4
Vim Vim

Vim is an open source, command line text editor

2026-07-10
CVE-2026-59856
Analyzed
8.4
Vim Vim

Vim is an open source, command line text editor

2026-07-10
CVE-2026-59855
Analyzed
8.6
SiYuan SiYuan

SiYuan is an open-source personal knowledge management system

2026-07-10
CVE-2026-5984
8.8
D-Link DIR

A vulnerability was identified in D-Link DIR-605L 2

2026-04-10
CVE-2026-59833
Analyzed
8.6
Unknown siyuan

SiYuan is an open-source personal knowledge management system

2026-07-10
CVE-2026-59832
Analyzed
7.7
SiYuan SiYuan

SiYuan is an open-source personal knowledge management system

2026-07-10
CVE-2026-5983
8.8
D-Link DIR

A vulnerability was determined in D-Link DIR-605L 2

2026-04-10
CVE-2026-59827
Analyzed
9.9
Intel metabase

Metabase instances using H2 database connections are vulnerable to remote code execution via the deserialization of untrusted data in native query res...

2026-07-10
CVE-2026-59826
Analyzed
9.1
Metabase Metabase

Metabase fails to validate H2 database connection properties, allowing an authenticated administrator to execute arbitrary Java code on the server.

2026-07-10
CVE-2026-59822
Analyzed
8.8
BerriAI LiteLLM

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

2026-07-09
CVE-2026-5982
8.8
D-Link DIR

A vulnerability was found in D-Link DIR-605L 2

2026-04-10
CVE-2026-5981
8.8
D-Link DIR

A vulnerability has been found in D-Link DIR-605L 2

2026-04-10
CVE-2026-59802
Analyzed
8.2
PasswordPusher PasswordPusher

PasswordPusher before 2

2026-07-09
CVE-2026-59801
Analyzed
9.8
Unknown 9Router

A missing authentication vulnerability in decolua 9Router allows unauthenticated remote attackers to interact with management API endpoints.

2026-07-14
CVE-2026-59800
Analyzed
9.8
Unknown 9router

9Router contains an OS command injection vulnerability in an unauthenticated API endpoint, allowing remote attackers to execute arbitrary system comma...

2026-07-08
CVE-2026-5980
8.8
D-Link DIR

A flaw has been found in D-Link DIR-605L 2

2026-04-10
CVE-2026-59796
Analyzed
8.1
JetBrains TeamCity

In JetBrains TeamCity before 2026

2026-07-11
CVE-2026-59795
Analyzed
8.1
JetBrains TeamCity

In JetBrains TeamCity before 2026

2026-07-11
CVE-2026-59794
Analyzed
7.3
JetBrains TeamCity

In JetBrains TeamCity before 2026

2026-07-12
CVE-2026-59793
Analyzed
8.8
JetBrains TeamCity

In JetBrains TeamCity before 2026

2026-07-11
CVE-2026-59792
Analyzed
9.6
Intel IntelliJ IDEA

JetBrains IntelliJ IDEA is vulnerable to remote code execution due to path traversal in project workspace ID handling.

2026-07-11
CVE-2026-5979
8.8
D-Link DIR

A vulnerability was detected in D-Link DIR-605L 2

2026-04-10
CVE-2026-5978
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU CGI Handler contains an OS command injection vulnerability in the setWiFiAclRules function, allowing remote attackers to execute...

2026-04-10
CVE-2026-5977
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU CGI Handler contains an OS command injection vulnerability in the setWiFiBasicCfg function, allowing remote attackers to execute...

2026-04-10
CVE-2026-5976
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU CGI Handler contains an OS command injection vulnerability in the setStorageCfg function, allowing remote attackers to execute ar...

2026-04-10
CVE-2026-5975
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU CGI Handler contains an OS command injection vulnerability in the setDmzCfg function, allowing remote attackers to execute arbitr...

2026-04-10
CVE-2026-59734
Analyzed
8.8
Coollabs Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-10
CVE-2026-59731
Analyzed
8.2
Unknown Astro

Astro is a web framework for content-driven websites

2026-07-09
CVE-2026-59726
Analyzed
10
Ruvnet Ruflo

Ruflo's default deployment exposes unauthenticated MCP endpoints, allowing remote attackers to execute terminal commands and steal API keys.

2026-07-10
CVE-2026-59723
Analyzed
8.8
Cline Cline

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant

2026-07-09
CVE-2026-59713
Analyzed
8.1
Leantime Leantime

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters

2026-07-07
CVE-2026-59712
Analyzed
8.1
Leantime Leantime

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential...

2026-07-07
CVE-2026-59707
Analyzed
8.6
LocalAI LocalAI

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitr...

2026-07-08
CVE-2026-59706
Analyzed
9.3
Unknown mem0

Unauthenticated configuration endpoints in mem0 expose plaintext API keys and allow for server-side request forgery (SSRF) attacks against internal se...

2026-07-08
CVE-2026-59705
Analyzed
9.8
Unknown mem0

The mem0 API component suffers from an unauthenticated access vulnerability allowing remote attackers to read, write, or delete user memories and trig...

2026-07-08
CVE-2026-59702
Analyzed
9.3
Repomix Repomix

Repomix contains a server-side request forgery (SSRF) vulnerability in the POST /api/pack endpoint, allowing unauthenticated attackers to make arbitra...

2026-07-09
CVE-2026-5967
8.8
Unknown Multiple Products

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability

2026-04-21
CVE-2026-5966
Analyzed
8.1
TeamT5 ThreatSonar Anti-Ransomware

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability

2026-04-20
CVE-2026-5965
Analyzed
9.8
Unknown Multiple Products

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and...

2026-04-21
CVE-2026-5964
Analyzed
9.8
Digiwin EasyFlow .NET

Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.

2026-04-20
CVE-2026-5963
Analyzed
9.8
Digiwin EasyFlow .NET

Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.

2026-04-20
CVE-2026-5955
Analyzed
9.8
Unknown BiEticaret

BiEticaret is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL commands against the database.

2026-07-10
CVE-2026-59518
Analyzed
9.8
HP Directorist

The Directorist plugin for WordPress is vulnerable to PHP Object Injection via deserialization of untrusted data, allowing unauthenticated attackers t...

2026-07-14
CVE-2026-59515
Analyzed
9.3
WordPress AIWU

The Sergey AIWU WordPress plugin contains a Blind SQL Injection vulnerability, permitting unauthenticated attackers to execute malicious database quer...

2026-07-14
CVE-2026-59510
Analyzed
7.1
AIL Project AIL Framework

AIL Framework contains a path traversal vulnerability in its PDF object handling

2026-07-06
CVE-2026-59509
Analyzed
9.2
Unknown cve-search

The cve-search application is vulnerable to improper input validation in its API, allowing unauthenticated remote attackers to read arbitrary MongoDB...

2026-07-06
CVE-2026-5947
Analyzed
7.5
Undefined Multiple Products

Undefined behavior may result due to a race condition leading to a use-after-free violation

2026-05-22
CVE-2026-5946
Analyzed
7.5
AWS have been

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `H...

2026-05-22