21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 11051-11100 of 21553 CVEs Page 222 of 432
CVE-2026-14653
Analyzed
7.3
HP Simple and Nice Shopping Cart Script

A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1

2026-07-05
CVE-2026-14652
Analyzed
7.3
SourceCodester Simple and Nice Shopping Cart Script

A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1

2026-07-05
CVE-2026-14649
Analyzed
7.3
HP Online Voting System

A vulnerability was detected in code-projects Online Voting System 1

2026-07-05
CVE-2026-14648
Analyzed
7.3
HP Online Voting System

A security vulnerability has been detected in code-projects Online Voting System up to 0

2026-07-05
CVE-2026-14644
Analyzed
8.6
Cisco Nexus Repository 3

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API

2026-08-08
CVE-2026-14642
Analyzed
7.3
HP Class and Exam Timetabling System

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1

2026-07-05
CVE-2026-14641
Analyzed
7.3
HP Class and Exam Timetabling System

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1

2026-07-05
CVE-2026-14640
Analyzed
7.3
HP Apartment Visitor Management System

A vulnerability was found in CodeAstro Apartment Visitor Management System 1

2026-07-05
CVE-2026-14637
Analyzed
8.2
F5 Ecommerce-CodeIgniter-Bootstrap

A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7

2026-07-05
CVE-2026-14635
Analyzed
7.3
Unknown Ecommerce-CodeIgniter-Bootstrap

A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b

2026-07-05
CVE-2026-1463
8.8
WordPress is vulnerable

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...

2026-03-19
CVE-2026-14622
Analyzed
7.3
HP restaurant-website-php-mysql

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35

2026-07-05
CVE-2026-1462
8.8
Unknown Multiple Products

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3

2026-04-14
CVE-2026-14606
Analyzed
7.8
RT-Thread RT-Thread

A security flaw has been discovered in RT-Thread up to 5

2026-07-03
CVE-2026-14605
Analyzed
7.8
RT-Thread RT-Thread

A vulnerability was identified in RT-Thread up to 5

2026-07-03
CVE-2026-14603
7.5
WordPress WowOptin: Next-Gen Popup Maker

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated use...

2026-08-05
CVE-2026-1459
7.2
Zyxel VMG3625

A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions throu...

2026-02-24
CVE-2026-14570
Analyzed
7.5
TIMLEGGE Crypt::DSA

Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery....

2026-07-10
CVE-2026-14564
Analyzed
9
Unknown Logsign SIEM

A vulnerability exists in Logsign SIEM involving insufficiently protected credentials, which allows an authenticated attacker with high privileges to...

2026-08-18
CVE-2026-14557
Analyzed
9.1
WordPress Digital Marketplace WordPress plugin

The SoftMarket Digital Marketplace WordPress plugin contains an authentication bypass flaw in its email-verification flow, allowing unauthenticated us...

2026-08-11
CVE-2026-14553
Analyzed
8.1
HP zportals

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the ori...

2026-08-09
CVE-2026-14551
Analyzed
8.8
Unknown servereye Windows Agent (Sensorhub)

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20

2026-07-23
CVE-2026-14545
Analyzed
9.8
WordPress TrueBooker WordPress Plugin

The TrueBooker WordPress plugin fails to validate account ownership during password resets, allowing unauthenticated attackers to hijack any user acco...

2026-07-29
CVE-2026-14544
Analyzed
9.8
HP Red Hat Enterprise Linux 10

An integer overflow in the HPLIP hpcups processing path allows a remote attacker to escalate privileges or execute arbitrary code via specially crafte...

2026-07-03
CVE-2026-14541
Analyzed
8
Google mcp-toolbox

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1

2026-08-01
CVE-2026-14540
Analyzed
8
Google mcp-toolbox

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0

2026-08-01
CVE-2026-14537
Analyzed
8.1
Google mcp-toolbox

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1

2026-08-01
CVE-2026-14536
Analyzed
9.8
Devolutions Server

Devolutions Server 2026.2.4.0 through 2026.2.9.0 fails to enforce mandatory multi-factor authentication (MFA) policies when encountering invalid defau...

2026-07-11
CVE-2026-14535
Analyzed
8.8
Unknown fickling

In Trail of Bits fickling versions up to and including 0

2026-07-05
CVE-2026-14534
Analyzed
8.8
Unknown fickling

Trail of Bits fickling versions up to and including 0

2026-07-05
CVE-2026-1453
Analyzed
9.8
Unknown Multiple Products

A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete ad...

2026-01-30
CVE-2026-14529
Analyzed
9.4
IBM WebSphere Application Server

IBM WebSphere Application Server is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled, poten...

2026-07-30
CVE-2026-14526
Analyzed
9.8
WordPress AI Copilot – Content Generator

An authorization bypass in the AI Copilot WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site tak...

2026-08-08
CVE-2026-14524
Analyzed
9.1
WordPress ProSolution WP Client

The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, potentially leading to remote...

2026-08-16
CVE-2026-14522
Analyzed
8.8
IBM App Connect Enterprise

IBM App Connect Enterprise 13

2026-07-31
CVE-2026-14512
Analyzed
9.8
IBM WebSphere Application Server

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to pre-authentication unsafe deserialization, enabling remote attackers to bypas...

2026-07-29
CVE-2026-14499
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-07-18
CVE-2026-14498
Analyzed
8.8
WordPress Query Wrangler

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1

2026-08-16
CVE-2026-14495
Analyzed
8.8
WordPress DoLogin Security

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4

2026-07-08
CVE-2026-14490
Analyzed
7.5
WordPress Demi – One Click Demo Import, Backup & Site Migration

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to,...

2026-07-28
CVE-2026-1449
7.3
Unknown Multiple Products

A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113

2026-01-27
CVE-2026-14489
Analyzed
8.8
WordPress WHMCS Bridge

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ver...

2026-07-08
CVE-2026-14487
Analyzed
9.1
WordPress Simple Coherent Form

The Simple Coherent Form WordPress plugin contains a path traversal vulnerability allowing unauthenticated remote file deletion and potential code exe...

2026-07-08
CVE-2026-14484
Analyzed
9.1
WordPress RapiSafe – Secure Multi File Upload for Contact Form 7

The RapiSafe WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, which may lead to remote code execution.

2026-08-16
CVE-2026-14483
Analyzed
9.8
WordPress Realtyna Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin + WPL Real Estate for WordPress is vulnerable to unauthenticated arbitrary file uploads due to missing validation and...

2026-07-31
CVE-2026-14482
Analyzed
8.8
WordPress 多说社会化评论框 (Duoshuo Social Comment Box)

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-07-08
CVE-2026-14480
Analyzed
9.9
OpenPLC OpenPLC

An authenticated arbitrary file write vulnerability in the OpenPLC Runtime v3 web UI allows attackers to achieve native code execution by uploading ma...

2026-07-11
CVE-2026-1448
7.2
D-Link Multiple Products

A vulnerability was detected in D-Link DIR-615 up to 4

2026-01-27
CVE-2026-14476
Analyzed
8
Red Hat Red Hat Enterprise Linux (SSSD)

A path traversal flaw was found in SSSD's AD GPO provider

2026-07-08
CVE-2026-14474
Analyzed
8.8
Red Hat Red Hat Enterprise Linux (RHEL) / OpenShift

A flaw was found in SSSD's LDAP sudo provider

2026-07-08