21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 11351-11400 of 21553 CVEs Page 228 of 432
CVE-2026-1320
7.2
WordPress is vulnerable

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTT...

2026-02-14
CVE-2026-13197
Analyzed
7.3
KUNBUS piControl

Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability i...

2026-08-16
CVE-2026-13196
Analyzed
7.3
KUNBUS piControl

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in vers...

2026-08-16
CVE-2026-13190
Analyzed
8.1
Progress Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13187
Analyzed
8.1
Progress Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13186
Analyzed
8.1
Progress Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13185
Analyzed
8.1
Progress Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13181
Analyzed
8.1
Progress Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13170
Analyzed
7.2
HP WordPress Plugin

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users...

2026-08-17
CVE-2026-13165
Analyzed
8.6
Krajowa SzafirHost

SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with J...

2026-06-30
CVE-2026-13164
Analyzed
8.8
Mailerup Mailerup

Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views

2026-06-25
CVE-2026-1316
7.2
WordPress is vulnerable

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[]

2026-02-14
CVE-2026-13158
Analyzed
7.2
WordPress Everest Toolkit (WordPress Plugin)

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type te...

2026-08-09
CVE-2026-13157
Analyzed
7.2
WordPress Theme Demo Import (WordPress Plugin)

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test...

2026-08-09
CVE-2026-13152
Analyzed
8.1
WordPress Custom Fields Account Registration For Woocommerce

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1

2026-07-28
CVE-2026-13149
Analyzed
7.7
Julian Gruber brace-expansion

brace-expansion through 5

2026-07-01
CVE-2026-13147
Analyzed
9.1
WordPress Kirki

The Kirki WordPress plugin fails to validate user-supplied URLs, enabling unauthenticated attackers to perform Server-Side Request Forgery (SSRF) and...

2026-07-23
CVE-2026-13142
Analyzed
8.1
WordPress Social Login, Passkeys, Magic Link & Email OTP

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its p...

2026-07-23
CVE-2026-13133
Analyzed
8.4
LY Corporation LINE for Windows

A vulnerability has been identified in LineInst

2026-08-10
CVE-2026-13132
Analyzed
8.3
GeoVision GeoWebPlayer

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVi...

2026-07-02
CVE-2026-13131
Analyzed
8.3
GeoVision GeoWebPlayer

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVi...

2026-07-02
CVE-2026-1313
8.3
WordPress is vulnerable

The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3

2026-03-21
CVE-2026-13129
Analyzed
7.8
Foxit Foxit PDF Editor / PDF Reader

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid...

2026-07-08
CVE-2026-13128
Analyzed
7.8
Foxit Foxit PDF Editor

Embedding JavaScript within a PDF file will cause the page to be deleted

2026-07-08
CVE-2026-13127
Analyzed
7.8
Foxit Foxit PDF Editor / Foxit PDF Reader

The application opens the PDF file

2026-07-08
CVE-2026-13126
Analyzed
7.8
Foxit Foxit PDF Editor

The embedded JavaScript in the PDF deleted the pages, making the object invalid

2026-07-08
CVE-2026-13125
Analyzed
8.8
GeoVision GeoWebPlayer

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVi...

2026-07-02
CVE-2026-13114
Analyzed
7.2
WordPress Motors – Car Dealership & Classified Listings Plugin

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and Use...

2026-07-12
CVE-2026-1311
8.8
WordPress is vulnerable

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0

2026-02-26
CVE-2026-13105
Analyzed
8.8
IBM i Access Client Solutions

IBM i Access Client Solutions 1

2026-08-13
CVE-2026-13089
Analyzed
7.5
RITOU OIDC::Lite

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When t...

2026-08-01
CVE-2026-13084
Analyzed
8.7
WatchGuard Fireware OS

A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) con...

2026-07-03
CVE-2026-13078
Analyzed
7.7
MongoDB MongoDB Server

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that en...

2026-07-24
CVE-2026-13072
Analyzed
8.1
MongoDB MongoDB Server

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline proc...

2026-07-24
CVE-2026-1306
Analyzed
9.8
WordPress is vulnerable

The midi-Synth WordPress plugin allows unauthenticated arbitrary file uploads via the 'export' AJAX action, potentially leading to remote code executi...

2026-02-14
CVE-2026-13059
Analyzed
8.1
MongoDB MongoDB Server

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access cont...

2026-07-24
CVE-2026-13054
Analyzed
8.6
WatchGuard Fireware OS

A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on...

2026-07-03
CVE-2026-13053
Analyzed
8.6
WatchGuard Fireware OS

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a spec...

2026-07-03
CVE-2026-13050
Analyzed
8.6
WatchGuard Fireware OS

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code...

2026-07-03
CVE-2026-13038
Analyzed
8.8
Microsoft Chrome

Use after free in Autofill in Google Chrome on Windows prior to 149

2026-06-25
CVE-2026-13036
Analyzed
8.8
Google Chrome

Use after free in Blink in Google Chrome prior to 149

2026-06-25
CVE-2026-13035
Analyzed
8.8
Google Chrome

Use after free in Bluetooth in Google Chrome on Mac prior to 149

2026-06-25
CVE-2026-13033
Analyzed
8.8
Google Chrome

Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149

2026-06-25
CVE-2026-13032
Analyzed
9.6
Google Chrome

A critical use-after-free vulnerability in Google Chrome's WebGL component on Android allows remote attackers to perform a sandbox escape via crafted...

2026-06-25
CVE-2026-13031
Analyzed
8.8
Google Chrome

Use after free in Blink in Google Chrome prior to 149

2026-06-25
CVE-2026-13028
Analyzed
9.6
Google Chrome

A use-after-free vulnerability in the WebGL component of Google Chrome on Android allows remote attackers to execute a sandbox escape via a malicious...

2026-06-25
CVE-2026-13027
Analyzed
8.8
Google Chrome

Use after free in FileSystem in Google Chrome prior to 149

2026-06-25
CVE-2026-13026
Analyzed
8.8
Google Chrome

Use after free in Digital Credentials in Google Chrome on Mac prior to 149

2026-06-25
CVE-2026-13025
Analyzed
8.3
Google Chrome

Race in DevTools in Google Chrome prior to 149

2026-06-25
CVE-2026-13020
Analyzed
8.1
Esri Portal for ArcGIS

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12

2026-07-08