21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 11401-11450 of 21553 CVEs Page 229 of 432
CVE-2026-13019
Analyzed
9.8
Esri Portal for ArcGIS

Esri Portal for ArcGIS versions 12.1 and earlier contain a missing authentication vulnerability allowing remote, unauthenticated attackers to access a...

2026-07-08
CVE-2026-13014
Analyzed
9.2
Thales CERT Suspicious

Thales CERT "Suspicious" versions 1.2.0-1.3.4 contain a path traversal and code injection vulnerability ("Matryoshka Mail") allowing unauthenticated r...

2026-07-14
CVE-2026-13001
Analyzed
9.8
WordPress Podlove Podcast Publisher

The Podlove Podcast Publisher plugin for WordPress contains an arbitrary file upload vulnerability allowing unauthenticated attackers to achieve remot...

2026-07-15
CVE-2026-12991
Analyzed
8.7
Ghost Robotics Vision 60

The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5

2026-07-28
CVE-2026-12990
Analyzed
7.7
Ghost Robotics Vision 60

An access control vulnerability in the mobile app (APK v5

2026-07-28
CVE-2026-12989
Analyzed
8.7
Ghost Robotics Vision 60

A lack of authentication in the mobile app (APK v5

2026-07-28
CVE-2026-12987
Analyzed
7.5
HP Events Manager WordPress Plugin

The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a book...

2026-07-29
CVE-2026-12984
Analyzed
8.2
Zyxel WAH7601

Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data

2026-08-11
CVE-2026-12981
7.5
WordPress CAFEHAUS API

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticat...

2026-08-05
CVE-2026-12978
Analyzed
7.1
WordPress FunnelKit

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its pa...

2026-07-20
CVE-2026-12975
Analyzed
8.5
Red Hat Apicurio Registry

A flaw was found in Apicurio Registry

2026-06-26
CVE-2026-12970
Analyzed
7.1
WordPress LearnPress

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cro...

2026-07-23
CVE-2026-12968
Analyzed
8.8
WordPress Product Addons and Product Options With Custom Fields

The Product Addons and Product Options With Custom Fields WordPress plugin before 1

2026-07-23
CVE-2026-12965
Analyzed
9.1
WordPress WordPress plugin

The Super Store Finder WordPress plugin contains a SQL injection vulnerability in an unauthenticated AJAX action, allowing remote attackers to extract...

2026-08-11
CVE-2026-12958
Analyzed
7.8
AWS Language Servers for AWS

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary

2026-06-24
CVE-2026-12957
Analyzed
7.8
Intel Language Servers for AWS

Improper trust boundary enforcement in Language Servers for AWS before version 1

2026-06-24
CVE-2026-12949
Analyzed
9.8
WordPress Wishlist Member

The Wishlist Member plugin for WordPress is vulnerable to unauthenticated account takeover due to improper validation of registration data, allowing a...

2026-08-14
CVE-2026-12946
Analyzed
9.9
IBM Langflow OSS

IBM Langflow OSS is vulnerable to code injection, allowing an authenticated remote attacker to execute arbitrary code due to improper control of user-...

2026-07-31
CVE-2026-12943
Analyzed
9.8
IBM HMC (Hardware Management Console)

IBM HMC management systems are vulnerable to OS command injection, allowing unauthenticated remote attackers to execute arbitrary commands with elevat...

2026-07-31
CVE-2026-12940
Analyzed
9.8
IBM Langflow OSS

IBM Langflow OSS is susceptible to unauthenticated remote code execution due to an incomplete blocklist of dangerous environment variables in the MCP...

2026-07-31
CVE-2026-1294
7.2
WordPress is vulnerable

The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1

2026-02-06
CVE-2026-12935
Analyzed
8.7
TP-Link TL-WR940N v6

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow

2026-07-30
CVE-2026-12927
Analyzed
8.4
Schneider Electric IGSS Definition (Def.exe)

CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file...

2026-07-30
CVE-2026-12923
Analyzed
7.5
WordPress Youtube Showcase

The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4

2026-07-01
CVE-2026-12921
Analyzed
8.4
AzeoTech DAQFactory

In AzeoTech DAQFactory versions 21

2026-06-26
CVE-2026-12912
Analyzed
7.3
Red Hat Red Hat Enterprise Linux 10

A flaw was found in libtiff

2026-06-30
CVE-2026-12897
Analyzed
8.4
Horner Automation Cscape

Horner Automation Cscape versions prior to 10

2026-06-26
CVE-2026-12877
9.1
WordPress Project Management, Bug and Issue Tracking Plugin

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it...

2026-08-03
CVE-2026-12872
Analyzed
9.8
WordPress WordPress plugin

The Webinfos WordPress plugin fails to validate uploaded files or restrict access, allowing unauthenticated attackers to upload arbitrary files and ac...

2026-08-11
CVE-2026-12866
Analyzed
9.8
Unknown expr-eval

The expr-eval package is vulnerable to arbitrary code execution via the toJSFunction() API due to insufficient sandboxing of user-supplied expressions...

2026-06-23
CVE-2026-12860
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-12856
Analyzed
8.8
Red Hat OpenShift Dev Spaces

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code

2026-06-30
CVE-2026-12852
Analyzed
8.7
Unknown BC-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-12851
Analyzed
9.1
GeoVision GV-I/O Box 4E

An unauthenticated OS command injection vulnerability in the libNetSetObj.so library of GeoVision GV-I/O Box 4E allows remote code execution via a cra...

2026-06-24
CVE-2026-12850
Analyzed
9.1
GeoVision GV-I/O Box 4E

An unauthenticated OS command injection vulnerability in the libNetSetObj.so library of GeoVision GV-I/O Box 4E allows remote code execution via a cra...

2026-06-24
CVE-2026-1285
Analyzed
7.5
Unknown Multiple Products

An issue was discovered in 6

2026-02-04
CVE-2026-12849
Analyzed
9.1
GeoVision GV-I/O Box 4E

An unauthenticated OS command injection vulnerability in the libNetSetObj.so library of GeoVision GV-I/O Box 4E allows remote code execution via a cra...

2026-06-24
CVE-2026-12848
Analyzed
10
GeoVision GV-I/O Box 4E

The GeoVision GV-I/O Box 4E contains a stack-based buffer overflow vulnerability in the DVRSearch service, allowing remote code execution via crafted...

2026-06-24
CVE-2026-12847
Analyzed
10
GeoVision GV-I/O Box 4E

A stack-based buffer overflow vulnerability in the GeoVision GV-I/O Box 4E DVRSearch service allows unauthenticated remote attackers to execute arbitr...

2026-06-24
CVE-2026-12846
Analyzed
10
GeoVision GV-I/O Box 4E

A stack-based buffer overflow in the DVRSearch service allows unauthenticated remote attackers to execute arbitrary code via crafted UDP packets.

2026-06-24
CVE-2026-1284
7.8
Release Multiple Products

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SO...

2026-01-27
CVE-2026-1283
Analyzed
7.8
Intel Multiple Products

A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Rele...

2026-01-27
CVE-2026-12819
Analyzed
9.3
Delta Electronics DVP-12SE PLC

The Delta Electronics DVP-12SE Modbus TCP service lacks authentication, allowing unauthenticated attackers to interact with security-sensitive functio...

2026-06-30
CVE-2026-12818
Analyzed
9.3
Delta Electronics DVP-12SE PLC

A resource allocation vulnerability in the Delta Electronics DVP-12SE PLC Modbus TCP service allows for potential denial-of-service conditions.

2026-06-30
CVE-2026-12817
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-12816
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-1281
KEV
9.8
Unknown Multiple Products

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

2026-01-30
CVE-2026-12806
Analyzed
8.8
Edimax BR-6478AC V2

A vulnerability has been found in Edimax BR-6478AC V2 1

2026-06-22
CVE-2026-12803
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-12802
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03