23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 1101-1150 of 23295 CVEs Page 23 of 466
CVE-2026-78270
Analyzed
7.6
WordPress FluentCRM Pro

Author SQL Injection in FluentCRM Pro <= 3

2026-08-25
CVE-2026-78268
Analyzed
7.5
WordPress Lead Generation Contact Widget & AI Chatbot (SiteLeads)

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1

2026-08-25
CVE-2026-78267
Analyzed
9.8
WordPress TranslatePress

The TranslatePress WordPress plugin contains an unauthenticated privilege escalation vulnerability, allowing remote attackers to gain unauthorized adm...

2026-08-25
CVE-2026-78265
Analyzed
9.8
HP The Events Calendar

The Events Calendar plugin for WordPress is vulnerable to unauthenticated PHP object injection, allowing remote attackers to execute arbitrary code.

2026-08-25
CVE-2026-78262
Analyzed
9.8
HP WP Project Manager

The WP Project Manager plugin for WordPress contains an unauthenticated PHP object injection vulnerability that can lead to remote code execution.

2026-08-25
CVE-2026-78257
Analyzed
8.8
HP Booking and Rental Manager for WooCommerce

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

2026-08-28
CVE-2026-78255
Analyzed
8.7
DJI Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2

The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client

2026-08-24
CVE-2026-78251
Analyzed
9.3
DJI Neo

DJI drones contain an FTP service with hardcoded credentials that allows unauthorized file uploads and storage exhaustion, potentially disabling criti...

2026-08-24
CVE-2026-78239
Analyzed
9.8
Xiiaozet Xiiaozet LK100W

The Xiiaozet LK100W device contains an authentication bypass vulnerability, allowing unauthenticated remote attackers to enable restricted administrat...

2026-08-28
CVE-2026-78236
Analyzed
8.8
Apple Admin By Request (ABR)

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process C...

2026-08-26
CVE-2026-7823
Analyzed
9.8
TOTOLINK A8000RU

A remote OS command injection vulnerability in the Totolink A8000RU allows unauthenticated attackers to execute arbitrary commands via the `setAppFilt...

2026-05-05
CVE-2026-78213
Analyzed
8.7
Hepta Platforms Heptabase

Heptabase developed by Hepta Platforms, Inc

2026-08-24
CVE-2026-78212
Analyzed
7.5
Unknown 4MOSAn Management Center

4MOSAn developed by 4MOSAn Security Technology Co

2026-08-24
CVE-2026-78211
Analyzed
9.8
HP 4MOSAn GCB Doctor

An OS command injection vulnerability in 4MOSAn GCB Doctor allows unauthenticated remote attackers to execute arbitrary system commands via a test pag...

2026-08-24
CVE-2026-78209
Analyzed
8.2
Microsoft exceljs

exceljs-hardened versions before 5

2026-08-24
CVE-2026-78208
Analyzed
7.5
Unknown exceljs

exceljs-hardened before 5

2026-08-24
CVE-2026-78207
Analyzed
9.4
Unknown exceljs

A prototype pollution vulnerability in the exceljs deepMerge helper allows attackers to inject malicious keys into object prototypes via crafted cell...

2026-08-24
CVE-2026-78206
Analyzed
7.5
Unknown exceljs

exceljs-hardened before 5

2026-08-24
CVE-2026-78203
Analyzed
7.1
GhostManager Ghostwriter

Ghostwriter before 7

2026-08-24
CVE-2026-78202
Analyzed
7.3
Unknown Payroll System

A vulnerability was found in itsourcecode Payroll System 1

2026-08-24
CVE-2026-78201
Analyzed
7.3
Unknown Payroll System

A vulnerability has been found in itsourcecode Payroll System 1

2026-08-24
CVE-2026-78199
Analyzed
7.3
SourceCodester Simple Online Food Ordering System

A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1

2026-08-24
CVE-2026-78198
Analyzed
7.3
SourceCodester Simple Online Food Ordering System

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1

2026-08-24
CVE-2026-78197
Analyzed
7.3
SourceCodester Simple Online Food Ordering System

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1

2026-08-24
CVE-2026-7819
Analyzed
8.1
File Multiple Products

Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager

2026-05-12
CVE-2026-78182
Analyzed
7.3
Unknown XBROTHER Dynamic Environment Monitoring System

A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300

2026-08-24
CVE-2026-78181
Analyzed
7.3
Unknown ractive

A weakness has been identified in ractivejs ractive up to 1

2026-08-24
CVE-2026-78180
Analyzed
7.3
Alibaba Fusion Next

A security flaw has been discovered in alibaba-fusion next up to 1

2026-08-24
CVE-2026-7818
Analyzed
7
Unknown Multiple Products

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager

2026-05-12
CVE-2026-78178
Analyzed
7.3
Unknown jQWidgets

A vulnerability was determined in jQWidgets up to 24

2026-08-24
CVE-2026-78171
Analyzed
7.3
Unknown Sales and Inventory System

A vulnerability has been found in itsourcecode Sales and Inventory System 1

2026-08-24
CVE-2026-78170
Analyzed
8.8
UTT HiPER 1200GW

A flaw has been found in UTT HiPER 1200GW up to 2

2026-08-24
CVE-2026-78169
Analyzed
9.9
UTT HiPER 1250GW

A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW HTTP request handler, allowing remote attackers to achieve arbitrary code e...

2026-08-24
CVE-2026-78168
Analyzed
9.8
EFM ipTIME T24000M

A session validation vulnerability in EFM ipTIME T24000M allows remote, unauthenticated attackers to bypass authentication controls via the httpcon_ch...

2026-08-24
CVE-2026-78167
Analyzed
10
EFM ipTIME T16000M

An improper authentication vulnerability in the EFM ipTIME T16000M session validation handler allows remote attackers to bypass security controls and...

2026-08-24
CVE-2026-78161
Analyzed
7.3
GitHub libwebsockets

A vulnerability was found in warmcat libwebsockets 4

2026-08-24
CVE-2026-7816
Analyzed
8.8
Unknown Multiple Products

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export

2026-05-12
CVE-2026-78157
Analyzed
7.4
Open5GS Open5GS

A vulnerability was detected in Open5GS 2

2026-08-24
CVE-2026-78156
Analyzed
7.4
GitHub Open5GS

A security vulnerability has been detected in Open5GS 2

2026-08-24
CVE-2026-78155
Analyzed
9.9
OnGres StackGres

The StackGres operator is vulnerable to privilege escalation, allowing a low-privilege tenant who owns a database to gain administrator privileges.

2026-08-24
CVE-2026-78154
Analyzed
7.3
GitHub open-wearables

A vulnerability was identified in the-momentum open-wearables up to 0

2026-08-24
CVE-2026-7815
Analyzed
8.8
Unknown server

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

2026-05-12
CVE-2026-78147
Analyzed
7.3
Unknown llama.cpp

A vulnerability was found in ggml-org llama

2026-08-24
CVE-2026-78143
Analyzed
7.3
HP Barangay Resident Profiling Management System

A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1

2026-08-24
CVE-2026-78141
Analyzed
7.4
Tenda CH22

A vulnerability has been found in Tenda CH22 1

2026-08-24
CVE-2026-78137
Analyzed
7.5
WordPress StoreGrowth (WordPress Plugin)

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unau...

2026-09-02
CVE-2026-78136
Analyzed
7.8
Unknown CHIRP

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data

2026-08-23
CVE-2026-7813
Analyzed
9.9
Unknown pgAdmin 4

An authorization flaw in pgAdmin 4 allows authenticated users to access private server data and execute arbitrary commands by manipulating object IDs...

2026-05-12
CVE-2026-78122
Analyzed
7.4
Docker docker-socket-proxy

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set

2026-08-23
CVE-2026-7812
Analyzed
7.3
Unknown Multiple Products

A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8

2026-05-05