21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1101-1150 of 21637 CVEs Page 23 of 433
CVE-2026-71961
Analyzed
8.8
Cudy WR3000 2.0

Cudy WR3000 2

2026-08-20
CVE-2026-71958
Analyzed
9.8
D-Link DWR-M961

D-Link DWR-M961 routers contain a buffer overflow vulnerability in the quicksetup.cgi interface, allowing unauthenticated attackers to execute arbitra...

2026-08-09
CVE-2026-71957
Analyzed
9.8
D-Link DWR-M961

D-Link DWR-M961 routers are susceptible to a buffer overflow in the app.cgi interface, which allows unauthenticated remote attackers to execute arbitr...

2026-08-09
CVE-2026-71956
Analyzed
9.8
D-Link DWR-M961

D-Link DWR-M961 routers contain a command injection vulnerability in the app.cgi interface, allowing unauthenticated remote attackers to execute arbit...

2026-08-09
CVE-2026-71955
Analyzed
9.8
D-Link DWR-M961

D-Link DWR-M961 routers are vulnerable to command injection in the /boafrm/formWsc interface, enabling unauthenticated remote attackers to execute arb...

2026-08-09
CVE-2026-71954
Analyzed
9.8
D-Link DWR-M961

D-Link DWR-M961 routers contain a command injection vulnerability in the L2TPv3 configuration interface allowing unauthenticated remote attackers to e...

2026-08-09
CVE-2026-71953
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formNtp interface allows unauthenticated remote attackers to execute arbitrary comman...

2026-08-09
CVE-2026-71952
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formPinManageSetup interface allows unauthenticated remote attackers to execute arbit...

2026-08-09
CVE-2026-71951
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formIMEISetup interface allows unauthenticated remote attackers to execute arbitrary...

2026-08-09
CVE-2026-71950
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formSmsManage interface allows remote unauthenticated attackers to execute arbitrary...

2026-08-09
CVE-2026-7195
Analyzed
8.8
Progress Sitefinity

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14

2026-06-03
CVE-2026-71949
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formUSSDSetup interface allows remote unauthenticated attackers to execute arbitrary...

2026-08-09
CVE-2026-71948
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formDebugDiagnosticRun interface allows remote unauthenticated attackers to execute a...

2026-08-09
CVE-2026-71947
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privil...

2026-08-09
CVE-2026-71946
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privil...

2026-08-09
CVE-2026-71945
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privil...

2026-08-09
CVE-2026-71944
Analyzed
9.8
D-Link DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formLtefotaUpgradeQuectel interface allows unauthenticated remote attackers to execut...

2026-08-09
CVE-2026-7194
7.3
HP Multiple Products

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-7189
Analyzed
7.5
Proliz Software Proliz's OBS

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd

2026-07-19
CVE-2026-7187
Analyzed
8.8
Universal Software UKBS

Missing authentication for critical function vulnerability in Universal Software Inc

2026-07-29
CVE-2026-71847
Analyzed
8.7
Ruby JSON

Ruby JSON is a JSON implementation for Ruby

2026-08-08
CVE-2026-7178
7.3
Infor Multiple Products

A weakness has been identified in ChatGPTNextWeb NextChat up to 2

2026-04-28
CVE-2026-7177
7.3
Infor Multiple Products

A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2

2026-04-28
CVE-2026-7166
Analyzed
9.2
Gaudire Assassin game

The Gaudire Assassin game API and local database improperly protect sensitive information, leading to the unauthorized exposure of email addresses, ph...

2026-06-23
CVE-2026-7165
Analyzed
9.4
Gaudire Assassin game

The Gaudire Assassin game contains multiple vulnerabilities in the ‘/addJugador’ endpoint, including insecure parameter handling, improper input valid...

2026-06-23
CVE-2026-7164
7.5
Unknown Multiple Products

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters

2026-05-01
CVE-2026-7162
Analyzed
7.8
WinFsp WinFsp

Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software

2026-07-13
CVE-2026-7161
Analyzed
9.3
LG GV-IP Device Utility

An insufficient encryption vulnerability in the GeoVision GV-IP Device Utility allows attackers on the same LAN to decrypt administrative credentials...

2026-05-04
CVE-2026-7160
8.8
Tenda Multiple Products

A vulnerability was determined in Tenda HG3 2

2026-04-28
CVE-2026-7159
7.3
Unknown Multiple Products

A vulnerability was found in douinc mkdocs-mcp-plugin up to 0

2026-04-28
CVE-2026-7158
7.3
Infor Multiple Products

A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6

2026-04-28
CVE-2026-71571
Analyzed
8.6
Joomla iCagenda extension for Joomla

Joomla Extension - icagenda

2026-08-15
CVE-2026-7157
7.3
Infor Multiple Products

A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc

2026-04-28
CVE-2026-71567
Analyzed
7.7
Unknown fakefish

In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into c...

2026-08-18
CVE-2026-71566
Analyzed
9.3
Kubernetes fakefish

The fakefish component in openshift-metal3 fails to perform credential validation when used with KubeVirt, allowing unauthorized cluster users to cont...

2026-08-18
CVE-2026-7156
Analyzed
9.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the comp...

2026-04-28
CVE-2026-71558
Analyzed
9.8
Apache Apache Fory

A heap type confusion vulnerability in Apache Fory C++ allows remote attackers to trigger denial of service or arbitrary code execution via crafted pa...

2026-08-08
CVE-2026-71556
Analyzed
7.1
Unknown go-git

go-git is an extensible git implementation library written in pure Go

2026-08-09
CVE-2026-7155
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary system commands...

2026-04-28
CVE-2026-7154
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary system commands...

2026-04-28
CVE-2026-71539
Analyzed
8.9
Unknown n8n

n8n is an open source workflow automation platform

2026-08-19
CVE-2026-7153
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary system commands...

2026-04-28
CVE-2026-7152
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability in the Totolink A8000RU CGI handler allows unauthenticated remote attackers to execute arbitrary commands by man...

2026-04-28
CVE-2026-71518
Analyzed
7.5
GitHub Typemill

Typemill before 2

2026-08-18
CVE-2026-7151
8.8
Tenda HG3

A vulnerability was determined in Tenda HG3 2

2026-04-28
CVE-2026-71491
Analyzed
8.7
Unknown sqlparse

sqlparse is a non-validating SQL parser module for Python

2026-08-18
CVE-2026-7149
7.3
Infor Multiple Products

A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d

2026-04-28
CVE-2026-71479
Analyzed
9.1
QuantumNous new-api

An integer overflow vulnerability in QuantumNous new-api allows unauthenticated attackers to manipulate billing calculations and gain unauthorized acc...

2026-08-18
CVE-2026-71476
Analyzed
8.7
Unknown nx

Nx is a monorepo solution for TypeScript and polyglot codebases

2026-08-07
CVE-2026-71472
Analyzed
9.1
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2

An input validation flaw in the acm-search-v2-rhel9 component allows authenticated attackers to perform OS command or SQL injection, potentially leadi...

2026-08-18