21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 11501-11550 of 21553 CVEs Page 231 of 432
CVE-2026-12535
Analyzed
9.8
Drupal Formatter Field

The Drupal Formatter Field module contains an object injection vulnerability due to improper control of dynamically determined object attributes.

2026-07-15
CVE-2026-12525
Analyzed
8.8
WordPress Redux Framework

The Redux Framework WordPress plugin before 4

2026-07-17
CVE-2026-12522
Analyzed
8.8
Zephyr Project Zephyr

The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800

2026-08-20
CVE-2026-12512
Analyzed
8.6
WordPress Quotes llama

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowin...

2026-07-19
CVE-2026-12511
Analyzed
8.1
WordPress AI Engine

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authentic...

2026-07-16
CVE-2026-12504
Analyzed
8.4
Loytec LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8

2026-07-25
CVE-2026-12503
Analyzed
9.2
Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC

A symlink attack in the `/usr/bin/larm_starter` utility of various Loytec devices allows authenticated attackers to escalate privileges to root.

2026-07-25
CVE-2026-12502
Analyzed
8.4
Loytec LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8

2026-07-25
CVE-2026-12497
7.5
WordPress Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not c...

2026-08-05
CVE-2026-12496
Analyzed
8.7
Loytec LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI

Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD th...

2026-07-25
CVE-2026-12493
Analyzed
7.5
WordPress Clover Payment Gateway for WooCommerce

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1

2026-07-28
CVE-2026-12492
Analyzed
9.8
Happy Coders OTP Login for WooCommerce

The Happy Coders OTP Login for WooCommerce plugin fails to validate one-time passwords during the authentication process, allowing unauthorized accoun...

2026-07-17
CVE-2026-12490
Analyzed
8.2
NLnet NSD

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name

2026-06-25
CVE-2026-12486
Analyzed
9.1
GeoVision GV-I/O Box 4E

Multiple OS command injection vulnerabilities in the GeoVision GV-I/O Box 4E allow remote attackers to execute arbitrary commands via crafted network...

2026-06-24
CVE-2026-12485
Analyzed
10
GeoVision GV-I/O Box 4E

The GeoVision GV-I/O Box 4E contains a stack-based buffer overflow in the DVRSearch service, allowing unauthenticated attackers to trigger remote code...

2026-06-24
CVE-2026-12484
Analyzed
7.8
Keras Keras

A vulnerability in keras-team/keras version 3

2026-07-20
CVE-2026-12481
Analyzed
8.8
Keras Team Keras

A vulnerability in keras-team/keras version 3

2026-07-04
CVE-2026-12473
Analyzed
8.2
Open DICOM Web Viewer Framework

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation

2026-06-26
CVE-2026-12468
Analyzed
8.3
Google Chrome

Race in Updater in Google Chrome on Mac prior to 149

2026-06-20
CVE-2026-12466
Analyzed
8.8
Microsoft Chrome

Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149

2026-06-18
CVE-2026-12454
Analyzed
8.3
Google Chrome

Race in Safe Browsing in Google Chrome on Mac prior to 149

2026-06-20
CVE-2026-12452
Analyzed
8.8
Google Chrome

Use after free in Downloads in Google Chrome on Android prior to 149

2026-06-18
CVE-2026-12448
Analyzed
8.8
Google Chrome (Android WebView)

Inappropriate implementation in WebView in Google Chrome on Android prior to 149

2026-06-18
CVE-2026-12447
Analyzed
8.8
Google Chrome

Heap buffer overflow in WebRTC in Google Chrome prior to 149

2026-06-18
CVE-2026-12443
Analyzed
8.8
Google Chrome

Use after free in Web Authentication in Google Chrome prior to 149

2026-06-18
CVE-2026-12442
Analyzed
8.8
Google Chrome

Use after free in Passwords in Google Chrome on Android prior to 149

2026-06-18
CVE-2026-12441
Analyzed
8.8
Google Chrome

Use after free in File Input in Google Chrome on Linux prior to 149

2026-06-18
CVE-2026-12439
Analyzed
8.8
Google Chrome

Use after free in Digital Credentials in Google Chrome prior to 149

2026-06-18
CVE-2026-12438
Analyzed
8.3
Google Chrome on Android

Inappropriate implementation in WebView in Google Chrome on Android prior to 149

2026-06-20
CVE-2026-12437
Analyzed
8.3
Microsoft Chrome

Use after free in WebShare in Google Chrome on Windows prior to 149

2026-06-20
CVE-2026-12436
Analyzed
8.4
GitLab GitLab CE/EE

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2026-07-30
CVE-2026-12417
Analyzed
9.8
WordPress SignUp & SignIn

The Pravel SignUp & SignIn WordPress plugin contains an authentication bypass vulnerability allowing unauthenticated attackers to reset any user passw...

2026-06-24
CVE-2026-12416
Analyzed
9.8
WordPress Invoice Generator

The Invoice Generator WordPress plugin contains an account takeover vulnerability via an insecure password reset function that allows unauthenticated...

2026-06-24
CVE-2026-12415
Analyzed
9.8
WordPress Invoice Generator

The Invoice Generator plugin for WordPress is vulnerable to unauthenticated privilege escalation, allowing attackers to modify arbitrary user accounts...

2026-06-27
CVE-2026-12411
Analyzed
8.4
Canonical LXD

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gue...

2026-06-27
CVE-2026-12407
Analyzed
8.8
WordPress Export Pdf Tool for WordPress

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1

2026-06-18
CVE-2026-12394
Analyzed
9.8
WordPress MemberGlut

The MemberGlut WordPress plugin fails to validate user roles during registration, allowing unauthenticated attackers to register as administrators and...

2026-07-28
CVE-2026-1239
Analyzed
7.5
WordPress Ninja Forms

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing auth...

2026-07-01
CVE-2026-12383
Analyzed
7.5
Red Hat Red Hat Ansible Automation Platform 2

A flaw was found in the Event-Driven Ansible (EDA) server

2026-08-15
CVE-2026-12382
Analyzed
8.2
Red Hat Red Hat Ansible Automation Platform

A flaw was found in the AAP Gateway Envoy proxy configuration

2026-07-17
CVE-2026-1238
7.2
WordPress is vulnerable

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, a...

2026-03-19
CVE-2026-12378
Analyzed
8.1
WordPress Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1

2026-07-09
CVE-2026-12375
Analyzed
9.8
WordPress Uncanny Automator Pro

The Uncanny Automator Pro WordPress plugin was distributed with a backdoor, allowing unauthenticated attackers to gain administrative access and exfil...

2026-07-08
CVE-2026-12366
Analyzed
8.8
Zephyr Project Zephyr

Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace

2026-08-15
CVE-2026-12364
Analyzed
8.4
Unknown zephyr

The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg

2026-08-16
CVE-2026-12341
Analyzed
8.8
SailPoint IdentityIQ

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to imp...

2026-07-21
CVE-2026-1233
Analyzed
7.5
WordPress is vulnerable

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and incl...

2026-04-05
CVE-2026-12291
Analyzed
8.8
Unknown Networking HTTP Component

Use-after-free in the Networking: HTTP component

2026-06-20
CVE-2026-12289
Analyzed
8.8
Mozilla Firefox/Thunderbird

Privilege escalation in the Graphics: WebRender component

2026-06-17
CVE-2026-12281
Analyzed
8.1
WordPress Shibboleth WordPress plugin

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating...

2026-07-18