21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 11551-11600 of 21553 CVEs Page 232 of 432
CVE-2026-12277
Analyzed
8.7
WordPress Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23

2026-07-08
CVE-2026-12275
Analyzed
7.1
WordPress Tutor LMS

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private...

2026-07-16
CVE-2026-12263
Analyzed
8.8
Zohocorp ManageEngine Password Manager Pro / PAM360

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerabil...

2026-08-14
CVE-2026-12257
Analyzed
9.3
Mura Software CMS

Mura Software CMS contains a critical remote code execution vulnerability via the “method” parameter in the “/index.cfm/_api/json/v1/default” endpoint...

2026-07-14
CVE-2026-12256
Analyzed
8.8
HP Avada

Contributor PHP Object Injection in Avada <= 3

2026-06-18
CVE-2026-12255
Analyzed
8.1
WordPress MainWP Child

The MainWP Child WordPress plugin before 6

2026-07-28
CVE-2026-12252
Analyzed
7.8
NLTK NLTK (Natural Language Toolkit)

In nltk/nltk versions 3

2026-07-04
CVE-2026-12251
Analyzed
8.1
WordPress Ultimate Member

The Ultimate Member WordPress plugin before 2

2026-08-01
CVE-2026-12250
Analyzed
7.9
TUBITAK BILGEM Pardus Domain Joiner

Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joine...

2026-07-06
CVE-2026-12249
Analyzed
8.3
Ubuntu ADSys

An issue was discovered in Canonical ADSys upstream versions through v0

2026-06-23
CVE-2026-12245
Analyzed
8.7
NLnet Labs NSD (Name Server Daemon)

NSD from version 4

2026-06-25
CVE-2026-12244
Analyzed
8.7
NLnet Labs NSD (Name Server Daemon)

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB...

2026-06-25
CVE-2026-12243
Analyzed
7.5
NLTK Project NLTK

NLTK version 3

2026-06-30
CVE-2026-12242
Analyzed
8.8
HP AdRotate Banner Manager

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5

2026-06-25
CVE-2026-12240
Analyzed
8
WordPress Export User Data Plugin

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize functio...

2026-06-30
CVE-2026-12228
Analyzed
8.7
Unknown lollms

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version)

2026-07-19
CVE-2026-12224
Analyzed
8.8
WordPress Dokan Pro

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5

2026-07-01
CVE-2026-12222
Analyzed
8
Yealink SIP-T46U

A vulnerability was determined in Yealink SIP-T46U 108

2026-06-15
CVE-2026-12221
Analyzed
8
Yealink SIP-T46U

A vulnerability was found in Yealink SIP-T46U 108

2026-06-15
CVE-2026-12220
Analyzed
8
Yealink SIP-T46U

A vulnerability has been found in Yealink SIP-T46U 108

2026-06-15
CVE-2026-1222
Analyzed
7.2
HP Multiple Products

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to uplo...

2026-01-20
CVE-2026-12218
Analyzed
8
Yealink SIP-T46U

A vulnerability was detected in Yealink SIP-T46U 108

2026-06-15
CVE-2026-12217
Analyzed
7.8
DVDFab Virtual Drive

A security vulnerability has been detected in DVDFab Virtual Drive 2

2026-06-15
CVE-2026-12214
Analyzed
7.8
Qihoo 360 Total Security

A security flaw has been discovered in Qihoo 360 Total Security 6

2026-06-15
CVE-2026-1221
Analyzed
9.8
PrismX Multiple Products

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote atta...

2026-01-20
CVE-2026-12204
Analyzed
7.3
HP ShopXO

A vulnerability was determined in ShopXO up to 6

2026-06-15
CVE-2026-12200
Analyzed
7.3
Ritlabs TinyWeb Server

A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1

2026-06-15
CVE-2026-12198
Analyzed
7.3
Microweber Microweber CMS

A weakness has been identified in Microweber up to 2

2026-06-15
CVE-2026-12197
Analyzed
7.2
Ruijie EG105G-P

A security flaw has been discovered in Ruijie EG105G-P 2

2026-06-15
CVE-2026-12196
Analyzed
8.3
HestiaCP HestiaCP

HestiaCP panel cronjob feature is affected by a broken access control vulnerability

2026-07-05
CVE-2026-12195
Analyzed
8.5
Unknown vesta

myVesta is affected by an authenticated remote code execution vulnerability

2026-07-05
CVE-2026-12193
Analyzed
7.8
VS Revo Group Revo Uninstaller

A vulnerability was identified in VS Revo RevoUninstaller 2

2026-06-15
CVE-2026-12192
Analyzed
8.8
GALAYOU Y4

A vulnerability was determined in GALAYOU Y4 1

2026-06-15
CVE-2026-12191
Analyzed
7.8
Comma AI Openpilot

A vulnerability was found in Comma AI Openpilot 0

2026-06-15
CVE-2026-12187
Analyzed
8.8
GL Unknown

A security vulnerability has been detected in GL

2026-06-15
CVE-2026-12186
Analyzed
8.8
GL Unknown

A weakness has been identified in GL

2026-06-15
CVE-2026-12185
Analyzed
7.1
Unknown BC-JAVA, BC-LTS-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-12183
Analyzed
9.8
HP BUK TS-G Gas Station Automation System

The BUK TS-G automation system contains an authentication bypass vulnerability that allows remote, unauthenticated attackers to execute arbitrary admi...

2026-06-14
CVE-2026-12174
Analyzed
8.8
D-Link DCS-935L

A security vulnerability has been detected in D-Link DCS-935L 1

2026-06-14
CVE-2026-12168
Analyzed
7.8
Little GameFirst Anti-Cheat

An improper validation vulnerability for driver `GFAC_Sys_x64

2026-07-03
CVE-2026-12167
Analyzed
7.8
Little (GameFirst) GameFirst Anti-Cheat

The Minifilter communication port for driver `GFAC_Sys_x64

2026-07-03
CVE-2026-12165
Analyzed
8.8
WordPress Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all version...

2026-06-18
CVE-2026-12161
Analyzed
8.8
Devolutions Remote Desktop Manager

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026

2026-06-17
CVE-2026-1216
7.2
WordPress is vulnerable

The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and includ...

2026-02-18
CVE-2026-12158
Analyzed
8.8
WordPress RegistrationMagic – User Registration Forms Plugin

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...

2026-07-01
CVE-2026-12153
Analyzed
9.8
WordPress WP Learn Manager

The WP Learn Manager plugin for WordPress contains an authorization bypass vulnerability that allows unauthenticated attackers to install and activate...

2026-07-08
CVE-2026-12144
Analyzed
8.8
WordPress Wholesale for WooCommerce

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2

2026-07-29
CVE-2026-12118
Analyzed
9.8
IBM webMethods Integration (on prem)

IBM webMethods Integration is vulnerable to unauthenticated remote code execution via deserialization of untrusted data in the WmServiceMock package.

2026-07-31
CVE-2026-12116
Analyzed
9.8
HP Xerte Online Tools

A code injection vulnerability in Xerte Online Tools allows unauthenticated attackers to achieve Remote Code Execution (RCE) by manipulating the antiv...

2026-07-10
CVE-2026-12112
Analyzed
7.8
Red Hat Satellite

A flaw was found in the foreman-mcp-server

2026-06-24