21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1151-1200 of 21637 CVEs Page 24 of 433
CVE-2026-7147
7.3
Infor Multiple Products

A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1

2026-04-28
CVE-2026-7146
7.3
Infor Multiple Products

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d

2026-04-28
CVE-2026-71445
Analyzed
8.2
Unknown ail-framework

AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint

2026-08-07
CVE-2026-71424
Analyzed
9.6
Unknown onyx

Onyx is vulnerable to sensitive information exposure because it incorrectly stores and leaks per-user OAuth tokens to unauthorized users through share...

2026-08-18
CVE-2026-7140
Analyzed
9.8
TOTOLINK A8000RU

An OS command injection vulnerability exists in the Totolink A8000RU CGI handler, allowing unauthenticated remote attackers to execute arbitrary syste...

2026-04-28
CVE-2026-71398
Analyzed
10
Adobe Campaign Classic

Adobe Campaign Classic contains an incorrect authorization vulnerability that permits unauthenticated remote attackers to achieve arbitrary code execu...

2026-08-12
CVE-2026-7139
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the mode parameter in the setWiFiAclRules...

2026-04-28
CVE-2026-71387
Analyzed
8.8
Adobe ColdFusion

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

2026-08-12
CVE-2026-71386
Analyzed
8.8
Adobe ColdFusion

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user

2026-08-12
CVE-2026-7138
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the tz parameter in the setNtpCfg function...

2026-04-28
CVE-2026-7137
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the sambaEnabled parameter in the setStora...

2026-04-28
CVE-2026-7136
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the wanIdx parameter in the setDmzCfg func...

2026-04-28
CVE-2026-71320
Analyzed
8.1
Nuxt Nuxt

Nuxt is an open-source web development framework for Vue

2026-08-06
CVE-2026-71315
Analyzed
8.2
Unknown nuxt

Nuxt is an open-source web development framework for Vue

2026-08-06
CVE-2026-7131
7.3
HP Multiple Products

A vulnerability has been found in code-projects Online Lot Reservation System up to 1

2026-04-28
CVE-2026-71309
Analyzed
8.6
Unknown rclone

rclone is a command-line program to sync files and directories to and from different cloud storage providers

2026-08-06
CVE-2026-7130
7.3
HP Multiple Products

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-71291
Analyzed
8.8
Bolt core

Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase

2026-08-06
CVE-2026-71289
Analyzed
9.8
NASA-AMMOS anms

The NASA-AMMOS ANMS reference implementation exposes its REST API directly to the network without authentication, allowing remote attackers to send un...

2026-08-06
CVE-2026-71288
Analyzed
8.8
Koha Koha

Koha's guided report builder (reports/guided_reports

2026-08-06
CVE-2026-71287
Analyzed
8.8
Cacti cacti

Cacti's sanitize_sql_column() (lib/functions

2026-08-06
CVE-2026-71281
Analyzed
8.8
Hugging Face peft

Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda

2026-08-06
CVE-2026-71280
Analyzed
8.5
Unknown shiori

go-shiori's DownloadBookmark() (internal/core/download

2026-08-06
CVE-2026-7128
7.3
HP Multiple Products

A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-71278
Analyzed
9.8
Unknown rust-iot-platform

The rust-iot-platform software lacks authentication on a calc rule creation endpoint, allowing unauthenticated attackers to execute arbitrary JavaScri...

2026-08-06
CVE-2026-71274
Analyzed
8.5
Unknown OpenBK7231T_App

OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels

2026-08-06
CVE-2026-71272
Analyzed
8.5
Unknown memos

Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook

2026-08-06
CVE-2026-71271
Analyzed
8.5
Unknown memos

Memos' webhook URL validation, isReservedIP() (internal/webhook/validate

2026-08-06
CVE-2026-71270
Analyzed
8.6
Stirling-Tools Stirling-PDF

Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF

2026-08-06
CVE-2026-7127
7.3
HP Multiple Products

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-71268
Analyzed
9.9
Unknown OpenPLC_v3

OpenPLC Runtime v3 contains a path traversal vulnerability in its compile_program function, allowing remote authenticated users to write arbitrary fil...

2026-08-06
CVE-2026-71267
Analyzed
9.8
Unknown microtar

A stack buffer overflow exists in rxi microtar due to improper boundary checks when copying filenames into the header structure.

2026-08-06
CVE-2026-71264
Analyzed
8.2
Aircoookie WLED

WLED's GET /json/cfg endpoint (registered in wled00/wled_server

2026-08-06
CVE-2026-71262
Analyzed
9.8
IoTSharp IoTSharp

IoTSharp fails to enforce authorization on its BlobStorageController, allowing unauthenticated remote attackers to perform arbitrary file operations v...

2026-08-06
CVE-2026-7126
7.3
HP Multiple Products

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-28
CVE-2026-71259
Analyzed
8.6
GitHub esphome

ESPHome through 2026

2026-08-06
CVE-2026-71256
Analyzed
9.8
GitHub nanoMODBUS

nanoMODBUS contains an out-of-bounds stack read and wild-pointer write vulnerability in its Modbus identification response handling, which can be trig...

2026-08-06
CVE-2026-71255
Analyzed
8.6
Unknown nanoMODBUS

nanoMODBUS through v1

2026-08-06
CVE-2026-71254
Analyzed
9.8
Unknown nanoMODBUS

An out-of-bounds write vulnerability in nanoMODBUS allows unauthenticated attackers to corrupt memory and potentially achieve remote code execution vi...

2026-08-06
CVE-2026-71252
Analyzed
8.2
Unknown toner-management

toner-management's admin state-changing handlers (add

2026-08-06
CVE-2026-7125
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the merge parameter in the setWiFiEasyCfg...

2026-04-28
CVE-2026-71243
Analyzed
8.8
Adaltas backmeup

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e

2026-08-06
CVE-2026-71242
Analyzed
8.2
Unknown crater

Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePoli...

2026-08-06
CVE-2026-7124
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the addrPrefixLen parameter in the setIpv6...

2026-04-28
CVE-2026-71235
Analyzed
8.8
Unknown magistrala

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive

2026-08-06
CVE-2026-71233
Analyzed
8.7
InvoiceNinja InvoiceNinja

InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! $entity->terms...

2026-08-06
CVE-2026-71231
Analyzed
9.8
HP IOTSmartHome

The IOTSmartHome platform is vulnerable to SQL injection via the lastLogin cookie, allowing unauthenticated attackers to bypass authentication and ext...

2026-08-06
CVE-2026-7123
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability in the Totolink A8000RU CGI handler occurs via the setIptvCfg function.

2026-04-28
CVE-2026-7122
Analyzed
9.8
TOTOLINK A8000RU

An unauthenticated remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler via the enable parameter in the setUPnPCfg fun...

2026-04-28
CVE-2026-71214
Analyzed
9.8
NASA-AMMOS plandev (sequencing-server)

The NASA-AMMOS plandev sequencing-server contains an authentication bypass flaw in the session role derivation middleware, allowing unauthenticated at...

2026-08-05