23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 11951-12000 of 23391 CVEs Page 240 of 468
CVE-2026-18794
Analyzed
8.2
CalcProgrammer1 OpenRGB

The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data.

2026-08-28
CVE-2026-18787
Analyzed
8.8
GitHub AX1800

A vulnerability was identified in GL

2026-08-05
CVE-2026-18786
Analyzed
8.8
WordPress CheckView

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the a...

2026-08-27
CVE-2026-18781
Analyzed
8.1
WordPress Drag and Drop Multiple File Upload for Contact Form 7

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1

2026-08-22
CVE-2026-18765
Analyzed
9.8
Unknown E-OSB

Teracity Software Technologies E-OSB is vulnerable to SQL injection due to improper neutralization of special elements in SQL commands, potentially al...

2026-09-02
CVE-2026-18759
Analyzed
8.5
Asus ABP and AES

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by...

2026-08-04
CVE-2026-18754
Analyzed
9.1
GeoVision GV-AS1620 (GV-Cloud)

The GeoVision GV-AS1620 GV-Cloud firmware contains a hard-coded RSA private key, which allows attackers to decrypt HTTPS traffic and spoof the server.

2026-08-04
CVE-2026-18753
Analyzed
9.1
GeoVision GV-AS1620 (AS-Manager)

The GeoVision GV-AS1620 AS-Manager firmware contains a hard-coded RSA private key, allowing attackers to decrypt HTTPS traffic and spoof the server.

2026-08-04
CVE-2026-18733
Analyzed
8.8
Amazon Strands Agents Tools

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0

2026-08-04
CVE-2026-18729
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of c...

2026-08-29
CVE-2026-18713
Analyzed
8.8
IBM i

IBM i 7

2026-08-13
CVE-2026-18692
Analyzed
8.8
MongoDB MongoDB Server

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal refe...

2026-08-12
CVE-2026-18691
Analyzed
8.8
MongoDB MongoDB Server

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechani...

2026-08-12
CVE-2026-18686
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the nas-web component of GL.iNet GL-MT3000 allows remote, unauthenticated attackers to execute arbitrary system c...

2026-08-04
CVE-2026-18685
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the set_upgrade function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to...

2026-08-04
CVE-2026-18684
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the remove_profile function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers...

2026-08-04
CVE-2026-18683
Analyzed
8.8
IBM i

IBM i 7

2026-08-13
CVE-2026-1868
Analyzed
9.9
GitLab has remediated

Insecure template expansion in GitLab AI Gateway allows attackers to cause a denial-of-service or execute arbitrary code via crafted Duo Agent definit...

2026-02-09
CVE-2026-18670
Analyzed
8.2
IBM AIX and PowerVM VIOS

IBM AIX 7

2026-08-22
CVE-2026-18669
Analyzed
8.8
IBM i

IBM i 7

2026-08-13
CVE-2026-18667
Analyzed
9.6
Tenable Sensor Proxy

Tenable Sensor Proxy is vulnerable to remote code execution, allowing an unauthenticated attacker to gain elevated privileges if an operator connects...

2026-08-04
CVE-2026-18658
Analyzed
9.8
IBM Operational Decision Manager

IBM Operational Decision Manager is vulnerable to unauthenticated SQL injection, allowing attackers to execute arbitrary commands and potentially achi...

2026-09-05
CVE-2026-18657
Analyzed
7.8
Amazon Kiro CLI

An uncontrolled search path element in Kiro CLI before version 2

2026-08-05
CVE-2026-18656
Analyzed
7.8
Amazon Kiro IDE

An uncontrolled search path element in Kiro IDE before version 1

2026-08-05
CVE-2026-18653
Analyzed
7.2
WordPress WP Directory Kit

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrator...

2026-08-25
CVE-2026-18650
Analyzed
8.8
HAVELSAN Liman MYS

Missing Authorization vulnerability in HAVELSAN Inc

2026-08-05
CVE-2026-18642
Analyzed
7.8
TUBITAK BILGEM eta-otp-lock

Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection

2026-08-04
CVE-2026-18634
Analyzed
8.4
SonicWall GMS

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier ve...

2026-08-27
CVE-2026-18630
Analyzed
8.8
Unknown Talassoft Industrial Management Software

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassof...

2026-09-03
CVE-2026-18621
Analyzed
7.6
Red Hat OpenShift AI

A flaw was found in Data Science Pipelines (DSP)

2026-08-11
CVE-2026-1862
Analyzed
8.8
Google Chrome prior

Type Confusion in V8 in Google Chrome prior to 144

2026-02-04
CVE-2026-18618
Analyzed
7.5
Red Hat OpenShift AI

A flaw was found in ml-metadata

2026-08-11
CVE-2026-18617
Analyzed
8.8
Red Hat OpenShift AI

A flaw was found in the Data Science Pipelines Operator (DSPO)

2026-08-11
CVE-2026-18616
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attacker...

2026-08-04
CVE-2026-18615
Analyzed
9.8
GitHub GL-MT3000

An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.ge...

2026-08-04
CVE-2026-18614
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands...

2026-08-04
CVE-2026-18613
Analyzed
9.8
GitHub GL-MT3000

A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attacker...

2026-08-04
CVE-2026-18612
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary co...

2026-08-04
CVE-2026-18611
Analyzed
7.5
Red Hat OpenShift AI

A flaw was found in the Data Science Pipelines Operator

2026-08-11
CVE-2026-1861
Analyzed
8.8
Google Chrome prior

Heap buffer overflow in libvpx in Google Chrome prior to 144

2026-02-04
CVE-2026-18608
Analyzed
8.7
Red Hat OpenShift AI

A flaw was found in the Data Science Pipelines Operator (DSPO)

2026-08-11
CVE-2026-18607
Analyzed
8.8
Wavlink WN572, WN570H, WN573, WN529, WN530, WN531

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc

2026-08-04
CVE-2026-18606
Analyzed
7.8
Razer RzUpdateService

A weakness has been identified in Razer RzUpdateService 1

2026-08-04
CVE-2026-18602
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attacker...

2026-08-04
CVE-2026-18601
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the GL.iNet GL-MT3000 ovpn-client.so plugin allows unauthenticated remote attackers to execute arbitrary code via...

2026-08-04
CVE-2026-18600
Analyzed
8.8
GL.iNet GL-MT3000

A vulnerability has been found in GL

2026-08-04
CVE-2026-18599
Analyzed
8
GitHub GL-MT3000

A flaw has been found in GL

2026-08-04
CVE-2026-18598
Analyzed
8.8
GL.iNet GL-MT3000

A vulnerability was detected in GL

2026-08-04
CVE-2026-18597
Analyzed
8.5
Foxit Foxit PDF Services API

The PDF creation feature of Foxit PDF Services API supports referencing external files

2026-08-06
CVE-2026-18589
Analyzed
9.8
GitHub WL-NU516U1

A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the...

2026-08-03