21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 12201-12250 of 21553 CVEs Page 245 of 432
CVE-2026-0546
7.3
Unknown Multiple Products

A vulnerability was determined in code-projects Content Management System 1

2026-01-02
CVE-2026-0545
Analyzed
9.1
Arch MLflow

An authentication bypass in MLflow's FastAPI job endpoints allows unauthenticated attackers to submit and execute jobs, potentially leading to remote...

2026-04-04
CVE-2026-0544
7.3
Unknown Multiple Products

A security flaw has been discovered in itsourcecode School Management System 1

2026-01-01
CVE-2026-0538
Analyzed
7.8
Intel 3ds Max

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability

2026-02-05
CVE-2026-0537
Analyzed
7.8
Intel 3ds Max

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability

2026-02-05
CVE-2026-0536
Analyzed
7.8
Unknown 3ds Max

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability

2026-02-05
CVE-2026-0532
Analyzed
8.6
Google Multiple Products

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file discl...

2026-01-15
CVE-2026-0511
8.1
SAP Multiple Products

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation o...

2026-01-13
CVE-2026-0509
Analyzed
9.6
SAP NetWeaver Application

SAP NetWeaver AS ABAP allows low-privileged authenticated users to execute Remote Function Calls (RFC) without proper S_RFC authorization, impacting s...

2026-02-10
CVE-2026-0508
Analyzed
7.3
Intel BusinessObjects Business Intelligence Platform

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the applic...

2026-02-10
CVE-2026-0507
Analyzed
8.4
SAP Multiple Products

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrativ...

2026-01-13
CVE-2026-0506
8.1
Unknown Multiple Products

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC functio...

2026-01-13
CVE-2026-0501
Analyzed
9.9
SAP Multiple Products

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute craf...

2026-01-13
CVE-2026-0500
Analyzed
9.6
SAP Multiple Products

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create...

2026-01-13
CVE-2026-0498
Analyzed
9.1
SAP Multiple Products

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC....

2026-01-13
CVE-2026-0492
Analyzed
8.8
SAP Multiple Products

SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially...

2026-01-13
CVE-2026-0491
Analyzed
9.1
SAP Multiple Products

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw ena...

2026-01-13
CVE-2026-0490
Analyzed
7.5
SAP BusinessObjects BI

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authent...

2026-02-10
CVE-2026-0488
Analyzed
9.9
SAP CRM and

A flaw in SAP CRM and S/4HANA allows authenticated attackers to exploit generic function module calls to execute arbitrary SQL statements, leading to...

2026-02-10
CVE-2026-0487
Analyzed
8.4
Microsoft SAProuter

SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute mal...

2026-07-14
CVE-2026-0485
7.5
SAP BusinessObjects BI

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (...

2026-02-10
CVE-2026-0300
KEV
9.5
Palo Alto PAN-OS

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability - Active in CISA KEV catalog.

2026-05-07
CVE-2026-0257
KEV Analyzed
9.5
Palo Alto PAN-OS

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability - Active in CISA KEV catalog.

2026-05-30
CVE-2026-0204
8
Unknown Multiple Products

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions

2026-04-30
CVE-2026-0164
Analyzed
8.8
Google Modem

In Modem, there is a possible out of bounds write due to a missing bounds check

2026-06-18
CVE-2026-0163
Analyzed
9.8
Google Android

A use after free vulnerability in the Android kernel vpu_ioctl.c functions could allow an unauthenticated remote attacker to escalate privileges.

2026-08-05
CVE-2026-0162
Analyzed
8.8
Google AudioSdpParser

In ParsePayloads of AudioSdpParser

2026-06-18
CVE-2026-0161
Analyzed
8.8
Google RtpSession

In numberOfReportBlocks of RtpSession

2026-06-18
CVE-2026-0160
Analyzed
8.8
Unknown TextRtpPayloadDecoderNode

In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode

2026-06-18
CVE-2026-0154
Analyzed
8.8
Modem (Hardware/Firmware) Modem Firmware

In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption

2026-06-18
CVE-2026-0151
Analyzed
8.8
Unknown intfgraph

In IntfGraphCreate of intfgraph

2026-06-18
CVE-2026-0149
Analyzed
8.8
Google WebRTC / RTP Implementation

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow

2026-06-18
CVE-2026-0148
Analyzed
8.8
Unknown VideoRtpPayloadDecoderNode

In multiple functions of VideoRtpPayloadDecoderNode

2026-06-18
CVE-2026-0147
Analyzed
8.8
Samsung MFC Core

In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q

2026-06-18
CVE-2026-0146
Analyzed
8.8
Samsung MFC Core (Multi-Format Codec)

In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api

2026-06-18
CVE-2026-0139
Analyzed
8.8
Modem (Hardware/Firmware) Modem Firmware

In Modem, there is a possible out of bounds write due to a missing bounds check

2026-06-18
CVE-2026-0132
Analyzed
8.8
Qualcomm Modem Firmware

In Modem, there is a possible out of bounds write due to a heap buffer overflow

2026-06-18
CVE-2026-0123
8.4
Unknown Multiple Products

In EfwApTransport::ProcessRxRing of efw_ap_transport

2026-03-11
CVE-2026-0122
8.4
Unknown Multiple Products

In multiple places, there is a possible out of bounds write due to memory corruption

2026-03-11
CVE-2026-0118
8.4
Unknown Multiple Products

In oobconfig, there is a possible bypass of carrier restrictions due to a logic error

2026-03-12
CVE-2026-0117
8.4
Unknown Multiple Products

In mfc_dec_dqbuf of mfc_dec_v4l2

2026-03-12
CVE-2026-0107
8.4
Unknown Multiple Products

In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr

2026-03-12
CVE-2026-0106
Analyzed
9.3
Google VPU Driver

A missing bounds check in the vpu_mmap function of the VPU driver allows for arbitrary address mapping. This facilitates local escalation of privilege...

2026-02-06
CVE-2026-0073
Analyzed
8.8
Unknown Multiple Products

In adbd_tls_verify_cert of auth

2026-05-05
CVE-2026-0047
8.4
Infor Multiple Products

In dumpBitmapsProto of ActivityManagerService

2026-03-03
CVE-2026-0038
8.4
Unknown Multiple Products

In multiple functions of mem_protect

2026-03-03
CVE-2026-0037
8.4
Unknown Multiple Products

In multiple functions of ffa

2026-03-03
CVE-2026-0035
8.4
Unknown Multiple Products

In createRequest of MediaProvider

2026-03-03
CVE-2026-0034
8.4
Unknown Multiple Products

In setPackageOrComponentEnabled of ManagedServices

2026-03-03
CVE-2026-0032
7.8
Unknown Multiple Products

In multiple functions of mem_protect

2026-03-04