23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 12651-12700 of 23871 CVEs Page 254 of 478
CVE-2026-17632
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-17626
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-17624
Analyzed
8.5
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-17623
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-17617
Analyzed
8.5
IBM Application Gateway Operator

IBM Application Gateway Operator 22

2026-08-06
CVE-2026-17615
Analyzed
7.5
Red Hat Apache Camel 4 for Quarkus 3

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. B...

2026-09-01
CVE-2026-1761
Analyzed
8.6
Red Hat Red Hat Enterprise Linux 10

A flaw was found in libsoup

2026-02-03
CVE-2026-17603
Analyzed
8.7
Sonatype Nexus Repository 3

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API

2026-08-08
CVE-2026-17601
Analyzed
8.9
Sonatype Nexus Repository 3

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader perm...

2026-08-08
CVE-2026-17600
Analyzed
8.7
Sonatype Nexus Repository 3

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account wa...

2026-08-08
CVE-2026-17594
Analyzed
8.2
Sonatype Nexus Repository 3

Nexus Repository 3 CE/Pro versions 3

2026-08-08
CVE-2026-17593
Analyzed
7.2
Sonatype Nexus Repository

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Reposit...

2026-08-09
CVE-2026-17583
Analyzed
8.4
Thermo Fisher

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because

2026-08-06
CVE-2026-17581
Analyzed
7.2
kilbot

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all v...

2026-08-16
CVE-2026-17568
Analyzed
8.8
Devolutions Server

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the u...

2026-07-29
CVE-2026-17566
Analyzed
9.9
pgadmin.org pgAdmin 4

An OS command injection vulnerability in the Import/Export Data tool of pgAdmin 4 allows authenticated users to execute arbitrary commands on the unde...

2026-08-01
CVE-2026-17561
Analyzed
9.8
Innotim Software Logsign SIEM

A code injection vulnerability in Logsign SIEM allows unauthenticated attackers to execute arbitrary code due to improper control of code generation.

2026-08-01
CVE-2026-1756
Analyzed
8.8
seezee WP FOFT Loader

The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::fi...

2026-02-04
CVE-2026-17556
Analyzed
8.8
GitHub Enterprise Server

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and direc...

2026-08-06
CVE-2026-17544
Analyzed
8.1
PHP Group PHP

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8

2026-08-01
CVE-2026-17543
Analyzed
8.1
PHP Group PHP

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8

2026-08-01
CVE-2026-17542
Analyzed
7.5
WordPress File Manager

The File Manager WordPress plugin before 6

2026-08-11
CVE-2026-17541
Analyzed
7.5
WordPress File Manager

The File Manager WordPress plugin before 6

2026-08-11
CVE-2026-17540
Analyzed
8.8
WordPress File Manager

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a su...

2026-08-18
CVE-2026-17527
Analyzed
7.7
Red Hat Red Hat Container Native Virtualization 4.14

In containerized-data-importer (CDI), the aggregated cdi

2026-07-28
CVE-2026-17524
Analyzed
7.5
Unknown zip-lib

Versions of the package zip-lib before 1

2026-07-28
CVE-2026-17523
Analyzed
7.8
Red Hat Red Hat Enterprise Linux 8

A flaw was found in the kernel

2026-07-28
CVE-2026-17510
Analyzed
7.5
JONASBN Crypt::OpenSSL::PKCS12

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print...

2026-08-17
CVE-2026-17502
Analyzed
8.6
IBM i

IBM i 7

2026-08-14
CVE-2026-1750
Analyzed
8.8
ecwid Ecwid by Lightspeed Ecommerce Shopping Cart

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7

2026-02-15
CVE-2026-17497
Analyzed
8.3
codexu NoteGen

NoteGen before 0

2026-07-27
CVE-2026-17496
Analyzed
8.1
codexu NoteGen

NoteGen before 0

2026-07-27
CVE-2026-17482
Analyzed
9.8
IBM Documentation Offline

IBM Documentation Offline 1.0.0 through 1.4.1 contains a path traversal vulnerability that permits unauthenticated remote attackers to execute arbitra...

2026-08-14
CVE-2026-17481
Analyzed
8.8
IBM Documentation Offline

IBM Documentation Offline 1

2026-08-14
CVE-2026-17436
Analyzed
8.8
IBM AIX

IBM AIX 7

2026-08-21
CVE-2026-17417
Analyzed
8.8
IBM i

IBM i 7

2026-08-13
CVE-2026-1740
Analyzed
7.3
EFM ipTIME A8004T

A vulnerability was found in EFM ipTIME A8004T 14

2026-02-02
CVE-2026-17351
Analyzed
9
pgadmin.org pgAdmin 4

A flawed fix in pgAdmin 4 allows for SQL injection via AI Assistant tool calls, enabling attackers to execute arbitrary multi-statement SQL commands.

2026-08-01
CVE-2026-17349
Analyzed
9.6
pgadmin.org pgAdmin 4

A vulnerability in the pgAdmin 4 Workspaces feature allows authenticated users to clone and inherit sensitive database credentials from other users, l...

2026-08-01
CVE-2026-17347
Analyzed
7.5
pgadmin.org pgAdmin 4

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7

2026-08-01
CVE-2026-17346
Analyzed
8.8
pgadmin.org pgAdmin 4

The fix for CVE-2026-12044 in pgAdmin 4 9

2026-08-01
CVE-2026-1731
KEV Analyzed
9.5
BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA)

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability - Active in CISA KEV catalog.

2026-02-14
CVE-2026-1730
Analyzed
8.8
skirridsystems OS DataHub Maps

The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::...

2026-02-03
CVE-2026-1729
Analyzed
9.8
scriptsbundle AdForest

The AdForest WordPress theme (<= 6.0.12) is vulnerable to authentication bypass via the sb_login_user_with_otp_fun function, allowing attackers to log...

2026-02-12
CVE-2026-1728
Analyzed
9.8
WSO2 WSO2 API Manager

WSO2 API Manager suffers from improper privilege management where low-privileged tokens can access administrative REST APIs, potentially leading to fu...

2026-08-06
CVE-2026-17250
Analyzed
8.5
TP-Link TL-MR6400 v7.0

A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlle...

2026-08-22
CVE-2026-17223
Analyzed
8.8
IBM i

IBM i 7

2026-08-14
CVE-2026-17218
Analyzed
9.8
IBM i

IBM i versions 7.3 through 7.6 are affected by an out-of-bounds write vulnerability that allows a remote, unauthenticated attacker to execute arbitrar...

2026-08-13
CVE-2026-17203
Analyzed
7.5
IBM Administration Runtime Expert for i

IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authenticati...

2026-08-30
CVE-2026-1720
Analyzed
8.8
wpxpo

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrar...

2026-03-06