23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 1251-1300 of 23295 CVEs Page 26 of 466
CVE-2026-77264
Analyzed
9.8
WordPress Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code

The Automation Web Platform plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to log in as any user,...

2026-08-21
CVE-2026-77236
Analyzed
7.3
Kernel FreeRTOS-Kernel

Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11

2026-08-23
CVE-2026-77235
Analyzed
7.3
Kernel FreeRTOS-Kernel

Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11

2026-08-23
CVE-2026-77234
Analyzed
8.8
FreeRTOS FreeRTOS-Kernel

Improper input validation in FreeRTOS-Kernel before 11

2026-08-22
CVE-2026-7723
Analyzed
7.3
PrefectHQ prefect

A flaw has been found in PrefectHQ prefect up to 3

2026-05-04
CVE-2026-7719
Analyzed
9.8
TOTOLINK WA300

A buffer overflow vulnerability in the Totolink WA300 loginauth function allows remote attackers to execute arbitrary code via a manipulated http_host...

2026-05-04
CVE-2026-77180
Analyzed
8.3
F5 NGINX Ingress Controller

When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingres...

2026-09-04
CVE-2026-7717
Analyzed
8.8
TOTOLINK Multiple Products

A vulnerability was determined in Totolink WA300 5

2026-05-04
CVE-2026-77148
Analyzed
9.9
Comfast CF-N1-S

The Comfast CF-N1-S Web Management interface contains a stack-based buffer overflow vulnerability in the ptest_channel configuration method, which can...

2026-08-21
CVE-2026-77146
Analyzed
8.3
TYPO3 femanager

The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted us...

2026-08-26
CVE-2026-77143
Analyzed
8.8
TYPO3 Extension "Forum"

The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified

2026-08-26
CVE-2026-77142
Analyzed
8.8
TYPO3 Extension Industry Directory

The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does...

2026-08-26
CVE-2026-77141
Analyzed
8.8
TYPO3 Extension Club Directory

The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs...

2026-08-26
CVE-2026-77140
Analyzed
8.7
TYPO3 Telephone Directory

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the c...

2026-08-26
CVE-2026-77134
Analyzed
8.3
TYPO3 femanager extension

The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash,...

2026-08-26
CVE-2026-77118
Analyzed
8.4
GraphicsMagick GraphicsMagick

A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick

2026-08-22
CVE-2026-77115
Analyzed
7.1
WordPress Popup Builder

Brave Popup Builder (brave-popup-builder) up to version 0

2026-08-24
CVE-2026-7711
Analyzed
7.3
MindsDB MindsDB

A weakness has been identified in MindsDB up to 26

2026-05-04
CVE-2026-7710
Analyzed
7.3
YunaiV yudao-cloud

A security flaw has been discovered in YunaiV yudao-cloud up to 3

2026-05-04
CVE-2026-77080
Analyzed
8.7
Unknown n8n

n8n before 1

2026-08-21
CVE-2026-77078
Analyzed
7.5
Unknown multer

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can ca...

2026-08-30
CVE-2026-77075
Analyzed
8.4
Unknown n8n

n8n before 1

2026-08-22
CVE-2026-77072
Analyzed
8.4
Unknown n8n

n8n before 1

2026-08-22
CVE-2026-77068
Analyzed
8.7
Unknown n8n

n8n before 2

2026-08-21
CVE-2026-77037
Analyzed
7.5
Unknown multer

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the wri...

2026-08-30
CVE-2026-7703
Analyzed
7.3
Media Multiple Products

A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25

2026-05-04
CVE-2026-77027
Analyzed
8.6
Joomla Fabrik extension for Joomla

Joomla Extension - fabrikar

2026-08-23
CVE-2026-77022
Analyzed
9.9
Comfast CF-N1-S

The Comfast CF-N1-S SSID configuration interface is vulnerable to a stack-based buffer overflow, allowing authenticated remote attackers to corrupt me...

2026-08-21
CVE-2026-77018
Analyzed
8.8
WordPress Workeera

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subseq...

2026-08-28
CVE-2026-77017
Analyzed
7.7
WordPress Workeera WordPress plugin

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an...

2026-09-03
CVE-2026-77016
Analyzed
9.6
WordPress Workeera WordPress plugin

The Workeera WordPress plugin contains a flaw allowing authenticated subscribers to delete arbitrary files on the server due to insufficient path vali...

2026-09-03
CVE-2026-77012
Analyzed
9.3
WordPress 数据采集和发布插件 (Data Collection and Publishing Plugin)

The 爱采集 WordPress plugin allows unauthenticated attackers to perform arbitrary file reads, server-side request forgery, and arbitrary file writes due...

2026-08-30
CVE-2026-77009
Analyzed
9.9
HP Site7

The WatchMan-Site7 WordPress plugin contains a code injection vulnerability in its debugging console that allows authenticated users to execute arbitr...

2026-09-03
CVE-2026-77007
Analyzed
7.5
WordPress HEL Online Classroom: AI-powered Online Classrooms

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API...

2026-08-30
CVE-2026-77002
Analyzed
9.8
WordPress Selfie Login

The SmilePass Selfie Login WordPress plugin fails to perform server-side identity verification, allowing unauthenticated attackers to hijack any user...

2026-08-29
CVE-2026-7698
Analyzed
7.3
Unknown Multiple Products

A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7

2026-05-04
CVE-2026-7695
Analyzed
7.3
Cloud Multiple Products

A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1

2026-05-04
CVE-2026-76943
Analyzed
9.8
Xiiaozet LK100W

The Xiiaozet LK100W administrative service contains an authentication weakness that allows unauthenticated attackers to bypass access controls and ach...

2026-08-28
CVE-2026-7694
Analyzed
7.3
Unknown Multiple Products

A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1

2026-05-04
CVE-2026-76905
Analyzed
7.5
Unknown kin-openapi

kin-openapi is a Go project for handling OpenAPI files

2026-08-23
CVE-2026-76904
Analyzed
9.8
Unknown geotools

A SQL injection vulnerability in the GeoTools library allows attackers to execute arbitrary SQL commands via the jsonArrayContains function in OGC fil...

2026-08-22
CVE-2026-7685
Analyzed
8.8
Edimax BR-6208AC

A vulnerability was detected in Edimax BR-6208AC up to 1

2026-05-03
CVE-2026-76847
Analyzed
8.8
Unknown act

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4

2026-08-25
CVE-2026-76846
Analyzed
7.5
Grav Grav

Grav before 2

2026-08-25
CVE-2026-76843
Analyzed
7.8
Unknown flair

The official Flair wheels for 0

2026-08-25
CVE-2026-76842
Analyzed
8.2
Mercado Pago Node.js SDK

The Mercado Pago Node

2026-08-25
CVE-2026-76841
Analyzed
8.8
Xorbits Xinference

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2

2026-08-25
CVE-2026-76840
Analyzed
9.6
Microsoft RustDesk

RustDesk's clipboard redirection feature in Windows is vulnerable to a heap buffer overflow, which could allow a malicious remote peer to execute arbi...

2026-08-25
CVE-2026-7684
Analyzed
8.8
Edimax BR-6428nC

A security vulnerability has been detected in Edimax BR-6428nC up to 1

2026-05-03
CVE-2026-76838
Analyzed
8.5
HiEventsDev Hi.Events

Hi

2026-08-25