23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 1301-1350 of 23295 CVEs Page 27 of 466
CVE-2026-76836
Analyzed
8.8
AzuraCast AzuraCast

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them

2026-08-25
CVE-2026-76835
Analyzed
9.1
Unknown oauth2-proxy

OAuth2 Proxy fails to properly validate the X-Forwarded-Uri header when configured with default proxy settings, allowing unauthenticated attackers to...

2026-08-25
CVE-2026-76832
Analyzed
8.8
Agno Agno

Agno's PythonTools in libs/agno/agno/tools/python

2026-08-20
CVE-2026-7679
Analyzed
7.3
GitHub yudao-cloud

A security flaw has been discovered in YunaiV yudao-cloud up to 2026

2026-05-04
CVE-2026-76789
Analyzed
8.8
WordPress Slider Hero with Video Background, Animation

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request hand...

2026-08-29
CVE-2026-76784
Analyzed
8.7
TP-Link Kasa Smart Home Devices

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol

2026-08-27
CVE-2026-7675
Analyzed
8.8
Unknown LBT-T300-HW1

A vulnerability has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1

2026-05-03
CVE-2026-7674
Analyzed
8.8
Unknown LBT-T300-HW1

A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1

2026-05-03
CVE-2026-7670
Analyzed
7.3
Jinher Multiple Products

A flaw has been found in Jinher OA 1

2026-05-03
CVE-2026-7668
Analyzed
7.3
MikroTik RouterOS

A vulnerability was identified in MikroTik RouterOS 6

2026-05-03
CVE-2026-7667
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-07-18
CVE-2026-76658
Analyzed
10
HP Fabric Composer

A critical vulnerability in the HPE Fabric Composer SSH daemon allows unauthenticated remote attackers to achieve full administrative system compromis...

2026-09-02
CVE-2026-76657
Analyzed
10
HP Fabric Composer

An authentication bypass vulnerability in the HPE Fabric Composer API allows unauthenticated remote attackers to gain administrative privileges and fu...

2026-09-02
CVE-2026-7664
Analyzed
9.8
IBM Langflow OSS

IBM Langflow OSS suffers from improper authorization enforcement in the Streamable MCP transport endpoint, enabling unauthenticated access to protecte...

2026-06-23
CVE-2026-76639
Analyzed
8.8
GitHub G1 EDU

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execut...

2026-08-28
CVE-2026-7663
Analyzed
9.1
IBM Langflow OSS

An improper authorization vulnerability in the IBM Langflow OSS Streamable MCP transport endpoint allows unauthenticated attackers to access and execu...

2026-07-01
CVE-2026-76612
Analyzed
8.6
Joomla Zoo extension for Joomla

Joomla Extension - yootheme

2026-08-22
CVE-2026-76607
Analyzed
10
Joomla Fabrik extension for Joomla

The Fabrik extension for Joomla contains a missing access control check in the download element, permitting unauthenticated users to perform unauthori...

2026-08-23
CVE-2026-76606
Analyzed
10
Joomla Fabrik extension for Joomla

A path traversal vulnerability in the image element of the Fabrik extension for Joomla allows unauthenticated attackers to access or manipulate files...

2026-08-23
CVE-2026-76605
Analyzed
10
Joomla Fabrik extension for Joomla

The Fabrik extension for Joomla is susceptible to remote code execution through the image element, potentially allowing unauthorized command execution...

2026-08-23
CVE-2026-76604
Analyzed
10
HP Fabrik extension for Joomla

The Fabrik extension for Joomla is vulnerable to unauthenticated remote code execution due to improper control of code generation within the PHP form...

2026-08-23
CVE-2026-76602
Analyzed
9.3
Joomla Fabrik extension for Joomla

The Fabrik extension for Joomla contains an unauthenticated SQL injection vulnerability in the list model's order parameter, allowing attackers to exe...

2026-08-23
CVE-2026-76599
Analyzed
8.7
Joomla Fabrik extension for Joomla

Joomla Extension - fabrikar

2026-08-23
CVE-2026-76598
Analyzed
8.7
Joomla Fabrik extension for Joomla

Joomla Extension - fabrikar

2026-08-23
CVE-2026-76597
Analyzed
8.7
Joomla Fabrik extension for Joomla

Joomla Extension - fabrikar

2026-08-23
CVE-2026-76596
Analyzed
8.7
Joomla Fabrik extension for Joomla

Joomla Extension - fabrikar

2026-08-23
CVE-2026-76590
Analyzed
9.9
GitHub TEW-755AP

The TRENDnet TEW-755AP file /cgi-bin/wan.cgi is vulnerable to a stack-based buffer overflow via the cameo.wan.wan_pppoe_password_00 argument, allowing...

2026-08-20
CVE-2026-76589
Analyzed
9.9
GitHub TEW-755AP

The TRENDnet TEW-755AP file /sbin/mycli contains a stack-based buffer overflow vulnerability in the function FUN_401000, which can be triggered remote...

2026-08-20
CVE-2026-76586
Analyzed
7.5
WordPress Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the serv...

2026-08-30
CVE-2026-76585
Analyzed
8.8
WordPress Customer Reviews for WooCommerce

The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of...

2026-09-04
CVE-2026-76584
Analyzed
9.9
GitHub TV-IP751WIC

A stack-based buffer overflow vulnerability in the TRENDnet TV-IP751WIC camera allows remote attackers to execute arbitrary code via the Currenttime a...

2026-08-20
CVE-2026-76581
Analyzed
9.8
WordPress WPMU DEV Dashboard

The WPMU DEV Dashboard plugin for WordPress contains an authentication bypass vulnerability due to improper HMAC signature verification in its SSO AJA...

2026-08-28
CVE-2026-76571
Analyzed
9.3
Joomla Fabrik extension for Joomla

The Fabrik extension for Joomla contains an unauthenticated SQL injection vulnerability in the list filter condition parameter, allowing for unauthori...

2026-08-23
CVE-2026-76564
Analyzed
8.6
Joomla Phoca Cart extension for Joomla

Joomla Extension - phoca

2026-08-21
CVE-2026-7656
Analyzed
8.1
Zephyr Project Zephyr RTOS

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr

2026-06-30
CVE-2026-7655
Analyzed
8.1
WordPress SureCart

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4

2026-07-11
CVE-2026-76548
Analyzed
8.2
WordPress User Profile Builder

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitor...

2026-08-30
CVE-2026-7654
Analyzed
8.8
HP Admin Columns Plugin

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7

2026-06-07
CVE-2026-7649
Analyzed
7.5
WordPress is vulnerable

The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based blin...

2026-05-02
CVE-2026-7647
Analyzed
8.1
HP is vulnerable

The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3

2026-05-02
CVE-2026-7644
Analyzed
7.3
Infor Multiple Products

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2

2026-05-03
CVE-2026-7641
Analyzed
8.8
WordPress is vulnerable

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2

2026-05-02
CVE-2026-76395
Analyzed
8.8
Splunk Splunk AI Toolkit

In Splunk AI Toolkit versions below 6

2026-08-20
CVE-2026-7639
Analyzed
7.8
Imagination Graphics DDK

Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilit...

2026-07-16
CVE-2026-76389
Analyzed
8.8
Cisco Cisco Talos Intelligence for Enterprise Security Cloud

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1

2026-08-20
CVE-2026-7637
Analyzed
9.8
HP is vulnerable

The Boost plugin for WordPress is vulnerable to PHP Object Injection via an untrusted cookie, which may lead to remote code execution if a POP chain e...

2026-05-20
CVE-2026-76352
Analyzed
8.8
Splunk Splunk Enterprise

In Splunk Enterprise versions below 10

2026-08-20
CVE-2026-76351
Analyzed
8.8
Splunk Splunk Enterprise

In Splunk Enterprise versions below 10

2026-08-20
CVE-2026-76350
Analyzed
8.8
Splunk Enterprise

In Splunk Enterprise versions below 10

2026-08-20
CVE-2026-76335
Analyzed
8.8
Splunk Enterprise

In Splunk Enterprise versions below 10

2026-08-20