21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1351-1400 of 21637 CVEs Page 28 of 433
CVE-2026-69836
Analyzed
10
Microsoft Microsoft Entra ID

A deserialization vulnerability in Microsoft Entra ID allows unauthorized remote code execution and has been actively exploited in the wild.

2026-08-21
CVE-2026-6980
7.3
Infor Multiple Products

A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd

2026-04-26
CVE-2026-6977
Analyzed
7.3
Vanna-AI Vanna

A security vulnerability has been detected in vanna-ai vanna up to 2

2026-04-26
CVE-2026-6973
KEV
9.5
Ivanti Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability - Active in CISA KEV catalog.

2026-05-08
CVE-2026-69703
Analyzed
9.8
GitHub Atals-Livre

Atals-Livre contains an improper access control vulnerability in admin controllers that allows unauthenticated attackers to bypass authentication and...

2026-08-05
CVE-2026-6963
8.8
WordPress is vulnerable

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX a...

2026-05-02
CVE-2026-6960
Analyzed
9.8
WordPress BookingPress Pro

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads, potentially allowing unauthenticated remote code execution.

2026-05-22
CVE-2026-69543
Analyzed
8.5
Microsoft Azure Virtual Machines

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network

2026-08-21
CVE-2026-6951
Analyzed
9.8
Unknown Multiple Products

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://s...

2026-04-25
CVE-2026-6947
7.5
D-Link has

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers...

2026-04-24
CVE-2026-6942
Analyzed
9.8
Radare radare2-mcp

An OS command injection vulnerability in radare2-mcp allows unauthenticated remote attackers to execute arbitrary commands via the JSON-RPC interface.

2026-04-24
CVE-2026-69414
Analyzed
7.8
Microsoft Microsoft Malware Protection Engine

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldB...

2026-08-16
CVE-2026-6940
7.1
Unknown Multiple Products

radare2 prior to 6

2026-04-24
CVE-2026-6939
Analyzed
7.2
WordPress CorvusPay WooCommerce Payment Gateway

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all v...

2026-07-12
CVE-2026-6933
Analyzed
8.8
WordPress Dev Tools

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2

2026-06-16
CVE-2026-69320
Analyzed
8.8
Microsoft Visual Studio Code

Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to ex...

2026-08-12
CVE-2026-69263
Analyzed
8.7
FlowiseAI Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-08-05
CVE-2026-69258
Analyzed
8.8
FlowiseAI Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-08-05
CVE-2026-69250
Analyzed
8.5
Intel Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-08-05
CVE-2026-69249
Analyzed
8.7
Unknown cryptography

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

2026-08-04
CVE-2026-69247
Analyzed
8.2
Unknown cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

2026-08-04
CVE-2026-69240
Analyzed
9.8
Oracle Sequelize

Sequelize ORM versions prior to 6.37.4 contain an SQL injection vulnerability in the Oracle dialect when processing specific date strings, allowing un...

2026-08-04
CVE-2026-6924
Analyzed
8.7
GitHub Silicon Labs Matter Github

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed

2026-07-24
CVE-2026-6921
Analyzed
8.3
Microsoft Chrome on

Race in GPU in Google Chrome on Windows prior to 147

2026-04-24
CVE-2026-6920
Analyzed
9.6
Google Chrome on

An out-of-bounds read vulnerability in the Google Chrome GPU process on Android allows a remote attacker to achieve sandbox escape via a crafted HTML...

2026-04-24
CVE-2026-69192
Analyzed
7.7
Unknown ip-address

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

2026-08-04
CVE-2026-69185
Analyzed
7.5
Unknown socket.io

Socket

2026-08-04
CVE-2026-6918
Analyzed
7.5
Eclipse Foundation OpenJ9

In Eclipse Open9J versions 0

2026-05-06
CVE-2026-69152
Analyzed
7.5
Unknown brace-expansion

The brace-expansion library generates arbitrary strings containing a common prefix and suffix

2026-08-04
CVE-2026-69151
Analyzed
7.6
Angular Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-08-04
CVE-2026-69149
Analyzed
8.6
Angular Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-08-04
CVE-2026-6912
Analyzed
8.8
AWS Ops Wheel

Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165...

2026-04-25
CVE-2026-69118
Analyzed
8.8
GitHub Cachet

Cachet through 2

2026-08-11
CVE-2026-6911
Analyzed
9.8
AWS Ops Wheel

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to...

2026-04-25
CVE-2026-69106
Analyzed
8.8
Unknown artifactory

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content

2026-08-13
CVE-2026-69102
Analyzed
9.8
Unknown MaxKey

MaxKey contains a hard-coded JWT signing secret that allows unauthenticated attackers to forge valid tokens and gain full administrative access via th...

2026-08-12
CVE-2026-69101
Analyzed
7.7
Unknown tis

Datavane TIS v5

2026-08-16
CVE-2026-69100
Analyzed
8.8
Dromara lamp-cloud

LAMP Rapid Development Platform through 5

2026-08-05
CVE-2026-69098
Analyzed
9.8
Cinnamon kotaemon

The kotaemon application contains an insecure deserialization vulnerability that allows unauthenticated attackers to achieve remote code execution by...

2026-08-05
CVE-2026-69096
Analyzed
8.8
Docker LuCI

OpenWrt luci-app-dockerman (LuCI master and openwrt-25

2026-08-04
CVE-2026-69095
Analyzed
7.5
OpenWrt luci-app-bmx7

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that...

2026-08-04
CVE-2026-69091
Analyzed
7.5
Admidio Admidio

Admidio before 5

2026-08-04
CVE-2026-69089
Analyzed
7.5
Grav grav

Grav CMS 2

2026-08-04
CVE-2026-69088
Analyzed
8.1
Unknown grav

Grav CMS versions 2

2026-08-04
CVE-2026-69086
Analyzed
7.7
Unknown siyuan

SiYuan versions before v3

2026-08-04
CVE-2026-69085
Analyzed
10
Unknown siyuan

SiYuan contains a SQL injection vulnerability in the searchDocs endpoint, allowing unauthenticated attackers to read and modify database content via s...

2026-08-04
CVE-2026-69084
Analyzed
10
Unknown siyuan

A critical SQL injection vulnerability in the SiYuan /api/search/searchEmbedBlock endpoint allows unauthenticated remote attackers to execute arbitrar...

2026-08-04
CVE-2026-69083
Analyzed
10
Unknown siyuan

A critical SQL injection vulnerability in the SiYuan fullTextSearchAssetContent endpoint allows unauthenticated attackers to read, modify, or delete d...

2026-08-04
CVE-2026-69082
Analyzed
8.8
MISP cti-transmute

CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality

2026-08-04
CVE-2026-69079
Analyzed
8.7
MISP cti-transmute

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint

2026-08-04