23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 1401-1450 of 23295 CVEs Page 29 of 466
CVE-2026-75948
Analyzed
8.6
Joomla iCagenda extension for Joomla

Joomla Extension - icagenda

2026-08-21
CVE-2026-75946
Analyzed
8.2
HP OMEN Gaming Hub

A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101

2026-08-22
CVE-2026-7594
Analyzed
7.3
Infor Multiple Products

A vulnerability was detected in Flux159 mcp-game-asset-gen 0

2026-05-02
CVE-2026-75933
Analyzed
7.3
Jet Jet Admin

Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option

2026-08-23
CVE-2026-75932
Analyzed
8.6
Jet Jet Admin

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and rer...

2026-08-22
CVE-2026-7593
Analyzed
7.3
Infor Multiple Products

A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0

2026-05-02
CVE-2026-7592
Analyzed
7.3
HP Multiple Products

A weakness has been identified in itsourcecode Courier Management System 1

2026-05-02
CVE-2026-75918
Analyzed
8.8
HP phpMyFAQ

phpMyFAQ before 4

2026-08-20
CVE-2026-75917
Analyzed
8.6
Unknown siyuan

SiYuan before v3

2026-08-21
CVE-2026-75916
Analyzed
8.6
SiYuan SiYuan

SiYuan through 3

2026-08-21
CVE-2026-7590
Analyzed
7.3
Infor Multiple Products

A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373

2026-05-02
CVE-2026-75877
Analyzed
9.9
GitHub TV-IP751WIC

The TRENDnet TV-IP751WIC contains a stack-based buffer overflow vulnerability in the alphapd component that can be triggered remotely by an authentica...

2026-08-19
CVE-2026-75874
Analyzed
10
Mozilla Firefox, Thunderbird

A sandbox escape vulnerability exists in the Remote Settings Client component of Mozilla Firefox and Thunderbird, potentially allowing full system com...

2026-08-19
CVE-2026-75871
Analyzed
8.2
Google AI Gateway

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1....

2026-08-28
CVE-2026-75870
Analyzed
9.1
LNATION Punk

The Punk web framework for Perl allows unauthenticated session cookie forgery because it defaults to an empty HMAC key when a session secret is not ex...

2026-08-29
CVE-2026-75865
Analyzed
9.8
WordPress WPLP Cookie Consent โ€“ Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

The WPLP Cookie Consent plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the saas_upload_logo function, potentially le...

2026-09-01
CVE-2026-75851
Analyzed
9.9
ArcadeData arcadedb

A privilege management flaw in ArcadeDB allows authenticated users to escalate privileges to administrator by exploiting asynchronous command worker t...

2026-08-19
CVE-2026-75843
Analyzed
9.9
ArcadeData arcadedb

An improper privilege management vulnerability in ArcadeDB allows authenticated users to execute unauthorized JavaScript commands, leading to privileg...

2026-08-19
CVE-2026-7584
Analyzed
7.8
Unknown Multiple Products

The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deseriali...

2026-05-01
CVE-2026-75814
Analyzed
8.8
Ebyte NE2-D11 Firmware

The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated rem...

2026-08-28
CVE-2026-75807
Analyzed
7.5
WordPress SAML Single Sign On โ€“ SSO Login

The SAML Single Sign On โ€“ SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due t...

2026-08-30
CVE-2026-7579
Analyzed
7.3
Unknown Multiple Products

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4

2026-05-02
CVE-2026-75784
Analyzed
10
GitHub TEW-WLC100

A stack-based buffer overflow in the TRENDnet TEW-WLC100 HTTP Header Handler allows remote unauthenticated attackers to execute arbitrary code.

2026-08-19
CVE-2026-75760
Analyzed
7.1
Unknown ash_ai

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a...

2026-08-31
CVE-2026-75759
Analyzed
7.6
Unknown oidcc

Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via...

2026-08-30
CVE-2026-75757
Analyzed
8.3
Unknown ash_admin

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain...

2026-08-31
CVE-2026-75754
Analyzed
10
Asus Control Center Enterprise (ACC)

A critical flaw in ASUS Control Center Enterprise allows unauthenticated attackers to obtain encryption keys, enable SSH, and gain root access via har...

2026-09-04
CVE-2026-7574
Analyzed
8.7
Anthropic Claude Desktop Cowork

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1

2026-06-24
CVE-2026-7571
Analyzed
7.1
Infor Multiple Products

A flaw was found in Keycloak

2026-05-20
CVE-2026-7570
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability

2026-06-25
CVE-2026-7569
Analyzed
8.8
Quest NetVault Backup

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability

2026-06-25
CVE-2026-7567
Analyzed
9.8
WordPress is vulnerable

The Temporary Login plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers to log in as any temporary user.

2026-05-02
CVE-2026-75596
Analyzed
8.7
Netty Netty

Netty is an asynchronous, event-driven network application framework

2026-08-21
CVE-2026-75594
Analyzed
8.2
HP kirby

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php...

2026-09-01
CVE-2026-75574
Analyzed
8.8
Unknown Grav

The Grav Email plugin (getgrav/grav-plugin-email) before 4

2026-08-25
CVE-2026-7555
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in itsourcecode Electronic Judging System 1

2026-05-01
CVE-2026-75542
Analyzed
8.3
Intel hexpm

Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another...

2026-08-25
CVE-2026-7551
Analyzed
8.8
Unknown Multiple Products

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to...

2026-05-01
CVE-2026-7550
Analyzed
7.3
HP Multiple Products

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-05-01
CVE-2026-7549
Analyzed
7.3
HP Multiple Products

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-05-01
CVE-2026-75486
Analyzed
8
Snyk sweater-comb

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to...

2026-08-30
CVE-2026-75482
Analyzed
7.5
Intel SWE-agent

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1

2026-08-18
CVE-2026-75481
Analyzed
8.8
Unknown skypilot

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions

2026-08-18
CVE-2026-7548
Analyzed
8.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink NR1800X 9

2026-05-01
CVE-2026-75479
Analyzed
7.5
Intel JimuReport

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enu...

2026-08-18
CVE-2026-7546
Analyzed
9.8
TOTOLINK NR1800X

A stack-based buffer overflow exists in the Totolink NR1800X lighttpd component, allowing remote attackers to trigger a crash or execute code via the...

2026-05-01
CVE-2026-75458
Analyzed
8.1
XueZhiSi Open Source Exam System

The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vuln...

2026-09-04
CVE-2026-7545
Analyzed
7.3
HP of the

A weakness has been identified in SourceCodester Advanced School Management System 1

2026-05-01
CVE-2026-75419
Analyzed
8.8
GoWind go-wind-cms

go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go a...

2026-08-28
CVE-2026-75417
Analyzed
7.2
HP YzmCMS

A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category....

2026-09-03