21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1401-1450 of 21637 CVEs Page 29 of 433
CVE-2026-69078
Analyzed
8.8
MISP cti-transmute

CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality

2026-08-04
CVE-2026-6903
7.5
Web Multiple Products

The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality

2026-04-24
CVE-2026-6901
Analyzed
7.7
Unknown APROL

Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL

2026-07-07
CVE-2026-6900
Analyzed
7.4
B&R Industrial Automation APROL

Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL

2026-07-07
CVE-2026-68981
Analyzed
8.8
Apache Apache NiFi

Apache NiFi 1

2026-08-04
CVE-2026-6898
Analyzed
8.8
WordPress WishList Member

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_...

2026-05-27
CVE-2026-6897
Analyzed
8.8
WordPress WishList Member

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\F...

2026-05-27
CVE-2026-6896
Analyzed
8.7
GitLab GitLab EE

GitLab has remediated an issue in GitLab EE affecting all versions from 13

2026-07-09
CVE-2026-6895
Analyzed
8.8
WordPress WishList Member

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation i...

2026-05-27
CVE-2026-68945
Analyzed
8.8
Angular Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-08-04
CVE-2026-6893
Analyzed
8.8
Red Hat dracut

A flaw was found in dracut

2026-06-11
CVE-2026-68899
Analyzed
8.7
Wekan Wekan

Wekan is open source kanban built with Meteor

2026-08-21
CVE-2026-6887
Analyzed
9.8
Borg Multiple Products

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attack...

2026-04-24
CVE-2026-6886
Analyzed
9.8
Borg Multiple Products

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remot...

2026-04-24
CVE-2026-6885
Analyzed
9.8
Borg Multiple Products

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remo...

2026-04-24
CVE-2026-68820
KEV Analyzed
9.5
Microsoft Windows Ancillary Function Driver for WinSock

A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.

2026-08-12
CVE-2026-68772
Analyzed
8
ZenML ZenML

ZenML 0

2026-08-08
CVE-2026-68771
Analyzed
9.8
Comfy-Org ComfyUI

ComfyUI v0.23.0 contains an insecure deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to exe...

2026-08-01
CVE-2026-68770
Analyzed
9.8
Hugging Face sentence-transformers

A logic flaw in the sentence-transformers library allows attackers to bypass security checks and achieve arbitrary code execution by loading malicious...

2026-08-01
CVE-2026-68750
Analyzed
8.2
F5 html_sanitize_ex

Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhau...

2026-08-06
CVE-2026-6875
Analyzed
9.5
ServiceNow ServiceNow AI Platform

A remote code execution vulnerability in the ServiceNow AI Platform allows unauthenticated users to execute arbitrary code, necessitating an immediate...

2026-07-14
CVE-2026-68749
Analyzed
8.2
Unknown html_sanitize_ex

Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to ex...

2026-08-06
CVE-2026-6859
8.8
Linux Multiple Products

A flaw was found in InstructLab

2026-04-23
CVE-2026-68587
Analyzed
8.6
Unknown siyuan

SiYuan versions before v3

2026-08-04
CVE-2026-68586
Analyzed
8.6
Unknown siyuan

SiYuan before v3

2026-08-04
CVE-2026-68584
Analyzed
8.6
Intel siyuan

SiYuan versions before v3

2026-08-04
CVE-2026-68581
Analyzed
8.1
Unknown vikunja

Vikunja versions 0

2026-08-03
CVE-2026-68580
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-03
CVE-2026-6858
Analyzed
7.1
WordPress Webpay WordPress Plugin

The Transbank Webpay WordPress plugin before 1

2026-06-23
CVE-2026-68579
Analyzed
9.6
Microsoft FreeRDP

FreeRDP contains a heap-based buffer overflow in the Windows clipboard client, which can be triggered by a malicious RDP server sending an oversized r...

2026-08-03
CVE-2026-68578
Analyzed
7.5
ArcadeData arcadedb

ArcadeDB versions before 26

2026-08-03
CVE-2026-6857
7.5
Unknown Multiple Products

A flaw was found in camel-infinispan

2026-04-24
CVE-2026-68561
Analyzed
8.8
Wekan Wekan

Wekan is open source kanban built with Meteor

2026-08-20
CVE-2026-6855
7.1
Unknown Multiple Products

A flaw was found in InstructLab

2026-04-24
CVE-2026-6853
Analyzed
9.8
Başbelen Group Pause+ Mobile App

The Pause+ Mobile App contains an authentication bypass vulnerability due to improper restriction of excessive authentication attempts.

2026-06-13
CVE-2026-68518
Analyzed
8.8
Unknown glances

Glances is an open-source system cross-platform monitoring tool

2026-08-18
CVE-2026-68503
Analyzed
9.8
Unknown LazyOwn

The LazyOwn C2 framework contains default credentials in its source code, allowing unauthenticated remote attackers to gain operator level access to t...

2026-07-31
CVE-2026-68502
Analyzed
9.8
Unknown LazyOwn

A missing authentication flaw in the LazyOwn Socket.IO event handler allows unauthenticated remote attackers to execute arbitrary commands within the...

2026-07-31
CVE-2026-68494
Analyzed
8.7
FasterXML jackson-core

The fix released in jackson-core 2

2026-08-05
CVE-2026-6849
Analyzed
8.8
TUBITAK BILGEM Institute Pardus

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Resea...

2026-04-30
CVE-2026-6847
Analyzed
9.3
HP ThemisNETPanel

ThemisNETPanel contains a critical remote code execution vulnerability due to the lack of authentication on its file upload functionality.

2026-07-14
CVE-2026-6846
7.8
Unknown Multiple Products

A flaw was found in binutils

2026-04-23
CVE-2026-68454
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to re...

2026-08-14
CVE-2026-6832
8.1
Unknown Multiple Products

Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files...

2026-04-22
CVE-2026-6823
8.2
HKUDS Multiple Products

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*...

2026-04-22
CVE-2026-6819
8.8
HKUDS Multiple Products

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /relo...

2026-04-22
CVE-2026-68134
Analyzed
7.3
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing facility check Only register the physical clock when...

2026-08-20
CVE-2026-68131
Analyzed
7.5
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object map update path In a reply me...

2026-08-20
CVE-2026-68128
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype, p...

2026-08-20
CVE-2026-68125
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the authentication tag llsec_do_dec...

2026-08-20