8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 101-150 of 8341 CVEs Page 3 of 167
CVE-2026-24070
Analyzed
8.8
During Multiple Products

During the installation of the Native Access application, a privileged helper `com

2026-02-03
CVE-2026-24061
KEV Analyzed
9.8
Unknown Multiple Products

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

2026-01-21
CVE-2026-24051
Analyzed
7
Unknown Multiple Products

OpenTelemetry-Go is the Go implementation of OpenTelemetry

2026-02-03
CVE-2026-24042
Analyzed
9.4
Unknown Multiple Products

Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticat...

2026-01-22
CVE-2026-24038
8.1
Horilla Multiple Products

Horilla is a free and open source Human Resource Management System (HRMS)

2026-01-22
CVE-2026-24016
Analyzed
7.8
Microsoft Multiple Products

The installer of ServerView Agents for Windows provided by Fsas Technologies Inc

2026-01-21
CVE-2026-24010
8.8
Horilla Multiple Products

Horilla is a free and open source Human Resource Management System (HRMS)

2026-01-22
CVE-2026-24009
Analyzed
8.1
Docling Multiple Products

Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling

2026-01-23
CVE-2026-24006
7.5
Seroval Multiple Products

Seroval facilitates JS value stringification, including complex structures beyond JSON

2026-01-22
CVE-2026-24002
Analyzed
9
Unknown Multiple Products

Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases wh...

2026-01-22
CVE-2026-23997
Analyzed
8
FacturaScripts Multiple Products

FacturaScripts is open-source enterprise resource planning and accounting software

2026-02-03
CVE-2026-23988
Analyzed
7.3
Rufus Multiple Products

Rufus is a utility that helps format and create bootable USB flash drives

2026-01-24
CVE-2026-23967
Analyzed
7.5
Unknown Multiple Products

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4

2026-01-22
CVE-2026-23966
Analyzed
9.1
Oracle Multiple Products

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists i...

2026-01-22
CVE-2026-23965
Analyzed
7.5
Unknown Multiple Products

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4

2026-01-22
CVE-2026-23962
7.5
Unknown Multiple Products

Mastodon is a free, open-source social network server based on ActivityPub

2026-01-22
CVE-2026-23957
7.5
Unknown Multiple Products

seroval facilitates JS value stringification, including complex structures beyond JSON

2026-01-22
CVE-2026-23956
7.5
Unknown Multiple Products

seroval facilitates JS value stringification, including complex structures beyond JSON

2026-01-22
CVE-2026-23954
8.7
Unknown Multiple Products

Incus is a system container and virtual machine manager

2026-01-23
CVE-2026-23953
8.7
Unknown Multiple Products

Incus is a system container and virtual machine manager

2026-01-23
CVE-2026-23950
Analyzed
8.8
Intel Multiple Products

node-tar,a Tar for Node

2026-01-20
CVE-2026-23949
Analyzed
8.6
Unknown Multiple Products

jaraco

2026-01-20
CVE-2026-23896
7.2
Unknown Multiple Products

immich is a high performance self-hosted photo and video management solution

2026-01-30
CVE-2026-23881
Analyzed
7.7
Kubernetes Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams

2026-01-28
CVE-2026-23880
Analyzed
7.3
Intel Multiple Products

OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida

2026-01-20
CVE-2026-23876
Analyzed
8.1
ImageMagick Multiple Products

ImageMagick is free and open-source software used for editing and manipulating digital images

2026-01-20
CVE-2026-23864
7.5
React Multiple Products

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-d...

2026-01-27
CVE-2026-23846
Analyzed
8.1
Docker Multiple Products

Tugtainer is a self-hosted app for automating updates of Docker containers

2026-01-20
CVE-2026-23843
Analyzed
7.1
HP Multiple Products

teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients

2026-01-20
CVE-2026-23842
Analyzed
7.5
Intel Multiple Products

ChatterBot is a machine learning, conversational dialog engine for creating chat bots

2026-01-20
CVE-2026-23841
Analyzed
9.3
Unknown Multiple Products

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-sit...

2026-01-20
CVE-2026-23840
Analyzed
9.3
Unknown Multiple Products

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-sit...

2026-01-20
CVE-2026-23839
Analyzed
9.3
Unknown Multiple Products

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-sit...

2026-01-20
CVE-2026-23837
Analyzed
9.8
Nginx Multiple Products

MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions a...

2026-01-20
CVE-2026-23836
Analyzed
9.9
HP Multiple Products

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formu...

2026-01-20
CVE-2026-23830
Analyzed
10
Unknown Multiple Products

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated i...

2026-01-28
CVE-2026-23800
10
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 bef...

2026-01-17
CVE-2026-23760
KEV
9.5
SmarterTools SmarterMail

SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.

2026-01-27
CVE-2026-23744
9.8
Unknown Multiple Products

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vul...

2026-01-17
CVE-2026-23742
Analyzed
8.8
Skipper Multiple Products

Skipper is an HTTP router and reverse proxy for service composition

2026-01-17
CVE-2026-23737
7.5
Unknown Multiple Products

seroval facilitates JS value stringification, including complex structures beyond JSON

2026-01-22
CVE-2026-23736
7.3
Unknown Multiple Products

seroval facilitates JS value stringification, including complex structures beyond JSON

2026-01-22
CVE-2026-23723
7.2
Unknown Multiple Products

WeGIA is a web manager for charitable institutions

2026-01-18
CVE-2026-23722
Analyzed
9.1
HP Multiple Products

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA s...

2026-01-17
CVE-2026-23699
7.2
Unknown Multiple Products

AP180 series with firmware versions prior to AP_RGOS 11

2026-01-22
CVE-2026-23625
Analyzed
8.7
Intel Multiple Products

OpenProject is an open-source, web-based project management software

2026-01-20
CVE-2026-23593
Analyzed
7.5
HP Multiple Products

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view s...

2026-01-28
CVE-2026-23592
Analyzed
7.2
HP Multiple Products

Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code e...

2026-01-28
CVE-2026-23550
Analyzed
10
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in Modular DS allows Privilege Escalation.This issue affects Modular DS: from n/a through 2.5.1.

2026-01-14
CVE-2026-23535
Analyzed
8
Unknown Multiple Products

wlc is a Weblate command-line client using Weblate's REST API

2026-01-17