23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 1501-1550 of 23295 CVEs Page 31 of 466
CVE-2026-74891
Analyzed
9.8
Unknown openssl_encrypt

The jahlives openssl_encrypt package contains hardcoded database credentials in standalone configuration files, allowing unauthorized network access t...

2026-08-18
CVE-2026-7489
Analyzed
8.8
Sunnet CTMS

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,...

2026-05-03
CVE-2026-74889
Analyzed
9.8
Unknown openssl_encrypt

A cryptographic weakness in jahlives openssl_encrypt before version 1.4.0 allows for predictable key derivation due to improper HKDF implementation.

2026-08-18
CVE-2026-74888
Analyzed
7.5
Jahlives openssl_encrypt

openssl_encrypt versions before 1

2026-08-18
CVE-2026-74886
Analyzed
9.8
Unknown openssl_encrypt

A plugin sandbox bypass vulnerability exists in jahlives openssl_encrypt before version 1.4.0, allowing unauthenticated attackers to execute arbitrary...

2026-08-18
CVE-2026-74884
Analyzed
7.5
Jahlives openssl_encrypt

openssl_encrypt versions before 1

2026-08-18
CVE-2026-74883
Analyzed
8.8
Jahlives openssl_encrypt

openssl_encrypt versions before 1

2026-08-18
CVE-2026-74882
Analyzed
7.5
Unknown openssl_encrypt

openssl_encrypt versions before 1

2026-08-18
CVE-2026-74880
Analyzed
9.8
Unknown openssl_encrypt

The openssl_encrypt library exposes sensitive refresh tokens in URL query parameters, leading to potential token leakage via server logs, proxy logs,...

2026-08-18
CVE-2026-7488
Analyzed
7.5
IKAS Technology E-Commerce

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc

2026-07-19
CVE-2026-74879
Analyzed
7.5
Unknown openssl_encrypt

openssl_encrypt versions before 1

2026-08-18
CVE-2026-74878
Analyzed
9.8
Unknown openssl_encrypt

The TOTP rate-limiting mechanism in openssl_encrypt is vulnerable to bypass because it uses local, non-persistent memory that is easily reset or distr...

2026-08-18
CVE-2026-74877
Analyzed
8.8
Jahlives openssl_encrypt

openssl_encrypt versions before 1

2026-08-18
CVE-2026-74876
Analyzed
9.8
Unknown openssl_encrypt

A cryptographic signature verification bypass in openssl_encrypt allows attackers to encrypt sensitive data using arbitrary public keys by abusing the...

2026-08-18
CVE-2026-74875
Analyzed
9.8
Unknown openssl_encrypt

A schema validation bypass vulnerability in openssl_encrypt allows attackers to process malicious data by manipulating the jsonschema dependency or su...

2026-08-18
CVE-2026-74874
Analyzed
7.5
Unknown openssl_encrypt

openssl_encrypt versions before 1

2026-08-18
CVE-2026-74872
Analyzed
9.8
Unknown openssl_encrypt

An arbitrary code execution vulnerability exists in the Whirlpool hash implementation of jahlives openssl_encrypt, caused by insecure loading of share...

2026-08-18
CVE-2026-74869
Analyzed
7.7
Unknown stoatchat

stoatchat before 0

2026-08-18
CVE-2026-74868
Analyzed
7.5
SiYuan SiYuan Note

SiYuan versions before 3

2026-08-18
CVE-2026-7486
Analyzed
9.8
Netcad Software E-ฤฐmar

An SQL injection vulnerability in Netcad Software E-ฤฐmar allows unauthorized attackers to manipulate database queries and potentially access sensitive...

2026-06-10
CVE-2026-74845
Analyzed
8.8
Unknown Official Document Management System

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers t...

2026-08-18
CVE-2026-74843
Analyzed
10
GitHub WN531P3, WN535M1

A stack-based buffer overflow in the Wavlink Export Pingortrace CGI function allows unauthenticated remote attackers to execute arbitrary code via a m...

2026-08-18
CVE-2026-74837
Analyzed
8.7
Unknown ash_typescript

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEA...

2026-09-01
CVE-2026-74836
Analyzed
8.7
Unknown bandit

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded num...

2026-08-21
CVE-2026-74835
Analyzed
8.7
Erlang OTP (inets application)

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTPย 17.0 before...

2026-09-02
CVE-2026-7483
Analyzed
8.5
ESET ESET Endpoint Security for macOS

Local privilege escalationย potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user

2026-07-25
CVE-2026-74820
Analyzed
10
ServiceNow ServiceNow AI Platform

A SQL injection vulnerability in the ServiceNow AI platform allows unauthenticated remote attackers to execute arbitrary SQL commands, potentially lea...

2026-08-28
CVE-2026-7482
Analyzed
9.1
Ollama Multiple Products

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied...

2026-05-05
CVE-2026-7481
Analyzed
8.7
GitLab has remediated

GitLab has remediated an issue in GitLab EE affecting all versions from 16

2026-05-14
CVE-2026-74803
Analyzed
10
Joomla Zoo extension for Joomla

The Zoo extension for Joomla contains an unauthenticated arbitrary file upload vulnerability within the image element, allowing attackers to bypass fi...

2026-08-20
CVE-2026-74802
Analyzed
8.2
SiYuan SiYuan

SiYuan versions before 3

2026-08-18
CVE-2026-74801
Analyzed
8.2
SiYuan SiYuan

SiYuan before 3

2026-08-18
CVE-2026-74800
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 are vulnerable to stored cross-site scripting due to missing security headers when serving user-uploaded assets, allowing...

2026-08-18
CVE-2026-74799
Analyzed
9.3
Unknown siyuan

SiYuan versions before 3.7.4 expose unauthenticated Go debug endpoints, allowing remote attackers to extract sensitive in-memory data such as API keys...

2026-08-18
CVE-2026-74798
Analyzed
8.7
Unknown siyuan

SiYuan kernel before v3

2026-08-18
CVE-2026-74795
Analyzed
7.5
Scriban Scriban

Scriban before 6

2026-08-17
CVE-2026-74794
Analyzed
7.5
Scriban Scriban

Scriban before 6

2026-08-17
CVE-2026-74792
Analyzed
7.5
Scriban Scriban

Scriban before 7

2026-08-17
CVE-2026-74791
Analyzed
8.6
Intel scriban

Scriban before 7

2026-08-17
CVE-2026-74790
Analyzed
9.1
Unknown scriban

Scriban fails to properly cache TypedObjectAccessor by Type, allowing attackers to reuse TemplateContext instances to bypass sandbox policies and acce...

2026-08-17
CVE-2026-74789
Analyzed
7.5
Scriban Scriban

Scriban before 7

2026-08-17
CVE-2026-74788
Analyzed
7.5
Scriban Scriban

Scriban before 7

2026-08-17
CVE-2026-74787
Analyzed
7.5
Scriban Scriban

Scriban before 7

2026-08-17
CVE-2026-74784
Analyzed
8.7
Scriban scriban

Scriban before 7

2026-08-17
CVE-2026-74783
Analyzed
7.5
Scriban Scriban

Scriban versions 6

2026-08-17
CVE-2026-74770
Analyzed
8.8
Dell PowerProtect One

Dell PowerProtect One, versions 20

2026-08-27
CVE-2026-74767
Analyzed
8.7
F5 pandora

Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files

2026-08-16
CVE-2026-74764
Analyzed
10
Unknown pandora

Pandora is vulnerable to path traversal during TAR archive extraction, allowing attackers to overwrite arbitrary files on the host system.

2026-08-16
CVE-2026-74752
Analyzed
9.8
Linux Kernel

The Linux kernel SCTP implementation fails to validate cookie AUTH state, leading to potential out-of-bounds memory access and local privilege escalat...

2026-08-27
CVE-2026-74746
Analyzed
9.8
Linux Kernel

A race condition exists in the Linux kernel netfilter flowtable implementation, allowing unauthenticated attackers to trigger a slab use-after-free vu...

2026-08-27