21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1501-1550 of 21637 CVEs Page 31 of 433
CVE-2026-6747
7.5
Unknown Multiple Products

Use-after-free in the WebRTC component

2026-04-22
CVE-2026-6746
7.5
Unknown Multiple Products

Use-after-free in the DOM: Core & HTML component

2026-04-22
CVE-2026-67436
Analyzed
8.3
Linux monitoring-plugins

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems

2026-07-30
CVE-2026-67431
Analyzed
8.3
Model Context Protocol ruby-sdk

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients

2026-07-30
CVE-2026-67429
Analyzed
10
Unknown flyto-core

Flyto-core fails to properly validate directory paths in its file-writing modules, enabling unauthenticated path traversal and arbitrary file write op...

2026-07-30
CVE-2026-67428
Analyzed
8.5
Unknown flyto-core

Flyto2 Core is an execution kernel for automation and AI-agent workflows

2026-07-30
CVE-2026-67427
Analyzed
8.6
Unknown flyto-core

Flyto2 Core is an execution kernel for automation and AI-agent workflows

2026-07-30
CVE-2026-67426
Analyzed
9.3
Unknown flyto-core

The flyto-verification service in flyto-core prior to 2.26.7 allows unauthenticated SSRF and secret exfiltration via a vulnerable POST endpoint that i...

2026-07-30
CVE-2026-67425
Analyzed
8.6
Intel flyto-core

Flyto2 Core is an execution kernel for automation and AI-agent workflows

2026-07-30
CVE-2026-67424
Analyzed
8.5
Unknown flyto-core

Flyto2 Core is an execution kernel for automation and AI-agent workflows

2026-07-30
CVE-2026-6741
8.8
WordPress is vulnerable

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and i...

2026-04-28
CVE-2026-67364
Analyzed
10
HP Balbooa Forms extension for Joomla

The Balbooa Forms extension for Joomla is vulnerable to pre-authentication PHP code injection via an unescaped query parameter, allowing unauthenticat...

2026-08-20
CVE-2026-67357
Analyzed
7.5
ArcadeData arcadedb

ArcadeDB versions before 26

2026-08-03
CVE-2026-67356
Analyzed
8.8
ArcadeData arcadedb

ArcadeDB before 26

2026-08-03
CVE-2026-67352
Analyzed
7.6
GitHub LuCI

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject...

2026-08-02
CVE-2026-67351
Analyzed
8.8
Serendipity Serendipity

Serendipity before 2

2026-07-31
CVE-2026-67348
Analyzed
8.1
Julep-ai Julep

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read anoth...

2026-08-01
CVE-2026-67346
Analyzed
8.6
Unknown swarms

Swarms through 6

2026-07-31
CVE-2026-67345
Analyzed
8.1
Dromara MaxKey

MaxKey through 4

2026-08-01
CVE-2026-67343
Analyzed
8.8
ArcadeData arcadedb

ArcadeDB versions before 26

2026-08-02
CVE-2026-67342
Analyzed
9.8
ArcadeData arcadedb

ArcadeDB suffers from an authorization bypass in multiple HTTP handlers, allowing unauthorized users to access or modify databases by manipulating end...

2026-08-02
CVE-2026-67341
Analyzed
9.8
ArcadeData arcadedb

ArcadeDB fails to enforce authorization checks on SQL DEFINE FUNCTION statements, allowing users with database access to execute arbitrary JavaScript...

2026-08-02
CVE-2026-67340
Analyzed
9.8
ArcadeData arcadedb

ArcadeDB allows authenticated users to execute arbitrary OS commands via malicious JavaScript triggers due to improper package filtering within the sc...

2026-08-02
CVE-2026-67336
Analyzed
8.7
Unknown better-auth

better-auth versions before 1

2026-08-02
CVE-2026-67333
Analyzed
7.2
Unknown better-auth

better-auth before 1

2026-08-02
CVE-2026-67331
Analyzed
8.3
Unknown scim

better-auth SCIM versions from 1

2026-08-02
CVE-2026-67330
Analyzed
9.9
Unknown scim

An authorization bypass in the @better-auth/scim plugin allows authenticated users to mint SCIM tokens that collide with existing provider namespaces,...

2026-08-02
CVE-2026-67329
Analyzed
7.1
Unknown stripe

@better-auth/stripe versions >= 1

2026-08-02
CVE-2026-67328
Analyzed
8.1
Better-auth SSO

@better-auth/sso versions before 1

2026-08-02
CVE-2026-67327
Analyzed
8.3
Unknown better-auth

better-auth versions >= 1

2026-08-02
CVE-2026-67326
Analyzed
7
GitPython GitPython

GitPython before 3

2026-08-02
CVE-2026-67325
Analyzed
8.8
GitPython GitPython

GitPython before 3

2026-08-02
CVE-2026-67324
Analyzed
9.8
Unknown GitPython

GitPython fails to properly filter joined short-option arguments, allowing attackers to bypass security gates and execute arbitrary commands during re...

2026-08-02
CVE-2026-67323
Analyzed
8.4
GitPython GitPython

GitPython before 3

2026-08-02
CVE-2026-67322
Analyzed
7.5
GitPython GitPython

GitPython before 3

2026-08-02
CVE-2026-67320
Analyzed
8.3
Unknown axios

axios in a Node

2026-08-02
CVE-2026-67309
Analyzed
7.8
Traefik Traefik

Traefik versions >= v3

2026-08-02
CVE-2026-67308
Analyzed
10
GitHub Wazuh

Wazuh workflows contain a shell injection vulnerability in GitHub Actions, allowing attackers to execute arbitrary commands via crafted VERSION.json f...

2026-08-02
CVE-2026-67305
Analyzed
9.4
Microsoft FreeRDP

A heap-based buffer overflow in the FreeRDP Windows client's clipboard virtual channel allows remote code execution when processing malicious clipboar...

2026-08-02
CVE-2026-67304
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67301
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67300
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67299
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67298
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP versions 3

2026-08-02
CVE-2026-67297
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67296
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67291
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67290
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02
CVE-2026-67289
Analyzed
9.8
FreeRDP FreeRDP

FreeRDP is vulnerable to HTTP request header injection because it fails to sanitize control characters in RDP redirection addresses when using an HTTP...

2026-08-02
CVE-2026-67288
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP before 3

2026-08-02