21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1551-1600 of 21637 CVEs Page 32 of 433
CVE-2026-67282
Analyzed
10
Joomla Fabrik extension for Joomla

The Fabrik extension for Joomla contains an unauthenticated remote code execution vulnerability within its frontend listfilter model.

2026-08-13
CVE-2026-67261
Analyzed
9.8
VMware Virtual Storage Integrator for VMware vSphere Client

An OS command injection vulnerability exists in the Dell Virtual Storage Integrator for VMware vSphere Client, allowing unauthenticated remote attacke...

2026-08-06
CVE-2026-67248
Analyzed
8.7
Asus ADM

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM

2026-07-30
CVE-2026-67244
Analyzed
8.6
Asus ADM

A format string vulnerability was found in the Notification OAuth settings of ADM

2026-07-30
CVE-2026-67243
Analyzed
8.6
Unknown freo2

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability

2026-08-04
CVE-2026-67208
Analyzed
9.8
Docker Juggle

An unauthenticated remote code execution vulnerability exists in somta Juggle through 1.6.0 due to exposed H2 database consoles with default credentia...

2026-07-31
CVE-2026-67207
Analyzed
8.8
CMS wolfcms

Wolf CMS through 0

2026-07-31
CVE-2026-67206
Analyzed
8.8
CMS wolfcms

Wolf CMS through 0

2026-07-31
CVE-2026-67201
Analyzed
8.6
Unknown v

V through 0

2026-07-30
CVE-2026-67195
Analyzed
8.8
Unknown perspective

Perspective 5

2026-08-05
CVE-2026-67192
Analyzed
8.1
Xlight Xlight FTP Server

Xlight FTP Server before 3

2026-07-30
CVE-2026-67191
Analyzed
9.8
Xlight Xlight FTP Server

A heap-based buffer overflow in Xlight FTP Server prior to 3.9.5 allows remote unauthenticated attackers to corrupt memory via a malformed SSH client...

2026-07-30
CVE-2026-66920
Analyzed
8.2
Pivotick Pivotick

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data

2026-07-29
CVE-2026-6692
8.8
WordPress is vulnerable

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7

2026-05-07
CVE-2026-66918
Analyzed
8.2
Pivotick Pivotick

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style

2026-07-29
CVE-2026-66915
Analyzed
10
Joomla Fabrik extension for Joomla

The Fabrik extension for Joomla is vulnerable to unauthenticated remote code execution via the ajax_calc feature of the calc plugin.

2026-08-11
CVE-2026-6691
Analyzed
7.8
SAP C Driver

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before...

2026-05-07
CVE-2026-66909
Analyzed
9.8
Apache Apache CXF

Apache CXF is vulnerable to remote code execution due to insecure native Java deserialization of inbound JMS ObjectMessages without type restrictions.

2026-08-06
CVE-2026-66898
Analyzed
9.9
Canonical LXD

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations, potentially lead...

2026-08-13
CVE-2026-66875
Analyzed
8.8
Quanovate Mira Firmware

In the Mira hormone monitor device firmware v1

2026-08-12
CVE-2026-66839
Analyzed
8.4
Unknown NetKids iMark

NetKids iMark, provided by Integrated Systems Technologies, Inc

2026-08-05
CVE-2026-66824
Analyzed
9.2
Unknown lookyloo

A stored cross-site scripting vulnerability in lookyloo allows attackers to inject malicious scripts into the capture tree visualization page, executi...

2026-07-28
CVE-2026-66808
Analyzed
8.8
Microsoft SharePoint

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-08-12
CVE-2026-66805
Analyzed
8.8
Microsoft SharePoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-08-12
CVE-2026-66803
Analyzed
10
Microsoft Azure Cosmos DB

Improper access control in Azure Cosmos DB allows an unauthenticated remote attacker to potentially execute arbitrary code.

2026-08-19
CVE-2026-66795
Analyzed
9.1
Red Hat Multicluster Engine for Kubernetes

Improper validation of Certificate Signing Requests in the managedcluster-import-controller allows privileged service accounts to escalate privileges...

2026-08-18
CVE-2026-66792
Analyzed
9.9
Red Hat Multicluster Global Hub

A privilege escalation vulnerability in the multicloud-operators-subscription component allows users to deploy resources with elevated permissions via...

2026-08-18
CVE-2026-6679
Analyzed
8.8
Unknown wolfSSL

A heap buffer overflow could occur in the DTLS 1

2026-06-26
CVE-2026-66780
Analyzed
9.9
Red Hat Advanced Cluster Management for Kubernetes

A flaw in the submariner-operator component allows a compromised cluster to perform MITM attacks across a cluster mesh by overwriting endpoint informa...

2026-08-19
CVE-2026-66763
Analyzed
7.9
Intel SAP BusinessObjects Business Intelligence Platform

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic...

2026-08-11
CVE-2026-66758
Analyzed
7.8
Red Hat GIMP (file-fits plugin)

A flaw was found in the file-fits plugin in GIMP

2026-07-28
CVE-2026-66748
Analyzed
8.8
GitHub camaleon-cms

Camaleon CMS versions 2

2026-07-29
CVE-2026-66747
Analyzed
9.8
Zbtlink CPE2801 Firmware

Multiple Zbtlink router models contain an embedded remote control implant that enables unauthenticated remote code execution with root privileges via...

2026-08-06
CVE-2026-66738
Analyzed
8.8
SPIP SPIP

SPIP before 4

2026-08-11
CVE-2026-66731
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66730
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66729
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66713
Analyzed
9.8
Apache Apache Axis2/Java

A deserialization vulnerability in the Apache Axis2/Java clustering component allows unauthenticated attackers to execute arbitrary code if the Tribes...

2026-07-29
CVE-2026-66710
Analyzed
8.1
HP e2pdf

Unauthenticated Local File Inclusion in e2pdf <= 1

2026-08-06
CVE-2026-66708
Analyzed
8.2
WordPress Total Upkeep

Unauthenticated Broken Access Control in Total Upkeep <= 1

2026-08-06
CVE-2026-66691
Analyzed
9.8
WordPress Nokri

A critical broken access control vulnerability exists in the scriptsbundle Nokri WordPress theme, which allows unauthenticated attackers to manipulate...

2026-08-14
CVE-2026-66665
Analyzed
10
WordPress Type Hub

An unauthenticated arbitrary file upload vulnerability exists in the Brandexponents Type Hub plugin for WordPress, allowing remote code execution.

2026-08-06
CVE-2026-66662
Analyzed
9.8
WordPress Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress contains an unauthenticated privilege escalation vulnerability caused by incorrect privilege ass...

2026-08-06
CVE-2026-6665
Analyzed
8.1
PgBouncer Multiple Products

The SCRAM code in PgBouncer before 1

2026-05-09
CVE-2026-6664
Analyzed
7.5
PgBouncer Multiple Products

An integer overflow in network packet parsing code in PgBouncer before 1

2026-05-10
CVE-2026-66627
Analyzed
9.9
WordPress GP Premium

GP Premium allows authenticated contributors to perform arbitrary file uploads, potentially leading to remote code execution.

2026-08-19
CVE-2026-6662
7.3
Unknown Multiple Products

A vulnerability was found in ericc-ch copilot-api up to 0

2026-04-21
CVE-2026-66602
Analyzed
8.8
WordPress HashBar – WordPress Notification Bar

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery

2026-08-19
CVE-2026-6659
7.5
Unknown Multiple Products

Crypt::PasswdMD5 versions through 1

2026-05-09
CVE-2026-6656
Analyzed
7.5
DRSTEVE Crypt::Password

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allow...

2026-07-23