18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 16951-17000 of 18466 CVEs Page 340 of 370
CVE-2024-58349
Analyzed
9.8
WordPress Theme Travelscape

WordPress Theme Travelscape 1.0.3 is susceptible to remote code execution due to insufficient validation of file uploads in the theme directory.

2026-06-08
CVE-2024-58348
Analyzed
9.8
WordPress Background Image Cropper

WordPress Background Image Cropper 1.2 allows unauthenticated attackers to execute arbitrary code via an insecure file upload endpoint.

2026-06-08
CVE-2024-58341
8.2
OpenCart Core

OpenCart Core 4

2026-03-26
CVE-2024-58338
Analyzed
9.8
Anevia Flamingo XL Multiple Products

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the tracer...

2025-12-31
CVE-2024-58337
7.5
Akuvox Multiple Products

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings an...

2025-12-31
CVE-2024-58336
Analyzed
9.8
Akuvox Smart Intercom Multiple Products

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video...

2025-12-31
CVE-2024-58316
7.5
Unknown Multiple Products

Online Shopping System Advanced 1

2025-12-13
CVE-2024-58315
8.4
Key Multiple Products

Tosibox Key Service 3

2025-12-31
CVE-2024-58314
Analyzed
8.8
Atcom Multiple Products

Atcom 100M IP Phones firmware version 2

2025-12-13
CVE-2024-58311
Analyzed
9.8
Intel Multiple Products

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique ide...

2025-12-13
CVE-2024-58305
Analyzed
8.8
WonderCMS Multiple Products

WonderCMS 4

2025-12-13
CVE-2024-58304
7.5
CART Multiple Products

SPA-CART CMS 1

2025-12-13
CVE-2024-58299
Analyzed
9.8
Unknown Multiple Products

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers c...

2025-12-13
CVE-2024-58274
8.3
Hikvision Multiple Products

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api...

2025-10-22
CVE-2024-58267
8
Rancher Multiple Products

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attack...

2025-10-02
CVE-2024-58260
7.6
Rancher Multiple Products

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `

2025-10-02
CVE-2024-58259
Analyzed
8.2
Kubernetes Multiple Products

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated)...

2025-09-02
CVE-2024-58258
Analyzed
7.2
SugarCRM Multiple Products

SugarCRM before 13

2025-07-14
CVE-2024-58041
Analyzed
9.1
Unknown Smolder (Perl)

Smolder versions through 1.51 use the insecure Perl rand() function for cryptographic operations. This lack of cryptographically secure entropy weaken...

2026-02-25
CVE-2024-58040
Analyzed
9.1
Intel Multiple Products

Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.

2025-09-30
CVE-2024-57728
KEV
9.5
SimpleHelp SimpleHelp

SimpleHelp Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-25
CVE-2024-57726
KEV
9.5
SimpleHelp SimpleHelp

SimpleHelp Missing Authorization Vulnerability - Active in CISA KEV catalog.

2026-04-25
CVE-2024-57695
7.7
Unknown Multiple Products

An issue in Agnitum Outpost Security Suite 7

2025-11-13
CVE-2024-57521
Analyzed
10
Intel Multiple Products

SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.jav...

2025-12-24
CVE-2024-57491
8.8
Unknown Multiple Products

Authentication Bypass vulnerability in jobx up to v1

2025-08-20
CVE-2024-57157
Analyzed
9.8
Unknown Multiple Products

Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.

2025-08-21
CVE-2024-57155
Analyzed
9.8
Unknown Multiple Products

Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.

2025-08-21
CVE-2024-57154
Analyzed
9.8
Unknown Multiple Products

Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

2025-08-21
CVE-2024-57152
7.5
Unknown Multiple Products

Incorrect access control in the preHandle function of my-site v1

2025-08-21
CVE-2024-56836
7.5
Unknown Multiple Products

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2

2025-12-11
CVE-2024-56835
8.8
Unknown Multiple Products

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2

2025-12-10
CVE-2024-56808
7.8
Unknown Multiple Products

A command injection vulnerability has been reported to affect Media Streaming add-on

2026-02-13
CVE-2024-56373
8.4
Infor Multiple Products

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server...

2026-02-25
CVE-2024-56190
Analyzed
7.8
Unknown Multiple Products

In wl_update_hidden_ap_ie() of wl_cfgscan

2025-09-04
CVE-2024-56189
Analyzed
7.5
Unknown Multiple Products

In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec

2025-09-04
CVE-2024-56179
Analyzed
7.8
Microsoft Multiple Products

In MindManager Windows versions prior to 24

2025-08-23
CVE-2024-56143
Analyzed
8.2
Strapi Multiple Products

Strapi is an open-source headless content management system

2025-10-16
CVE-2024-56089
7.5
Unknown Multiple Products

An issue in Technitium through v13

2025-12-02
CVE-2024-55568
Analyzed
7.5
Samsung Multiple Products

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 240...

2025-10-20
CVE-2024-55270
8.8
HP Multiple Products

phpgurukul Student Management System 1

2026-02-18
CVE-2024-55027
7.5
Weintek Multiple Products

Weintek cMT-3072XH2 easyweb v2

2026-03-05
CVE-2024-55024
8.8
Unknown Multiple Products

An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2

2026-03-04
CVE-2024-55022
8.8
Weintek Multiple Products

Weintek cMT-3072XH2 easyweb v2

2026-03-05
CVE-2024-55021
7.5
Weintek Multiple Products

Weintek cMT-3072XH2 easyweb v2

2026-03-05
CVE-2024-55020
Analyzed
9.8
Unknown cMT-3072XH2 (easyweb)

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 allows attackers to execute arbitrary commands with root privi...

2026-03-04
CVE-2024-55019
7.5
Unknown Multiple Products

Incorrect access control in the component download_wb

2026-03-05
CVE-2024-55017
Analyzed
7.5
Account Multiple Products

Account Takeover in Corezoid 6

2025-09-30
CVE-2024-54678
8.2
Unknown Multiple Products

A vulnerability has been identified in SIMATIC PCS neo V4

2025-08-12
CVE-2024-54263
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allow...

2026-02-02
CVE-2024-54085
KEV Analyzed
9.5
AMI MegaRAC SPx

AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.

2025-07-10