18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 17101-17150 of 18466 CVEs Page 343 of 370
CVE-2024-32643
7.5
Masa Multiple Products

Masa CMS is an open source Enterprise Content Management platform

2025-12-03
CVE-2024-32642
8.8
Masa Multiple Products

Masa CMS is an open source Enterprise Content Management platform

2025-12-03
CVE-2024-32641
Analyzed
9.8
Unknown Multiple Products

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code e...

2025-12-03
CVE-2024-32640
Analyzed
9.8
Unknown Multiple Products

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.6, 7.3.13, and 7.2.8 contain a SQL inject...

2025-08-11
CVE-2024-32537
7.1
Adobe Multiple Products

Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery

2026-03-22
CVE-2024-32444
Analyzed
9.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege Escalation.This issue affects RealHomes: from n/a through 4.3...

2025-09-03
CVE-2024-32011
8.8
Spectrum Multiple Products

A vulnerability has been identified in Spectrum Power 4 (All versions < V4

2025-11-13
CVE-2024-32010
7.8
Spectrum Multiple Products

A vulnerability has been identified in Spectrum Power 4 (All versions < V4

2025-11-13
CVE-2024-32009
7.8
Spectrum Multiple Products

A vulnerability has been identified in Spectrum Power 4 (All versions < V4

2025-11-13
CVE-2024-32008
7.8
Spectrum Multiple Products

A vulnerability has been identified in Spectrum Power 4 (All versions < V4

2025-11-13
CVE-2024-31854
8.1
Unknown Multiple Products

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07

2025-07-10
CVE-2024-31853
8.1
Unknown Multiple Products

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07

2025-07-10
CVE-2024-31328
8.8
Unknown Multiple Products

In broadcastIntentLockedTraced of BroadcastController

2026-03-03
CVE-2024-30547
7.1
Shazdeh Header Image Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Header Image Slider header-image-...

2026-01-07
CVE-2024-30516
7.5
Unknown Multiple Products

Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functionality Not Properly Constraine...

2026-01-06
CVE-2024-30461
7.1
Tumult Inc Tumult Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc Tumult Hype Animations allows...

2026-01-06
CVE-2024-30151
8.3
Unknown Multiple Products

HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation

2026-05-07
CVE-2024-29371
7.5
Unknown Multiple Products

In jose4j before 0

2025-12-18
CVE-2024-28988
Analyzed
9.8
Unknown Multiple Products

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an...

2025-09-02
CVE-2024-27708
Analyzed
9.6
Unknown Multiple Products

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via t...

2025-12-23
CVE-2024-27686
7.5
MikroTik RouterOS

Mikrotik RouterOS (x86) 6

2026-05-09
CVE-2024-27199
KEV
9.5
JetBrains TeamCity

JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-21
CVE-2024-26480
7.5
Infor Multiple Products

An issue in Statping-ng v

2026-02-13
CVE-2024-26477
7.5
Infor Multiple Products

An issue in Statping-ng v

2026-02-13
CVE-2024-26009
Analyzed
8.1
Apple Multiple Products

An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS version 6

2025-08-12
CVE-2024-25621
7.3
Unknown Multiple Products

containerd is an open-source container runtime

2025-11-06
CVE-2024-25183
7.5
Unknown Multiple Products

givanz VvvebJs 1

2025-12-31
CVE-2024-24909
Analyzed
8.8
Microsoft OpenManage Integration with Microsoft Windows Admin Center

Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin

2026-06-17
CVE-2024-24844
7.5
IdeaBox Creations Multiple Products

Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security...

2025-12-24
CVE-2024-2374
7.5
Unknown Multiple Products

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entitie...

2026-04-17
CVE-2024-23564
Analyzed
9.1
HCL Software Aftermarket EPC

HCL Aftermarket EPC contains a business logic flaw that allows unauthenticated users to retrieve passwords from the server and redirect them to attack...

2026-07-18
CVE-2024-2356
Analyzed
9.6
Unknown Multiple Products

A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within...

2026-02-02
CVE-2024-21947
7.5
Unknown Multiple Products

Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in...

2025-09-07
CVE-2024-21923
Analyzed
7.3
AMD Multiple Products

Incorrect default permissions in AMD StoreMIâ„¢ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code executio...

2025-11-23
CVE-2024-21922
Analyzed
7.3
AMD Multiple Products

A DLL hijacking vulnerability in AMD StoreMIâ„¢ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code executi...

2025-11-23
CVE-2024-21182
KEV Analyzed
9.5
Oracle WebLogic Server

Oracle WebLogic Server contains an unspecified vulnerability that is currently being exploited in the wild.

2026-06-02
CVE-2024-2104
8.8
GATT Multiple Products

Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control comman...

2025-12-11
CVE-2024-1708
KEV
9.5
ConnectWise ScreenConnect

ConnectWise ScreenConnect Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-29
CVE-2024-1524
7.7
Infor Multiple Products

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's...

2026-02-24
CVE-2024-14037
Analyzed
9.8
Unknown Red Sea Cloud eHR

Guangzhou Red Sea Cloud eHR contains an arbitrary file upload vulnerability in the PtFjk.mob servlet, allowing unauthenticated attackers to achieve re...

2026-07-03
CVE-2024-14034
Analyzed
9.8
Unknown HiEOS

An authentication bypass in the Hirschmann HiEOS HTTP(S) management module allows unauthenticated attackers to gain administrative access and modify d...

2026-04-03
CVE-2024-14033
Analyzed
7.5
HiLCOS web Multiple Products

Hirschmann Industrial IT products (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) contain a heap overflow vulnerability in t...

2026-04-03
CVE-2024-14032
7.8
Studio Multiple Products

Twitch Studio version 0

2026-04-07
CVE-2024-14031
8.1
Unknown Multiple Products

Sereal::Encoder versions from 4

2026-04-01
CVE-2024-14030
8.1
Unknown Multiple Products

Sereal::Decoder versions from 4

2026-04-01
CVE-2024-14015
Analyzed
7.1
WordPress Multiple Products

The WordPress eCommerce Plugin WordPress plugin through 2

2025-11-25
CVE-2024-14010
Analyzed
9.8
HP Multiple Products

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Atta...

2025-12-13
CVE-2024-13974
8.1
Unknown Multiple Products

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21

2025-07-22
CVE-2024-13972
Analyzed
8.8
Microsoft Multiple Products

A vulnerability related to registry permissions in the Intercept X for Windows updater prior to version 2024

2025-07-17
CVE-2024-13807
Analyzed
7.5
WordPress Multiple Products

The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7

2025-08-28