20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 1701-1750 of 20297 CVEs Page 35 of 406
CVE-2026-6161
7.3
HP of the

A vulnerability was determined in code-projects Simple ChatBox up to 1

2026-04-13
CVE-2026-6158
7.3
TOTOLINK Multiple Products

A flaw has been found in Totolink N300RH 6

2026-04-13
CVE-2026-6157
8.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink A800R 4

2026-04-13
CVE-2026-6156
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU allows remote OS command injection via the setIpQosRules function in the CGI handler.

2026-04-13
CVE-2026-6155
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU is vulnerable to remote OS command injection via the setWanCfg function in the CGI handler.

2026-04-13
CVE-2026-6154
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU allows remote OS command injection via the setWizardCfg function within the CGI handler.

2026-04-13
CVE-2026-6153
7.3
HP Multiple Products

A vulnerability was identified in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6152
7.3
HP Multiple Products

A vulnerability was determined in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-61515
Analyzed
9.8
Puwell Technology IP Camera

Puwell IP Camera firmware versions 2.x through 4.x contain an unauthenticated command injection vulnerability in the DebugShell interface on TCP port...

2026-08-05
CVE-2026-61514
Analyzed
9.8
Puwell Technology IP Camera

Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability, allowing unauthenticated attackers to control devic...

2026-08-05
CVE-2026-61511
Analyzed
9.8
HP vBulletin

vBulletin contains an eval injection vulnerability in the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code...

2026-07-28
CVE-2026-6151
7.3
HP Multiple Products

A vulnerability was found in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-61500
Analyzed
9.8
Rejetto HFS

Rejetto HFS uses a predictable PRNG for session-cookie signing, allowing unauthenticated attackers to forge administrator session cookies and achieve...

2026-07-14
CVE-2026-61498
Analyzed
9.8
HP Flamingo

Vitec Flamingo 4.12.2 is susceptible to unauthenticated OS command injection via the admin/ajax/gen_graphs.php endpoint due to insufficient input sani...

2026-07-14
CVE-2026-6149
Analyzed
7.3
HP Vehicle Showroom Management System

A flaw has been found in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6148
Analyzed
7.3
HP Vehicle Showroom Management System

A vulnerability was detected in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6147
Analyzed
8.8
WordPress LightSync Pro

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functio...

2026-08-05
CVE-2026-61463
Analyzed
8.8
Unknown shiori

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without...

2026-07-14
CVE-2026-61462
Analyzed
8.6
GitLab mcp-gitlab

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index

2026-07-14
CVE-2026-61461
Analyzed
8.8
LangGenius Dify

Dify before 1

2026-07-11
CVE-2026-61460
Analyzed
8.8
Krayin Laravel-CRM

Krayin CRM through 2

2026-07-11
CVE-2026-61459
Analyzed
9.8
Kubernetes mcp-server-kubernetes

Flux159 mcp-server-kubernetes before 3.9.0 is susceptible to argument injection, allowing attackers to redirect kubectl commands and steal bearer toke...

2026-07-11
CVE-2026-61458
Analyzed
7.5
PasswordPusher PasswordPusher

PasswordPusher before 2

2026-07-14
CVE-2026-61457
Analyzed
8.8
Unknown grav

The Grav API plugin (getgrav/grav-plugin-api) before 1

2026-07-16
CVE-2026-61451
Analyzed
9.6
Unknown grav

The Grav API plugin is vulnerable to an open redirect during password reset, allowing attackers to hijack reset tokens and perform full account takeov...

2026-07-16
CVE-2026-61447
Analyzed
10
MervinPraison PraisonAI

PraisonAI contains a remote code execution vulnerability in CodeAgent._execute_python() that allows attackers to execute arbitrary code via LLM prompt...

2026-07-12
CVE-2026-61446
Analyzed
8.4
MervinPraison PraisonAI

PraisonAI (praisonaiagents) before 1

2026-07-17
CVE-2026-61445
Analyzed
9.9
MervinPraison PraisonAI

PraisonAI is vulnerable to arbitrary file write and command execution via the AICoder component due to missing path and command validation in LLM tool...

2026-07-12
CVE-2026-61444
Analyzed
9.1
MervinPraison PraisonAI

PraisonAI contains a code injection vulnerability in its API module where unsanitized user input is passed to subprocess.Popen(), allowing arbitrary c...

2026-07-11
CVE-2026-61442
Analyzed
7.1
MervinPraison PraisonAI

PraisonAI Platform (praisonai-platform) before 0

2026-07-13
CVE-2026-61439
Analyzed
7.5
MervinPraison PraisonAI

PraisonAI versions before 4

2026-07-12
CVE-2026-61437
Analyzed
7.8
MervinPraison PraisonAI

PraisonAI (pip package praisonaiagents) before 1

2026-07-11
CVE-2026-61436
Analyzed
8.6
MervinPraison PraisonAI

PraisonAI before 4

2026-07-17
CVE-2026-61435
Analyzed
8.2
MervinPraison PraisonAI

PraisonAI before 4

2026-07-17
CVE-2026-61434
Analyzed
8.8
MervinPraison PraisonAI

PraisonAI versions before 4

2026-07-11
CVE-2026-61430
Analyzed
8.5
MervinPraison PraisonAI

PraisonAI before 1

2026-07-17
CVE-2026-61429
Analyzed
8.5
MervinPraison PraisonAI

PraisonAI versions before 1

2026-07-12
CVE-2026-61428
Analyzed
7.3
MervinPraison PraisonAI

PraisonAI AgentMail versions before 4

2026-07-12
CVE-2026-61426
Analyzed
8.6
Intel PraisonAI

PraisonAI before 1

2026-07-12
CVE-2026-61424
Analyzed
10
Joomla DJ-Classifieds extension for Joomla

The DJ-Classifieds extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote cod...

2026-07-21
CVE-2026-6142
Analyzed
7.3
F5 Hotel Management System

A vulnerability was identified in tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15

2026-04-13
CVE-2026-6140
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU is susceptible to remote OS command injection via the UploadFirmwareFile function in the CGI handler.

2026-04-13
CVE-2026-61390
Analyzed
7.7
Hikvision DS-2CD and DS-2DE Series Cameras

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by send...

2026-07-24
CVE-2026-6139
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU contains an OS command injection vulnerability in the UploadOpenVpnCert function of the CGI handler.

2026-04-13
CVE-2026-6138
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU is vulnerable to remote OS command injection via the setAccessDeviceCfg function in the CGI handler.

2026-04-13
CVE-2026-61376
Analyzed
8.6
ELECOM WAB-M1775-PS, WAB-S1775, WAB-M2133, WAB-I1750-PS, WAB-S1167-PS

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings

2026-07-29
CVE-2026-61372
Analyzed
7.5
Apache Jena Fuseki

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki

2026-08-04
CVE-2026-6137
8.8
Tenda F451

A vulnerability was detected in Tenda F451 1

2026-04-13
CVE-2026-6136
8.8
Tenda F451

A security vulnerability has been detected in Tenda F451 1

2026-04-13
CVE-2026-6135
8.8
Tenda F451

A weakness has been identified in Tenda F451 1

2026-04-13