21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 1751-1800 of 21637 CVEs Page 36 of 433
CVE-2026-65592
Analyzed
8.4
Unknown n8n

n8n before 1

2026-07-24
CVE-2026-65591
Analyzed
8.9
Unknown n8n

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler

2026-07-23
CVE-2026-65581
Analyzed
9.8
HP AI ANN

A critical PHP Object Injection vulnerability exists in the Axiomthemes AI ANN theme, allowing unauthenticated attackers to potentially execute arbitr...

2026-08-06
CVE-2026-65579
Analyzed
9.8
HP Agricola

An unauthenticated PHP Object Injection vulnerability exists in the axiomthemes Agricola theme, specifically affecting versions 1.21.0 and earlier.

2026-08-06
CVE-2026-65578
Analyzed
9.8
HP Agora

An unauthenticated PHP Object Injection vulnerability exists in AncoraThemes Agora versions 1.9 and earlier, allowing for potential remote code execut...

2026-08-06
CVE-2026-65577
Analyzed
9.8
HP Advice

The AncoraThemes Advice WordPress theme contains an unauthenticated PHP Object Injection flaw that could allow remote attackers to execute arbitrary c...

2026-08-06
CVE-2026-65576
Analyzed
9.8
HP Adrena

The AncoraThemes Adrena WordPress theme is susceptible to unauthenticated PHP Object Injection, enabling remote attackers to execute arbitrary code by...

2026-08-06
CVE-2026-65575
Analyzed
9.8
HP Accalia

The AncoraThemes Accalia WordPress theme is vulnerable to unauthenticated PHP Object Injection, allowing remote code execution via deserialization of...

2026-08-06
CVE-2026-65574
Analyzed
9.8
HP Abogado

The AncoraThemes Abogado WordPress theme contains an unauthenticated PHP object injection vulnerability, which could lead to remote code execution.

2026-08-06
CVE-2026-65573
Analyzed
9.8
HP Abelle

The ThemeREX Abelle WordPress theme is susceptible to unauthenticated PHP object injection, potentially enabling remote code execution.

2026-08-06
CVE-2026-65572
Analyzed
9.8
HP A.Williams

The Axiomthemes A.Williams WordPress theme is vulnerable to unauthenticated PHP object injection, which may allow remote code execution.

2026-08-06
CVE-2026-65571
Analyzed
9.8
HP 69 Clothing

The 69 Clothing WordPress theme is affected by an unauthenticated PHP object injection vulnerability, which enables attackers to execute arbitrary cod...

2026-08-06
CVE-2026-65570
Analyzed
8.1
WordPress Login with phone number

Unauthenticated Bypass Vulnerability in Login with phone number <= 1

2026-08-06
CVE-2026-65569
Analyzed
8.5
WordPress WP Job Portal

Subscriber SQL Injection in WP Job Portal <= 2

2026-08-06
CVE-2026-65556
Analyzed
9.8
HP WPBruiser {no- Captcha anti-Spam}

The WPBruiser {no- Captcha anti-Spam} WordPress plugin is vulnerable to unauthenticated PHP object injection, enabling attackers to execute arbitrary...

2026-08-06
CVE-2026-65553
Analyzed
10
WordPress Spider Analyser

The Spider Analyser WordPress plugin contains an unauthenticated Remote Code Execution vulnerability, allowing attackers to execute arbitrary code on...

2026-08-06
CVE-2026-65552
Analyzed
9.8
HP Export User Data

The Export User Data WordPress plugin is vulnerable to PHP object injection, which allows unauthenticated attackers to execute arbitrary code or manip...

2026-08-06
CVE-2026-6555
Analyzed
9.8
WordPress is vulnerable

The ProSolution WP Client WordPress plugin is vulnerable to arbitrary file upload due to improper validation of the upload array, allowing remote code...

2026-05-20
CVE-2026-65548
Analyzed
9.9
WordPress Betheme

A critical remote code execution vulnerability exists in the Betheme WordPress theme, allowing authenticated contributors to execute arbitrary code on...

2026-08-06
CVE-2026-65547
Analyzed
8.5
WordPress Creative Mail

Subscriber SQL Injection in Creative Mail <= 1

2026-08-06
CVE-2026-65542
Analyzed
8.8
WordPress Super Socializer

Unauthenticated Broken Authentication in Super Socializer <= 7

2026-08-06
CVE-2026-65532
Analyzed
7.6
PersianScript Persian Woocommerce SMS

Shop manager SQL Injection in Persian Woocommerce SMS <= 7

2026-07-24
CVE-2026-65526
Analyzed
8.5
WordPress Visualizer

Contributor SQL Injection in Visualizer <= 4

2026-07-24
CVE-2026-6552
Analyzed
8.7
GitLab GitLab EE

GitLab has remediated an issue in GitLab EE affecting all versions from 15

2026-06-12
CVE-2026-65507
Analyzed
9.8
WordPress AIWU

The AIWU plugin for WordPress is susceptible to an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment.

2026-08-06
CVE-2026-65471
Analyzed
9.6
WordPress Avada Core

Avada Core versions 5.15.6 and below are vulnerable to an unauthenticated Cross-Site Request Forgery (CSRF) attack, potentially leading to unauthorize...

2026-07-24
CVE-2026-65462
Analyzed
7.6
WordPress Uncanny Automator

Administrator SQL Injection in Uncanny Automator <= 7

2026-07-24
CVE-2026-65454
Analyzed
8.5
WordPress Quiz And Survey Master

Contributor SQL Injection in Quiz And Survey Master <= 11

2026-07-24
CVE-2026-65451
Analyzed
8.5
WordPress MapSVG

Contributor SQL Injection in MapSVG <= 8

2026-07-24
CVE-2026-65450
Analyzed
8.5
WordPress MapSVG

Contributor SQL Injection in MapSVG <= 8

2026-07-24
CVE-2026-65442
Analyzed
7.2
WordPress FormCraft

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3

2026-07-28
CVE-2026-65431
Analyzed
9.8
Joomla GeoIP extension for Joomla

A path traversal vulnerability in the Regular Labs GeoIP extension for Joomla allows for arbitrary file writes during the extraction of database updat...

2026-08-02
CVE-2026-65430
Analyzed
7.5
Joomla GeoIP extension for Joomla

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a crede...

2026-08-02
CVE-2026-6543
8.8
IBM Langflow Desktop

IBM Langflow Desktop 1

2026-05-01
CVE-2026-65423
Analyzed
8.8
GitHub open62541

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write

2026-07-31
CVE-2026-65400
KEV Analyzed
9.5
Apple macOS

An improper authentication flaw in Apple macOS Screen Sharing allows unauthenticated network attackers to bypass credentials and gain remote access.

2026-08-19
CVE-2026-6540
Analyzed
7.9
Tigera Calico

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization

2026-08-01
CVE-2026-65321
Analyzed
9.8
Unknown PyAthena

An SQL injection vulnerability in PyAthena versions prior to 3.35.4 allows unauthenticated attackers to execute arbitrary SQL commands due to improper...

2026-08-03
CVE-2026-65313
Analyzed
8.1
ANDRITZ HIPASE-250

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password

2026-08-01
CVE-2026-65310
Analyzed
7.5
ANDRITZ HIPASE-250

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any au...

2026-08-01
CVE-2026-65309
Analyzed
7.5
ANDRITZ HIPASE-250

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way passwo...

2026-08-01
CVE-2026-6518
8.8
WordPress is vulnerable

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all...

2026-04-18
CVE-2026-6516
Analyzed
10
Zohocorp ManageEngine ADAudit Plus

ManageEngine ADAudit Plus is vulnerable to unauthenticated remote code execution due to a flaw in the agent API, which fails to properly neutralize OS...

2026-07-24
CVE-2026-6512
Analyzed
9.1
WordPress is vulnerable

The InfusedWoo Pro plugin for WordPress is vulnerable to an authorization bypass that allows unauthenticated attackers to perform destructive actions...

2026-05-15
CVE-2026-6510
Analyzed
9.8
WordPress is vulnerable

The InfusedWoo Pro WordPress plugin is vulnerable to authentication bypass and privilege escalation via an insecure AJAX handler.

2026-05-14
CVE-2026-6509
Analyzed
7.8
TUBITAK BILGEM Pardus Update

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation

2026-07-06
CVE-2026-6508
Analyzed
9.8
Arch Institute Liderahenk

Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properl...

2026-05-08
CVE-2026-6507
7.5
Unknown Multiple Products

A flaw was found in dnsmasq

2026-04-18
CVE-2026-6506
Analyzed
8.8
WordPress is vulnerable

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5

2026-05-14
CVE-2026-65016
Analyzed
7.7
Unknown n8n

n8n versions before 1

2026-07-24