23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 1801-1850 of 23295 CVEs Page 37 of 466
CVE-2026-73332
Analyzed
8.7
Unknown CamaleonCMS

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to...

2026-08-14
CVE-2026-73329
Analyzed
8.7
Unknown CamaleonCMS

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an...

2026-08-14
CVE-2026-7332
Analyzed
7.2
WordPress is vulnerable

The LatePoint โ€“ Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking...

2026-05-06
CVE-2026-73305
Analyzed
8.8
Budibase Budibase

Budibase is an open-source low-code platform

2026-08-14
CVE-2026-73299
Analyzed
10
Microsoft Prompty

Microsoft Prompty is vulnerable to code injection due to improper template evaluation, allowing unauthenticated attackers to execute arbitrary JavaScr...

2026-08-13
CVE-2026-73298
Analyzed
8.7
Microsoft Container-Migration-Solution-Accelerator

The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for mo...

2026-08-14
CVE-2026-73294
Analyzed
9.9
Unknown semaphore

Semaphore UI is vulnerable to OS command injection via improper handling of git_url parameters in the API, allowing authenticated project managers or...

2026-08-13
CVE-2026-73293
Analyzed
8.8
Unknown semaphore

Semaphore UI is a web interface for managing DevOps tools

2026-08-13
CVE-2026-7329
Analyzed
9.9
Progress Software MarkLogic Server

Progress MarkLogic Server contains an improper privilege management vulnerability in its query interfaces allowing authenticated users with low-privil...

2026-08-06
CVE-2026-73284
Analyzed
8.8
Unknown rustfs

RustFS is a distributed object storage system built in Rust

2026-08-13
CVE-2026-7327
Analyzed
8.1
Progress MarkLogic Server

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11

2026-08-06
CVE-2026-73263
Analyzed
9.9
Kubernetes prowler

Prowler is vulnerable to OS command injection via the Kubernetes provider connection test, allowing authenticated users to execute arbitrary commands...

2026-08-13
CVE-2026-73226
Analyzed
8.8
Unknown electerm

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

2026-08-12
CVE-2026-73224
Analyzed
8.8
Unknown electerm

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

2026-08-12
CVE-2026-73222
Analyzed
8.8
Unknown claude-code-templates

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code

2026-08-12
CVE-2026-73220
Analyzed
8.5
CVAT-AI CVAT

CVAT is an open source interactive video and image annotation tool for computer vision

2026-08-22
CVE-2026-73211
Analyzed
9.8
Chocobozzz PeerTube

An SQL injection vulnerability in the PeerTube ActorFollowModel allows unauthenticated remote servers to execute arbitrary database queries and take o...

2026-08-12
CVE-2026-7321
Analyzed
9.6
Mozilla Firefox, Thunderbird

A sandbox escape vulnerability in the WebRTC networking component allows attackers to bypass security boundaries.

2026-04-29
CVE-2026-7320
Analyzed
7.5
Infor Multiple Products

Information disclosure due to incorrect boundary conditions in the Audio/Video component

2026-04-29
CVE-2026-73160
Analyzed
8.7
MISP cti-transmute

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints

2026-08-12
CVE-2026-7313
Analyzed
8.7
Progress Sitefinity

CWEโ€‘522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8

2026-06-04
CVE-2026-73125
Analyzed
9.8
Ebyte NE2-D11 Firmware

The web management interface of Ebyte NE2-D11 firmware fails to enforce authentication, allowing unauthenticated remote attackers to modify device set...

2026-08-28
CVE-2026-7312
Analyzed
10
Progress Sitefinity

Progress Sitefinity web services contain a vulnerability that allows unauthenticated remote attackers to retrieve plain-text credentials for the Sitef...

2026-06-03
CVE-2026-7311
Analyzed
8.1
WordPress JPEG, PNG & WebP image compression plugin

The TinyPNG โ€“ JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio...

2026-07-03
CVE-2026-73081
Analyzed
8.7
Activepieces Activepieces

Activepieces is an open source AI workflow automation platform

2026-08-12
CVE-2026-7307
Analyzed
7.5
Unknown Multiple Products

A flaw was found in Keycloak

2026-05-20
CVE-2026-73062
Analyzed
7.5
Scriban Scriban

Scriban versions 3

2026-08-17
CVE-2026-73061
Analyzed
9.8
Unknown scriban

The Scriban template engine contains an access-modifier bypass vulnerability in TypedObjectAccessor, allowing unauthenticated attackers to perform una...

2026-08-17
CVE-2026-73060
Analyzed
7.5
Scriban Scriban

Scriban versions from 3

2026-08-17
CVE-2026-73057
Analyzed
7.5
Unknown stoatchat

stoatchat before 0

2026-08-17
CVE-2026-73056
Analyzed
9.8
Unknown siyuan

The SiYuan kernel before 3.7.4 fails to restrict excessive authentication attempts, allowing unauthenticated attackers to brute-force API tokens and g...

2026-08-17
CVE-2026-73054
Analyzed
7.5
SiYuan SiYuan

SiYuan versions before v3

2026-08-16
CVE-2026-73053
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 are susceptible to cross-site scripting in the unicode2Emoji function, allowing arbitrary code execution in the renderer.

2026-08-16
CVE-2026-73052
Analyzed
9
Unknown siyuan

A stored cross-site scripting vulnerability in SiYuan allows authenticated attackers to execute arbitrary JavaScript by injecting malicious markup int...

2026-08-16
CVE-2026-73050
Analyzed
9
Unknown siyuan

SiYuan before v3.7.4 contains a stored Cross-site Scripting vulnerability in the attribute-view select option color field, allowing arbitrary JavaScri...

2026-08-16
CVE-2026-73046
Analyzed
9.8
Unknown siyuan

The SiYuan CheckAuth middleware fails to enforce rate limiting or account lockout for HTTP Basic Authentication, allowing unauthenticated attackers to...

2026-08-16
CVE-2026-73045
Analyzed
7.5
SiYuan SiYuan

SiYuan before 3

2026-08-16
CVE-2026-73044
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 are vulnerable to stored cross-site scripting via the setAttrViewColWidth API, which can lead to arbitrary code execution...

2026-08-16
CVE-2026-73043
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 contain a remote code execution vulnerability in the Template calculation operator, allowing execution of arbitrary code...

2026-08-16
CVE-2026-73042
Analyzed
9
Unknown siyuan

SiYuan before v3.7.4 is vulnerable to stored Cross-site Scripting via improperly escaped database menu metadata, allowing execution of arbitrary code...

2026-08-16
CVE-2026-73041
Analyzed
9
Unknown siyuan

SiYuan versions before 3.7.4 allow arbitrary code execution via malicious PDF annotations that trigger script execution in the PDF renderer with Node....

2026-08-16
CVE-2026-73040
Analyzed
8.8
Unknown dockge

Dockge validates a stack name only on the write path

2026-08-21
CVE-2026-7304
Analyzed
9.8
SGLangs Multimodal Generation Runtime

The SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when custom logit processing is enabled, due to unsaf...

2026-05-19
CVE-2026-73034
Analyzed
9.8
Unknown DB-GPT

DB-GPT v0.8.1 is vulnerable to an unauthenticated path traversal attack that allows remote attackers to write arbitrary files to the server via the us...

2026-08-12
CVE-2026-73031
Analyzed
8.7
GramSearch telegram-search

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers...

2026-08-12
CVE-2026-73030
Analyzed
8.1
Unknown unearth

unearth through 0

2026-08-11
CVE-2026-7302
Analyzed
9.1
SGLangs Multimodal Generation Runtime

The SGLangs runtime is vulnerable to an unauthenticated path traversal attack, allowing remote attackers to write arbitrary files to the server's file...

2026-05-19
CVE-2026-7301
Analyzed
9.8
SGLangs Multimodal Generation Runtime

The SGLangs scheduler binds its ROUTER socket to 0.0.0.0 and performs unsafe pickle deserialization on incoming messages, enabling unauthenticated rem...

2026-05-19
CVE-2026-72984
Analyzed
8.8
Microsoft Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2026-08-29
CVE-2026-72970
Analyzed
8.3
Microsoft Microsoft Edge (Chromium-based)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-08-16