23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 1901-1950 of 23391 CVEs Page 39 of 468
CVE-2026-72984
Analyzed
8.8
Microsoft Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2026-08-29
CVE-2026-72970
Analyzed
8.3
Microsoft Microsoft Edge (Chromium-based)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-08-16
CVE-2026-72920
Analyzed
9.8
Unknown seaweedfs

SeaweedFS prior to 4.24 fails to enforce authentication on the gRPC IdentityAccessManagement service when the signing key is unset, allowing unauthori...

2026-08-12
CVE-2026-72915
Analyzed
7.5
Mastodon Mastodon

Mastodon is a free, open-source social network server based on ActivityPub

2026-08-11
CVE-2026-72914
Analyzed
7.5
Mastodon Mastodon

Mastodon is a free, open-source social network server based on ActivityPub

2026-08-11
CVE-2026-72913
Analyzed
7.3
Unknown kitty

Kitty is a cross-platform GPU based terminal

2026-08-11
CVE-2026-72911
Analyzed
9.9
Unknown erpnext

ERPNext contains a template injection vulnerability that allows authenticated users to execute arbitrary server-side code by manipulating template par...

2026-08-11
CVE-2026-72904
Analyzed
9.3
Unknown firecrawl

An arbitrary file read and SSRF vulnerability in Firecrawl prior to 2.11.32 allows unauthenticated attackers to read local files via malicious JSON sc...

2026-08-11
CVE-2026-72903
Analyzed
8.1
Eugeny tabby

Tabby (formerly Terminus) is a highly configurable terminal emulator

2026-08-11
CVE-2026-72902
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection via the registry testing functions, allowing authenticated users to execute arb...

2026-08-11
CVE-2026-72901
Analyzed
9.9
Docker dokploy

Dokploy versions prior to 0.29.13 are susceptible to OS command injection via the volume backup functionality, allowing authenticated low-privilege us...

2026-08-11
CVE-2026-72899
Analyzed
10
Metabase Metabase

Metabase contains an SQL injection vulnerability allowing unauthenticated attackers to execute arbitrary SQL commands via manipulated field-filter par...

2026-08-11
CVE-2026-72898
KEV Analyzed
10
Metabase Metabase

Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full admi...

2026-08-11
CVE-2026-7289
Analyzed
8.8
D-Link DIR

A vulnerability was found in D-Link DIR-825M 1

2026-04-29
CVE-2026-72887
Analyzed
9.8
Net::OAuth Net::OAuth::Client

A security flaw in Net::OAuth::Client allows service providers to silently downgrade OAuth 1.0a to the less secure OAuth 1.0 protocol.

2026-08-26
CVE-2026-72886
Analyzed
9.9
Dokploy dokploy

An improper privilege management vulnerability in Dokploy allows authenticated users to escalate privileges and execute arbitrary scripts as root on t...

2026-08-11
CVE-2026-72884
Analyzed
8.7
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72883
Analyzed
8.8
Dokploy Dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72882
Analyzed
9.9
Dokploy dokploy

Dokploy versions 0.28.8 and earlier are vulnerable to OS command injection via the filePath parameter, allowing authenticated users to execute arbitra...

2026-08-11
CVE-2026-72880
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 contain an arbitrary file write and deletion vulnerability due to improper input validation in the certificate managem...

2026-08-11
CVE-2026-7288
Analyzed
8.8
D-Link DIR

A vulnerability has been found in D-Link DIR-825M 1

2026-04-29
CVE-2026-72879
Analyzed
9.4
Dokploy dokploy

Dokploy versions prior to 0.29.8 are vulnerable to OS command injection via the getRegistryCommands function, allowing authenticated users to execute...

2026-08-11
CVE-2026-72878
Analyzed
9.6
Dokploy dokploy

Dokploy prior to 0.29.13 is vulnerable to OS command injection via the backup and restore pipeline, allowing authenticated admins to execute arbitrary...

2026-08-11
CVE-2026-72877
Analyzed
9.6
Docker dokploy

Dokploy versions before 0.29.13 are vulnerable to OS command injection via the dockerImage field, allowing authenticated users to execute arbitrary co...

2026-08-11
CVE-2026-72876
Analyzed
9.9
Dokploy dokploy

Dokploy versions before 0.29.13 contain an authorization bypass and OS command injection flaw, allowing authenticated users to manipulate server IDs a...

2026-08-11
CVE-2026-72875
Analyzed
8.8
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72874
Analyzed
8.7
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72872
Analyzed
9.9
Dokploy dokploy

Dokploy improperly validates Bitbucket repository fields, allowing authenticated users to inject arbitrary OS commands into git clone operations.

2026-08-11
CVE-2026-72871
Analyzed
7.5
Dokploy Dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72870
Analyzed
8.7
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-7287
Analyzed
7.5
Zyxel NWA1100

** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert(...

2026-05-12
CVE-2026-72869
Analyzed
9.9
Docker dokploy

An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with backup permissions to execute arbitrary commands in...

2026-08-11
CVE-2026-72868
Analyzed
9.9
Docker dokploy

Dokploy allows a low-privileged member to execute arbitrary OS commands as root by injecting malicious input into the rclone configuration fields duri...

2026-08-11
CVE-2026-72867
Analyzed
9.9
Dokploy dokploy

Dokploy versions 0.29.3 through 0.29.12 are susceptible to OS command injection due to insufficient server-side validation of git branch fields during...

2026-08-11
CVE-2026-72866
Analyzed
8.8
Dokploy dokploy

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-08-11
CVE-2026-72865
Analyzed
9.9
Dokploy dokploy

Dokploy versions prior to 0.29.13 contain an OS command injection vulnerability in the compose update process, allowing authenticated users to execute...

2026-08-11
CVE-2026-72864
Analyzed
9.9
Docker dokploy

Dokploy versions before 0.29.13 are vulnerable to a missing authorization flaw in the docker-container-terminal component, allowing authenticated user...

2026-08-11
CVE-2026-72863
Analyzed
9.9
Docker dokploy

Dokploy versions prior to 0.29.13 fail to enforce authorization checks on WebSocket handlers, allowing authenticated users to access interactive shell...

2026-08-11
CVE-2026-72862
Analyzed
9.9
Docker dokploy

Dokploy contains an OS command injection vulnerability in its database service deployment functions, allowing authenticated users to execute arbitrary...

2026-08-11
CVE-2026-72860
Analyzed
8.5
Unknown 9router

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destin...

2026-08-22
CVE-2026-72859
Analyzed
7.7
Budibase server

Budibase versions 3

2026-08-16
CVE-2026-72851
Analyzed
10
Budibase Server

Budibase server versions before 3.40.0 contain an unauthenticated SQL injection vulnerability in webhook-triggered automations, allowing remote attack...

2026-08-14
CVE-2026-72848
Analyzed
8.6
Unknown langchain-community

SitemapLoader

2026-08-21
CVE-2026-72842
Analyzed
9.9
Unknown luci

An ACL inconsistency in the OpenWrt LuCI LXC application allows authenticated users with low privileges to bypass authorization and execute arbitrary...

2026-08-14
CVE-2026-72841
Analyzed
9.9
Unknown luci

The luci-app-openvpn package for OpenWrt is vulnerable to path traversal during file uploads, enabling authenticated users to write arbitrary files an...

2026-08-14
CVE-2026-72840
Analyzed
8.8
OpenWrt LuCI

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended o...

2026-08-15
CVE-2026-7284
Analyzed
9.8
WordPress is vulnerable

The Easy Elements for Elementor plugin is vulnerable to privilege escalation, allowing unauthenticated users to register as administrators.

2026-05-20
CVE-2026-72839
Analyzed
9.8
Unknown filebrowser

Filebrowser through 2.63.16 contains an incorrect privilege assignment vulnerability that allows unauthenticated attackers to register accounts with f...

2026-08-14
CVE-2026-72837
Analyzed
8.8
Unknown filebrowser

File Browser versions before 2

2026-08-15
CVE-2026-72836
Analyzed
8.1
FileBrowser filebrowser

FileBrowser before 2

2026-08-16