8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 151-200 of 8341 CVEs Page 4 of 167
CVE-2026-23529
Analyzed
7.7
Google Multiple Products

Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery

2026-01-17
CVE-2026-23527
8.9
Unknown Multiple Products

H3 is a minimal H(TTP) framework built for high performance and portability

2026-01-16
CVE-2026-23524
Analyzed
9.8
HP Multiple Products

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the...

2026-01-22
CVE-2026-23523
9.6
Unknown Multiple Products

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install...

2026-01-17
CVE-2026-23520
9
Docker Multiple Products

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported l...

2026-01-16
CVE-2026-23515
Analyzed
9.9
Unknown Multiple Products

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated u...

2026-02-03
CVE-2026-23512
Analyzed
8.6
Microsoft Multiple Products

SumatraPDF is a multi-format reader for Windows

2026-01-15
CVE-2026-23493
Analyzed
8.6
Intel Multiple Products

Pimcore is an Open Source Data & Experience Management Platform

2026-01-16
CVE-2026-23492
Analyzed
8.8
Pimcore Multiple Products

Pimcore is an Open Source Data & Experience Management Platform

2026-01-15
CVE-2026-23490
7.5
Unknown Multiple Products

pyasn1 is a generic ASN

2026-01-18
CVE-2026-23477
7.7
Unknown Multiple Products

Rocket

2026-01-16
CVE-2026-22910
7.5
Unknown Multiple Products

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access

2026-01-16
CVE-2026-22909
7.5
Unknown Multiple Products

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentiall...

2026-01-16
CVE-2026-22908
9.1
Unknown Multiple Products

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confid...

2026-01-16
CVE-2026-22907
9.9
Unknown Multiple Products

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

2026-01-16
CVE-2026-22867
8.7
LaSuite Multiple Products

LaSuite Doc is a collaborative note taking, wiki and documentation platform

2026-01-16
CVE-2026-22864
Analyzed
8.1
Intel Multiple Products

Deno is a JavaScript, TypeScript, and WebAssembly runtime

2026-01-16
CVE-2026-22861
8.8
Unknown Multiple Products

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) col...

2026-01-14
CVE-2026-22850
Analyzed
8.3
WordPress Multiple Products

Koko Analytics is an open-source analytics plugin for WordPress

2026-01-20
CVE-2026-22844
Analyzed
9.9
Zoom Multiple Products

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote c...

2026-01-21
CVE-2026-22818
Analyzed
8.2
Intel Multiple Products

Hono is a Web application framework that provides support for any JavaScript runtime

2026-01-14
CVE-2026-22817
Analyzed
8.2
Intel Multiple Products

Hono is a Web application framework that provides support for any JavaScript runtime

2026-01-14
CVE-2026-22812
Analyzed
8.8
Intel Multiple Products

OpenCode is an open source AI coding agent

2026-01-13
CVE-2026-22807
8.8
Unknown Multiple Products

vLLM is an inference and serving engine for large language models (LLMs)

2026-01-22
CVE-2026-22806
Analyzed
9.1
Kubernetes Multiple Products

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4....

2026-01-30
CVE-2026-22804
Analyzed
8
Unknown Multiple Products

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

2026-01-13
CVE-2026-22797
Analyzed
9.9
Unknown Multiple Products

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 1...

2026-01-20
CVE-2026-22794
Analyzed
9.6
Unknown Multiple Products

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers...

2026-01-13
CVE-2026-22793
Analyzed
9.6
Intel Multiple Products

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsin...

2026-01-22
CVE-2026-22792
Analyzed
9.6
Intel Multiple Products

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML renderin...

2026-01-22
CVE-2026-22788
8.2
Unknown Multiple Products

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry

2026-01-13
CVE-2026-22783
Analyzed
9.6
Unknown Multiple Products

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS data...

2026-01-13
CVE-2026-22778
Analyzed
9.8
Unknown Multiple Products

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimo...

2026-02-03
CVE-2026-22777
7.5
Unknown Multiple Products

ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI

2026-01-10
CVE-2026-22775
Analyzed
7.5
Svelte Multiple Products

Svelte devalue is a JavaScript library that serializes values into strings when JSON

2026-01-16
CVE-2026-22774
Analyzed
7.5
Svelte Multiple Products

Svelte devalue is a JavaScript library that serializes values into strings when JSON

2026-01-16
CVE-2026-22771
Analyzed
8.8
Kubernetes Multiple Products

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

2026-01-13
CVE-2026-22709
Analyzed
9.8
Docker Multiple Products

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization...

2026-01-27
CVE-2026-22704
Analyzed
8
HP Multiple Products

HAX CMS helps manage microsite universe with PHP or NodeJs backends

2026-01-10
CVE-2026-22700
7.5
Unknown Multiple Products

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic...

2026-01-10
CVE-2026-22699
7.5
Unknown Multiple Products

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic...

2026-01-10
CVE-2026-22697
Analyzed
7.5
CryptoLib Multiple Products

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2026-01-10
CVE-2026-22688
Analyzed
9.9
Unknown Multiple Products

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command inject...

2026-01-10
CVE-2026-22687
8.1
WeKnora Multiple Products

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval

2026-01-10
CVE-2026-22686
Analyzed
10
Unknown Multiple Products

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in...

2026-01-14
CVE-2026-22685
Analyzed
8.8
DevToys Multiple Products

DevToys is a desktop app for developers

2026-01-10
CVE-2026-22643
8.3
Unknown Multiple Products

In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vul...

2026-01-16
CVE-2026-22638
8.3
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect

2026-01-16
CVE-2026-22623
7.2
Unknown Multiple Products

Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary commands on...

2026-01-31
CVE-2026-22600
Analyzed
9.1
Unknown Multiple Products

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export func...

2026-01-10