23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 151-200 of 23295 CVEs Page 4 of 466
CVE-2026-9211
Analyzed
8.8
Unknown Router

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation

2026-06-20
CVE-2026-9208
Analyzed
8.8
Connect Multiple Products

Tanium addressed an unauthorized code execution vulnerability in Connect

2026-05-28
CVE-2026-9207
Analyzed
8.8
Tanium Connect

Tanium addressed an unauthorized code execution vulnerability in Connect

2026-05-27
CVE-2026-9203
Analyzed
8.5
Unknown MarkLogic Server

A server-side request forgery vulnerability in Progress MarkLogic Server before 11

2026-08-06
CVE-2026-9202
Analyzed
9.8
IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.0 allow unauthenticated attackers to create new user accounts that may automatically gain access to remot...

2026-07-18
CVE-2026-9201
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-9198
KEV Analyzed
9.8
IBM Langflow OSS

A critical code injection vulnerability in IBM Langflow OSS allows unauthenticated attackers to gain superuser privileges and execute arbitrary code o...

2026-07-18
CVE-2026-9196
Analyzed
8.1
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-9193
Analyzed
9.9
Progress Software MarkLogic Server

Progress Software MarkLogic Server contains an improper privilege management flaw in its Hadoop integration, enabling authenticated users to escalate...

2026-08-06
CVE-2026-9192
Analyzed
9.8
Progress Software MarkLogic Server

Progress MarkLogic Server contains an authentication bypass vulnerability in the ODBC App Server, allowing unauthenticated attackers to execute querie...

2026-08-06
CVE-2026-9181
Analyzed
9.8
Esri ArcGIS Server

ArcGIS Server is affected by a directory traversal vulnerability that allows unauthenticated attackers to access sensitive files on the host system vi...

2026-07-07
CVE-2026-9177
Analyzed
9.4
Axway SecureTransport

Axway SecureTransport is vulnerable to server-side template injection in its mail template functionality, allowing authenticated admins to execute arb...

2026-07-30
CVE-2026-9171
Analyzed
7.5
IBM PowerVM Novalink

IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request

2026-07-19
CVE-2026-9169
Analyzed
8.8
LUCID Vision Labs Arena SDK

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1

2026-08-07
CVE-2026-9165
Analyzed
7.7
Kubernetes Red Hat Advanced Cluster Security (RHACS)

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS)

2026-07-07
CVE-2026-9157
Analyzed
8.4
Gmission Web Fax Multiple Products

Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion

2026-05-22
CVE-2026-9155
Analyzed
8.8
Linux InsightConnect Sed Plugin

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via th...

2026-06-25
CVE-2026-9147
Analyzed
7.8
Unknown uproot

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime

2026-07-19
CVE-2026-9144
Analyzed
7.6
Alert Multiple Products

Taiko AG1000-01A SMS Alert Gateway Rev 7

2026-05-21
CVE-2026-9141
Analyzed
9.8
Unknown AG1000-01A SMS Alert Gateway

The Taiko AG1000-01A SMS Alert Gateway web interface lacks server-side authentication, allowing unauthenticated attackers to access internal pages dir...

2026-05-21
CVE-2026-9140
Analyzed
8.7
Rockwell Automation 1718-AENTR/1719-AENTR

A denial-of-service security issue exists in the 1719-AENTR

2026-07-15
CVE-2026-9139
Analyzed
9.8
Unknown AG1000-01A SMS Alert Gateway

The Taiko AG1000-01A SMS Alert Gateway exposes hard-coded administrative credentials via client-side JavaScript in its configuration interface.

2026-05-21
CVE-2026-9135
Analyzed
9.9
IBM Langflow OSS

IBM Langflow OSS contains a code injection vulnerability in its ToolGuard integration, allowing authenticated users to bypass security controls and ex...

2026-07-18
CVE-2026-9133
Analyzed
7.7
Unknown Multiple Products

Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0

2026-05-21
CVE-2026-9126
Analyzed
8.8
Google Chrome on

Use after free in DOM in Google Chrome on prior to 148

2026-05-21
CVE-2026-9123
Analyzed
7.5
Google Chrome

Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148

2026-05-22
CVE-2026-9121
Analyzed
8.8
Google Chrome on

Out of bounds read in GPU in Google Chrome on prior to 148

2026-05-21
CVE-2026-9120
Analyzed
8.8
Google Chrome prior

Use after free in WebRTC in Google Chrome prior to 148

2026-05-21
CVE-2026-9119
Analyzed
8.8
Google Chrome on

Heap buffer overflow in WebRTC in Google Chrome on prior to 148

2026-05-21
CVE-2026-9118
Analyzed
8.8
Microsoft Chrome on

Use after free in XR in Google Chrome on Windows prior to 148

2026-05-21
CVE-2026-9117
Analyzed
7.5
Google Chrome

Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148

2026-05-22
CVE-2026-9114
Analyzed
8.8
Google Chrome on

Use after free in QUIC in Google Chrome on prior to 148

2026-05-21
CVE-2026-9112
Analyzed
8.8
Microsoft Chrome on

Use after free in GPU in Google Chrome on Windows prior to 148

2026-05-21
CVE-2026-9111
Analyzed
8.8
Google Chrome on

Use after free in WebRTC in Google Chrome on Linux prior to 148

2026-05-21
CVE-2026-9103
Analyzed
9.8
IBM Langflow OSS

IBM Langflow OSS contains an authentication bypass vulnerability in the auto_login endpoint, allowing unauthenticated attackers to gain full administr...

2026-07-18
CVE-2026-9089
Analyzed
8.8
ConnectWise Automate

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations

2026-05-22
CVE-2026-9085
Analyzed
8.8
TUBITAK BILGEM Pardus-Parental-Control

Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institut...

2026-07-06
CVE-2026-9082
KEV Analyzed
9.5
Drupal Core

Drupal Core SQL Injection Vulnerability - Active in CISA KEV catalog.

2026-05-23
CVE-2026-9077
Analyzed
8.5
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-9074
Analyzed
9.1
IBM API Connect

An unauthenticated SQL injection vulnerability exists in the password reset functionality of IBM API Connect, potentially allowing unauthorized access...

2026-07-09
CVE-2026-9072
Analyzed
8.1
IBM i

IBM i 7

2026-06-23
CVE-2026-9071
Analyzed
7.5
IBM WebSphere Application Server

IBM WebSphere Application Server 9

2026-06-23
CVE-2026-9064
Analyzed
7.5
Unknown Multiple Products

A flaw was found in 389-ds-base

2026-05-22
CVE-2026-9057
Analyzed
8.2
Unknown Multiple Products

A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend...

2026-05-20
CVE-2026-9055
Analyzed
9.8
WordPress Booking for Appointments and Events Calendar – Amelia

The Amelia WordPress plugin contains a critical privilege escalation vulnerability allowing unauthenticated attackers to gain administrative access vi...

2026-09-02
CVE-2026-9044
Analyzed
8.5
TP-Link AXE75 V1

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers

2026-08-01
CVE-2026-9029
Analyzed
7.3
Grafana Grafana OSS

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug

2026-06-23
CVE-2026-9024
Analyzed
8.7
Dassault Systèmes DELMIA Service Process Engineer

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R20...

2026-06-02
CVE-2026-9018
Analyzed
8.8
WordPress is vulnerable

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inc...

2026-05-22
CVE-2026-9010
Analyzed
7.5
WordPress is vulnerable

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and inclu...

2026-05-20