20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 2001-2050 of 20297 CVEs Page 41 of 406
CVE-2026-59726
Analyzed
10
Ruvnet Ruflo

Ruflo's default deployment exposes unauthenticated MCP endpoints, allowing remote attackers to execute terminal commands and steal API keys.

2026-07-10
CVE-2026-59723
Analyzed
8.8
Cline Cline

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant

2026-07-09
CVE-2026-59713
Analyzed
8.1
Leantime Leantime

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters

2026-07-07
CVE-2026-59712
Analyzed
8.1
Leantime Leantime

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential...

2026-07-07
CVE-2026-59707
Analyzed
8.6
LocalAI LocalAI

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitr...

2026-07-08
CVE-2026-59706
Analyzed
9.3
Unknown mem0

Unauthenticated configuration endpoints in mem0 expose plaintext API keys and allow for server-side request forgery (SSRF) attacks against internal se...

2026-07-08
CVE-2026-59705
Analyzed
9.8
Unknown mem0

The mem0 API component suffers from an unauthenticated access vulnerability allowing remote attackers to read, write, or delete user memories and trig...

2026-07-08
CVE-2026-59702
Analyzed
9.3
Repomix Repomix

Repomix contains a server-side request forgery (SSRF) vulnerability in the POST /api/pack endpoint, allowing unauthenticated attackers to make arbitra...

2026-07-09
CVE-2026-59695
Analyzed
8.3
ZenHive mpp

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single re...

2026-07-18
CVE-2026-59694
Analyzed
8.3
ZenHive mpp

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per paym...

2026-07-18
CVE-2026-59690
Analyzed
8
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, Multi Tenant

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi...

2026-07-28
CVE-2026-59689
Analyzed
8
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allo...

2026-07-28
CVE-2026-59688
Analyzed
8.4
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows...

2026-07-28
CVE-2026-59687
Analyzed
8.4
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows...

2026-07-28
CVE-2026-59686
Analyzed
8.4
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows...

2026-07-28
CVE-2026-5967
8.8
Unknown Multiple Products

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability

2026-04-21
CVE-2026-5966
Analyzed
8.1
TeamT5 ThreatSonar Anti-Ransomware

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability

2026-04-20
CVE-2026-59651
Analyzed
7.1
Unknown BC-JAVA, BC-LTS-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59650
Analyzed
9.3
Unknown BC-JAVA

Bouncy Castle for Java and Java LTS versions contain an improper input validation vulnerability where peer values are exponentiated without validation...

2026-08-03
CVE-2026-5965
Analyzed
9.8
Unknown Multiple Products

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and...

2026-04-21
CVE-2026-59649
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59646
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59645
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59644
Analyzed
8.7
Unknown BC-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59643
Analyzed
8.7
Unknown BC-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59642
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59641
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59640
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-5964
Analyzed
9.8
Digiwin EasyFlow .NET

Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.

2026-04-20
CVE-2026-59639
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59638
Analyzed
9.3
Unknown BC-JAVA

Bouncy Castle for Java has an insecure default configuration for the JSSE hostname verifier, which incorrectly enables CN-fallback.

2026-08-03
CVE-2026-5963
Analyzed
9.8
Digiwin EasyFlow .NET

Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.

2026-04-20
CVE-2026-59555
Analyzed
10
WordPress Participants Database

The Roland Barker Participants Database plugin for WordPress contains an unauthenticated arbitrary file deletion vulnerability due to improper path va...

2026-07-24
CVE-2026-59551
Analyzed
8.5
WordPress rtMedia for WordPress, BuddyPress and bbPress

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4

2026-07-28
CVE-2026-59550
Analyzed
9.3
WordPress AWP Classifieds

An unauthenticated SQL injection vulnerability in AWP Classifieds allows remote attackers to execute arbitrary SQL commands via the plugin, potentiall...

2026-07-28
CVE-2026-5955
Analyzed
9.8
Unknown BiEticaret

BiEticaret is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL commands against the database.

2026-07-10
CVE-2026-59549
Analyzed
9.3
WordPress rtMedia for WordPress, BuddyPress and bbPress

An unauthenticated SQL injection vulnerability exists in the rtMedia for WordPress plugin, allowing attackers to manipulate database queries via vulne...

2026-07-28
CVE-2026-59548
Analyzed
7.5
WordPress Byteflows Travel & Hotel Booking

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1

2026-07-28
CVE-2026-59546
Analyzed
7.4
WordPress Hide My WP Ghost

Subscriber Broken Authentication in Hide My WP Ghost <= 7

2026-07-28
CVE-2026-59545
Analyzed
8.1
Discord Discord Integration Plugin

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2

2026-07-24
CVE-2026-59544
Analyzed
9.8
HP Thrive Quiz Builder

Thrive Quiz Builder contains an unauthenticated PHP Object Injection vulnerability in versions 10.9.3.0 and below, allowing remote attackers to execut...

2026-07-24
CVE-2026-59543
Analyzed
9.9
WordPress Advanced Views

The WPLake Advanced Views WordPress plugin contains a code injection vulnerability allowing remote code execution for authenticated subscribers.

2026-07-24
CVE-2026-59542
Analyzed
7.7
WordPress Kali Forms

Subscriber Arbitrary File Deletion in Kali Forms <= 2

2026-07-24
CVE-2026-59541
Analyzed
8.8
WordPress WP BASE Booking

Subscriber Privilege Escalation in WP BASE Booking <= 6

2026-07-24
CVE-2026-59540
Analyzed
9.8
WordPress SMS Alert Order Notifications

The SMS Alert Order Notifications WordPress plugin contains an unauthenticated privilege escalation vulnerability that allows attackers to gain unauth...

2026-07-24
CVE-2026-59539
Analyzed
7.5
WordPress Paid Member Subscriptions

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3

2026-07-28
CVE-2026-59538
Analyzed
9.3
Ruben Garcia GamiPress

A critical, unauthenticated SQL injection vulnerability exists in the GamiPress plugin, enabling remote attackers to manipulate database queries.

2026-07-28
CVE-2026-59537
Analyzed
7.6
WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2

2026-07-28
CVE-2026-59536
Analyzed
7.5
WordPress CoCart – Headless ecommerce

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4

2026-07-28
CVE-2026-59535
Analyzed
7.3
WordPress Thrive Product Manager

Unauthenticated Broken Access Control in Thrive Product Manager <= 10

2026-07-28