20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 2101-2150 of 20297 CVEs Page 43 of 406
CVE-2026-59145
9.1
EGOR Data::Intern::Shared

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The at...

2026-08-03
CVE-2026-59144
9.8
EGOR Data::RingBuffer::Shared

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time v...

2026-07-31
CVE-2026-59142
9.1
EGOR Data::HashMap::Shared

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attac...

2026-08-07
CVE-2026-59140
9.1
EGOR Data::SortedSet::Shared

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. T...

2026-08-07
CVE-2026-5914
8.8
Google Chrome prior

Type Confusion in CSS in Google Chrome prior to 147

2026-04-10
CVE-2026-59139
9.1
EGOR Data::ReqRep::Shared

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The...

2026-08-07
CVE-2026-5912
8.8
Google Chrome prior

Integer overflow in WebRTC in Google Chrome prior to 147

2026-04-10
CVE-2026-5910
8.8
Google Chrome prior

Integer overflow in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-59099
Analyzed
9.1
Apereo CAS

A cryptographic flaw in Apereo CAS allows unauthenticated attackers to decrypt webflow conversation states by exploiting AES-GCM initialization vector...

2026-07-03
CVE-2026-59095
Analyzed
7.7
LobeHub LobeChat

LobeChat before 2

2026-07-03
CVE-2026-59093
Analyzed
8.8
Weaviate Weaviate

Weaviate before 1

2026-07-03
CVE-2026-59092
Analyzed
7.7
JuiceFS JuiceFS

JuiceFS through 1

2026-07-03
CVE-2026-5909
8.8
Google Chrome prior

Integer overflow in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-59083
Analyzed
9.1
Apache Apache Tomcat

A URL encoding vulnerability in Apache Tomcat's RewriteValve allows unauthenticated attackers to bypass security constraints by manipulating hex-encod...

2026-07-16
CVE-2026-5908
8.8
Google Chrome prior

Integer overflow in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-5907
8.1
Google Chrome prior

Insufficient data validation in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-5883
Analyzed
8.8
Google Chrome

Use after free in Media in Google Chrome prior to 147

2026-06-03
CVE-2026-5879
Analyzed
8.8
Google Chrome for Mac

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147

2026-05-27
CVE-2026-58662
Analyzed
8.7
Apache Apache Thrift

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings

2026-07-28
CVE-2026-5866
8.8
Google Chrome prior

Use after free in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-58658
Analyzed
8.2
Intel GPUStack

GPUStack through 2

2026-07-17
CVE-2026-58655
Analyzed
8.8
Grav Grav

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1

2026-07-16
CVE-2026-5865
Analyzed
8.8
Google Chrome

Type Confusion in V8 in Google Chrome prior to 147

2026-05-27
CVE-2026-58644
KEV Analyzed
9.8
Microsoft SharePoint

A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthenticated, remote attacker to execute arbitrary code.

2026-07-15
CVE-2026-58630
Analyzed
10
Microsoft Azure App Service for Linux

An improper access control flaw in Microsoft Azure App Service for Linux allows an unauthenticated, remote attacker to elevate privileges over a netwo...

2026-07-25
CVE-2026-58626
Analyzed
8.8
Microsoft Windows

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-58608
Analyzed
8.8
Microsoft Windows Print Spooler

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized a...

2026-07-15
CVE-2026-5860
Analyzed
8.8
Google Chrome

Use after free in WebRTC in Google Chrome prior to 147

2026-05-27
CVE-2026-58596
Analyzed
8.3
Microsoft Microsoft Edge (Chromium-based)

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network

2026-07-13
CVE-2026-58594
Analyzed
8.8
Microsoft Windows

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-58586
Analyzed
9.8
GitHub Image::WebP

The Perl module Image::WebP bundles a vulnerable version of libwebp, which allows remote attackers to trigger heap corruption and potential code execu...

2026-08-02
CVE-2026-5857
Analyzed
8.1
Contiki-NG Contiki-NG

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt

2026-08-08
CVE-2026-5854
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU is susceptible to remote OS command injection via the setWiFiEasyCfg function, specifically through the merge argument in the CGI...

2026-04-09
CVE-2026-58534
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-5853
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU is vulnerable to remote OS command injection via the setIpv6LanCfg function, exploitable through the addrPrefixLen argument in th...

2026-04-09
CVE-2026-58525
Analyzed
8.2
Microsoft Microsoft Edge (Chromium-based)

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network

2026-07-09
CVE-2026-5852
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU allows remote OS command injection via the setIptvCfg function by manipulating the igmpVer argument in the CGI handler.

2026-04-09
CVE-2026-5851
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU is susceptible to remote OS command injection via the setUPnPCfg function, specifically through the enable parameter in the CGI h...

2026-04-09
CVE-2026-58500
Analyzed
8.2
Apple appium-mcp

MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS

2026-07-14
CVE-2026-5850
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU contains an OS command injection vulnerability in the setVpnPassCfg function, allowing remote attackers to execute arbitrary syst...

2026-04-09
CVE-2026-58499
Analyzed
8.2
EverMind-AI EverOS

EverOS is a memory runtime for agents

2026-07-11
CVE-2026-58492
Analyzed
9.2
Unknown grav

The grav-plugin-database for Grav CMS is vulnerable to SQL injection via the PDO::tableExists method due to improper input sanitization.

2026-07-11
CVE-2026-58486
Analyzed
8.3
HedgeDoc HedgeDoc

HedgeDoc is an open source, real-time, collaborative, markdown notes application

2026-07-14
CVE-2026-58480
Analyzed
9.8
WordPress Blocksy Companion

The Blocksy Companion WordPress plugin is vulnerable to unauthenticated arbitrary file uploads via the save_attachments function, enabling remote code...

2026-07-09
CVE-2026-58479
Analyzed
9.8
Dan-in-CA Sustainable Irrigation Platform (SIP)

Sustainable Irrigation Platform (SIP) contains a command injection vulnerability in the cli_control plugin that allows unauthenticated attackers to ex...

2026-07-15
CVE-2026-58473
Analyzed
9.1
Intel cognee

Cognee contains an improper access control vulnerability allowing unauthenticated attackers to overwrite global LLM provider settings via the API, ena...

2026-07-08
CVE-2026-58466
Analyzed
9.8
EstrellaXD Auto_Bangumi

Auto_Bangumi contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to gain administrative access.

2026-07-03
CVE-2026-58460
Analyzed
7.7
Unknown react-native-receive-sharing-intent

react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the...

2026-07-03
CVE-2026-58459
Analyzed
7.8
F5 gpsd

gpsd through release-3

2026-07-10
CVE-2026-58457
Analyzed
9.8
Unknown M300 Wi-Fi Repeater

The Shenzhen Aitemi M300 Wi-Fi Repeater is vulnerable to unauthenticated OS command injection via the smacfilter_conf handler, allowing remote attacke...

2026-07-02