23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 22301-22350 of 23871 CVEs Page 447 of 478
CVE-2024-8068
KEV Analyzed
9.5
Citrix Citrix Session Recording

Citrix Session Recording Improper Privilege Management Vulnerability - Active in CISA KEV catalog.

2025-08-25
CVE-2024-7953
Analyzed
8.7
Rockwell Automation DataEdgePlatform DataMosaix™ Private Cloud

A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a th...

2026-09-02
CVE-2024-7952
Analyzed
8.7
Rockwell Automation DataEdgePlatform DataMosaix™ Private Cloud

A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached...

2026-09-03
CVE-2024-7694
KEV Analyzed
9.5
TeamT5 ThreatSonar Anti-Ransomware

TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.

2026-02-18
CVE-2024-7593
KEV Analyzed
9.8
Ivanti vTM

An authentication bypass vulnerability in the Ivanti vTM admin panel allows remote unauthenticated attackers to gain unauthorized administrative acces...

2026-06-05
CVE-2024-7399
KEV Analyzed
9.5
Samsung Electronics MagicINFO 9 Server

Samsung MagicINFO 9 Server Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-25
CVE-2024-7017
Analyzed
7.5
Google Chrome

Inappropriate implementation in DevTools in Google Chrome prior to 126

2025-11-15
CVE-2024-6228
Analyzed
7.5
WordPress Notifications for Forms & WordPress Actions

The Notifications for Forms & WordPress Actions WordPress plugin before 2

2026-07-07
CVE-2024-6107
Analyzed
9.6
Canonical MAAS

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has...

2025-07-22
CVE-2024-5986
Analyzed
9.1
h2oai h2oai/h2o-3

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploit...

2026-02-02
CVE-2024-5958
Analyzed
8.8
Eliz Software Panel

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Executio...

2026-06-04
CVE-2024-58378
Analyzed
9.8
Unknown nokogiri

Nokogiri is affected by a use-after-free vulnerability in the xmlTextReader module when processing crafted XML documents with DTD validation and XIncl...

2026-08-26
CVE-2024-58376
Analyzed
8.8
renovatebot renovate

Renovate versions 37

2026-08-20
CVE-2024-58375
Analyzed
7.5
opentofu opentofu

OpenTofu versions 1

2026-08-17
CVE-2024-58368
Analyzed
7.5
surrealdb surrealdb

SurrealDB versions before 1

2026-07-19
CVE-2024-58367
Analyzed
7.1
surrealdb surrealdb

SurrealDB versions before 2

2026-07-19
CVE-2024-58366
Analyzed
8.5
surrealdb surrealdb

SurrealDB before 1

2026-07-19
CVE-2024-58362
Analyzed
8.8
surrealdb surrealdb

SurrealDB before 1

2026-07-19
CVE-2024-58355
Analyzed
8.9
calcom cal.diy

Cal

2026-07-24
CVE-2024-58354
Analyzed
9.9
calcom cal.diy

A repository takeover vulnerability exists in the cal.diy GitHub Actions workflow, allowing attackers to execute arbitrary code via malicious pull req...

2026-07-24
CVE-2024-58353
Analyzed
8.9
calcom cal.diy

Cal

2026-07-24
CVE-2024-58351
Analyzed
9.8
Flowise Flowise

Flowise versions before 2.1.4 are vulnerable to remote code execution and sandbox escape via an insecure overrideConfig option in the Chainflow execut...

2026-06-21
CVE-2024-58349
Analyzed
9.8
WP Travel Kit Travelscape

WordPress Theme Travelscape 1.0.3 is susceptible to remote code execution due to insufficient validation of file uploads in the theme directory.

2026-06-08
CVE-2024-58348
Analyzed
9.8
background-image-cropper Background Image Cropper

WordPress Background Image Cropper 1.2 allows unauthenticated attackers to execute arbitrary code via an insecure file upload endpoint.

2026-06-08
CVE-2024-58341
Analyzed
8.2
Opencart OpenCart Core

OpenCart Core 4

2026-03-26
CVE-2024-58338
Analyzed
9.8
Ateme Flamingo XL

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the tracer...

2025-12-31
CVE-2024-58337
Analyzed
7.5
The Akuvox Company Akuvox Smart Doorphone

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings an...

2025-12-31
CVE-2024-58336
Analyzed
9.8
The Akuvox Company Akuvox Smart Doorphone

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video...

2025-12-31
CVE-2024-58316
Analyzed
7.5
PuneethReddyHC online-shopping-system-advanced

Online Shopping System Advanced 1

2025-12-13
CVE-2024-58315
Analyzed
8.4
Tosibox Oy Tosibox Key Service

Tosibox Key Service 3

2025-12-31
CVE-2024-58314
Analyzed
8.8
ATCOM Technology 100M IP Phones

Atcom 100M IP Phones firmware version 2

2025-12-13
CVE-2024-58311
Analyzed
9.8
dormakaba Dormakaba Saflok System 6000

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique ide...

2025-12-13
CVE-2024-58305
Analyzed
8.8
wondercms WonderCMS

WonderCMS 4

2025-12-13
CVE-2024-58304
Analyzed
7.5
SPA-Cart SPA-CART CMS

SPA-CART CMS 1

2025-12-13
CVE-2024-58299
Analyzed
9.8
PCMan FTP Server

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers c...

2025-12-13
CVE-2024-58274
Analyzed
8.3
Hikvision CSMP iSecure Center

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api...

2025-10-22
CVE-2024-58267
Analyzed
8
SUSE Rancher

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attack...

2025-10-02
CVE-2024-58260
Analyzed
7.6
SUSE Rancher

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `

2025-10-02
CVE-2024-58259
Analyzed
8.2
SUSE Rancher

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated)...

2025-09-02
CVE-2024-58258
Analyzed
7.2
SugarCRM SugarCRM

SugarCRM before 13

2025-07-14
CVE-2024-58041
Analyzed
9.1
WONKO Smolder

Smolder versions through 1.51 use the insecure Perl rand() function for cryptographic operations. This lack of cryptographically secure entropy weaken...

2026-02-25
CVE-2024-58040
Analyzed
9.1
QWER Crypt::RandomEncryption

Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.

2025-09-30
CVE-2024-58023
Analyzed
8.4
Bosch Bosch Configuration Manager

Information disclosure in Bosch Configuration Manager in Version 7

2026-07-24
CVE-2024-57728
KEV Analyzed
9.5
SimpleHelp SimpleHelp

SimpleHelp Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-25
CVE-2024-57726
KEV Analyzed
9.5
SimpleHelp SimpleHelp

SimpleHelp Missing Authorization Vulnerability - Active in CISA KEV catalog.

2026-04-25
CVE-2024-57695
Analyzed
7.7
Unknown

An issue in Agnitum Outpost Security Suite 7

2025-11-13
CVE-2024-57521
Analyzed
10
Unknown

SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.jav...

2025-12-24
CVE-2024-57491
Analyzed
8.8
Unknown

Authentication Bypass vulnerability in jobx up to v1

2025-08-20
CVE-2024-57157
Analyzed
9.8
Unknown

Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.

2025-08-21
CVE-2024-57155
Analyzed
9.8
Unknown

Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.

2025-08-21