21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 2201-2250 of 21637 CVEs Page 45 of 433
CVE-2026-63455
Analyzed
9.8
HP EdgeConnect SD-WAN Orchestrator

HPE EdgeConnect SD-WAN Orchestrator contains multiple REST API vulnerabilities that allow unauthenticated remote attackers to bypass authentication an...

2026-08-05
CVE-2026-63429
Analyzed
8.6
Intel HeyForm

HeyForm is an open-source form builder

2026-07-21
CVE-2026-63409
Analyzed
8.2
Unknown deskflow

Deskflow is a keyboard and mouse sharing app

2026-08-18
CVE-2026-63384
Analyzed
8.7
Unknown libevent

Libevent is an event notification library

2026-08-21
CVE-2026-63383
Analyzed
8.7
Unknown libevent

Libevent is an event notification library

2026-08-21
CVE-2026-63361
Analyzed
8.5
GitHub LimeSurvey

LimeSurvey Community Edition 7

2026-08-15
CVE-2026-63359
Analyzed
9.8
Appriss Insights Victim Information Notification Exchange (VINE)

The Appriss Insights VINE application is vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication and access sensitive...

2026-07-24
CVE-2026-63313
Analyzed
7.7
Unknown 9router

9Router before 0

2026-07-24
CVE-2026-63306
Analyzed
8.6
StoatChat StoatChat

stoatchat before 0

2026-07-17
CVE-2026-63305
Analyzed
8.1
HP AVideo

AVideo through 29

2026-07-17
CVE-2026-63304
Analyzed
8.1
GitHub AVideo

AVideo through 29

2026-07-17
CVE-2026-63300
Analyzed
9.9
Canonical LXD

LXD fails to validate instance configurations during migration, allowing an authenticated attacker to bypass project-level security restrictions and e...

2026-08-13
CVE-2026-63298
Analyzed
8.7
NVIDIA LXD

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to injec...

2026-08-14
CVE-2026-63297
Analyzed
9.9
Canonical LXD

A time-of-check to time-of-use race condition in Canonical LXD allows authenticated users to bypass project security restrictions during cross-project...

2026-08-13
CVE-2026-63296
Analyzed
9.9
Canonical LXD

An authorization bypass in Canonical LXD allows authenticated users to move instances into restricted projects while bypassing enforced configuration...

2026-08-13
CVE-2026-63294
Analyzed
9.9
Canonical LXD

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system by providing a malicious archive with a...

2026-08-13
CVE-2026-63293
Analyzed
9.9
Canonical LXD

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system by providing a crafted...

2026-08-13
CVE-2026-63252
Analyzed
8.7
Eclipse Foundation Eclipse Milo

In Eclipse Milo versions 0

2026-08-05
CVE-2026-63234
Analyzed
9.9
Three Learning Koollab LMS

Koollab LMS contains a SQL injection and unsafe deserialisation vulnerability in the manual mark assessment endpoint, allowing authenticated attackers...

2026-07-29
CVE-2026-63233
Analyzed
9.9
Three Learning Koollab LMS

Koollab LMS contains a SQL injection and unsafe deserialization vulnerability in the assessment overall answer endpoint, allowing authenticated attack...

2026-07-29
CVE-2026-63232
Analyzed
9.9
Three Learning Koollab LMS

Koollab LMS contains a SQL injection and unsafe deserialization vulnerability in the assessment reinforcement endpoint, allowing authenticated attacke...

2026-07-29
CVE-2026-63231
Analyzed
8.1
Oracle Koollab LMS

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-fa...

2026-07-29
CVE-2026-63227
Analyzed
9.9
HP LMS

Koollab LMS 5.3.2 contains an unrestricted file upload vulnerability allowing authenticated module designers to upload PHP webshells and execute arbit...

2026-07-29
CVE-2026-63223
Analyzed
9.8
Unknown CodeIgniter4

CodeIgniter4 versions prior to 4.7.4 fail to properly validate file extensions during upload, potentially allowing remote attackers to execute arbitra...

2026-07-31
CVE-2026-63222
Analyzed
7.5
HP CodeIgniter4

CodeIgniter is a PHP full-stack web framework

2026-08-01
CVE-2026-63221
Analyzed
9.4
Unknown CodeIgniter4

A SQL injection vulnerability in the deleteBatch method of CodeIgniter4 allows attackers to bypass escape flags and execute arbitrary SQL commands via...

2026-08-01
CVE-2026-6322
Analyzed
7.5
Fastify fast-uri

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serializ...

2026-05-06
CVE-2026-6321
Analyzed
7.5
Unknown Multiple Products

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions

2026-05-05
CVE-2026-6320
7.5
WordPress is vulnerable

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10

2026-05-03
CVE-2026-6319
7.5
Google Chrome on

Use after free in Payments in Google Chrome on Android prior to 147

2026-04-17
CVE-2026-63188
Analyzed
8.7
Logto Logto

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

2026-08-21
CVE-2026-6318
Analyzed
8.8
Google Chrome prior

Use after free in Codecs in Google Chrome prior to 147

2026-04-17
CVE-2026-6317
Analyzed
8.8
Google Chrome prior

Use after free in Cast in Google Chrome prior to 147

2026-04-16
CVE-2026-6316
Analyzed
8.8
Google Chrome prior

Use after free in Forms in Google Chrome prior to 147

2026-04-16
CVE-2026-6315
Analyzed
8.8
Google Chrome on

Use after free in Permissions in Google Chrome on Android prior to 147

2026-04-16
CVE-2026-6314
8.3
Google Chrome prior

Out of bounds write in GPU in Google Chrome prior to 147

2026-04-16
CVE-2026-6311
Analyzed
8.3
Microsoft Chrome on

Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147

2026-04-16
CVE-2026-63108
Analyzed
8.8
RooCodeInc Roo-Code

Roo Code through 3

2026-07-21
CVE-2026-63106
Analyzed
9.8
HP Ready eCommerce

Ready eCommerce contains an unauthenticated SQL injection vulnerability in the product listing API, allowing attackers to extract database contents an...

2026-08-11
CVE-2026-63101
Analyzed
7.5
FOSSASIA open-event-server

Open Event Server through 1

2026-07-19
CVE-2026-6310
Analyzed
8.3
Google Chrome prior

Use after free in Dawn in Google Chrome prior to 147

2026-04-16
CVE-2026-63094
Analyzed
8.1
SigNoz signoz

SigNoz through 0

2026-07-18
CVE-2026-63093
Analyzed
8.8
Microsoft Cursor

Cursor for Windows version 3

2026-07-18
CVE-2026-63090
Analyzed
8.8
ProFTPD proftpd

ProFTPD before 1

2026-07-21
CVE-2026-6309
8.3
Google Chrome prior

Use after free in Viz in Google Chrome prior to 147

2026-04-16
CVE-2026-63089
Analyzed
9.3
Unknown wg-easy

WireGuard Easy contains a cryptographically weak one-time link token generation vulnerability, allowing unauthenticated attackers to brute-force crede...

2026-07-17
CVE-2026-63088
Analyzed
8.6
Stoatchat Stoatchat

stoatchat before 0

2026-07-17
CVE-2026-63087
Analyzed
9.8
Unknown oncall

An unauthenticated access vulnerability in Grafana OnCall allows remote attackers to hijack plugin tokens, authenticate as administrators, and redirec...

2026-07-17
CVE-2026-63086
Analyzed
8.6
Hugging Face text-generation-inference

text-generation-inference through 3

2026-07-17
CVE-2026-63085
Analyzed
8.8
Axelor Axelor Open Platform

Axelor Open Platform versions 8

2026-07-17