24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 22651-22700 of 24021 CVEs Page 454 of 481
CVE-2024-27708
Analyzed
9.6
Unknown

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via t...

2025-12-23
CVE-2024-27686
Analyzed
7.5
MikroTik RouterOS

Mikrotik RouterOS (x86) 6

2026-05-09
CVE-2024-27253
Analyzed
10
IBM DOORS Next

IBM DOORS Next contains an authentication bypass vulnerability, allowing an attacker to perform unauthorized activities within the system.

2026-08-13
CVE-2024-27199
KEV Analyzed
9.5
JetBrains TeamCity

JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-21
CVE-2024-26480
Analyzed
7.5

An issue in Statping-ng v

2026-02-13
CVE-2024-26477
Analyzed
7.5

An issue in Statping-ng v

2026-02-13
CVE-2024-26009
Analyzed
8.1
Fortinet FortiProxy

An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS version 6

2025-08-12
CVE-2024-25621
Analyzed
7.3
containerd containerd

containerd is an open-source container runtime

2025-11-06
CVE-2024-25183
Analyzed
7.5
Unknown

givanz VvvebJs 1

2025-12-31
CVE-2024-24909
Analyzed
8.8
Dell OpenManage

Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin

2026-06-17
CVE-2024-24844
Analyzed
7.5
IdeaBox Creations PowerPack Pro for Elementor

Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security...

2025-12-24
CVE-2024-2374
Analyzed
7.5
WSO2 WSO2 API Manager

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entitie...

2026-04-17
CVE-2024-23564
Analyzed
9.1
HCL Software Aftermarket EPC

HCL Aftermarket EPC contains a business logic flaw that allows unauthenticated users to retrieve passwords from the server and redirect them to attack...

2026-07-18
CVE-2024-2356
Analyzed
9.6
parisneo parisneo/lollms-webui

A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within...

2026-02-02
CVE-2024-21947
Analyzed
7.5
AMD AMD Ryzen™ Threadripper™ 3000 Processors

Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in...

2025-09-07
CVE-2024-21923
Analyzed
7.3
AMD AMD StoreMI™

Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code executio...

2025-11-23
CVE-2024-21922
Analyzed
7.3
AMD AMD StoreMI™

A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code executi...

2025-11-23
CVE-2024-21182
KEV Analyzed
9.5
Oracle WebLogic Server

Oracle WebLogic Server contains an unspecified vulnerability that is currently being exploited in the wild.

2026-06-02
CVE-2024-2104
Analyzed
8.8
JBL LIVE PRO 2 TWS

Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control comman...

2025-12-11
CVE-2024-1708
KEV Analyzed
9.5
ConnectWise ScreenConnect

ConnectWise ScreenConnect Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-29
CVE-2024-1524
Analyzed
7.7
WSO2 WSO2 API Manager

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's...

2026-02-24
CVE-2024-14041
Analyzed
8.2

In Bouncy Castle for Java from 1

2026-07-28
CVE-2024-14037
Analyzed
9.8
Guangzhou Red Sea Cloud Computing Red Sea Cloud eHR

Guangzhou Red Sea Cloud eHR contains an arbitrary file upload vulnerability in the PtFjk.mob servlet, allowing unauthenticated attackers to achieve re...

2026-07-03
CVE-2024-14034
Analyzed
9.8
Belden Hirschmann HiEOS LRS11

An authentication bypass in the Hirschmann HiEOS HTTP(S) management module allows unauthenticated attackers to gain administrative access and modify d...

2026-04-03
CVE-2024-14033
Analyzed
7.5
Belden Hirschmann EagleSDV

Hirschmann Industrial IT products (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) contain a heap overflow vulnerability in t...

2026-04-03
CVE-2024-14032
Analyzed
7.8
Twitch Twitch Studio

Twitch Studio version 0

2026-04-07
CVE-2024-14031
Analyzed
8.1
YVES Sereal::Encoder

Sereal::Encoder versions from 4

2026-04-01
CVE-2024-14030
Analyzed
8.1
YVES Sereal::Decoder

Sereal::Decoder versions from 4

2026-04-01
CVE-2024-14015
Analyzed
7.1
WordPress WordPress eCommerce Plugin

The WordPress eCommerce Plugin WordPress plugin through 2

2025-11-25
CVE-2024-14010
Analyzed
9.8
Typora Typora

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Atta...

2025-12-13
CVE-2024-13974
Analyzed
8.1
Sophos Sophos Firewall

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21

2025-07-22
CVE-2024-13972
Analyzed
8.8
Sophos

A vulnerability related to registry permissions in the Intercept X for Windows updater prior to version 2024

2025-07-17
CVE-2024-13807
Analyzed
7.5
xagio Xagio SEO – AI Powered SEO

The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7

2025-08-28
CVE-2024-13786
Analyzed
9.8

The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted...

2025-07-05
CVE-2024-13784
Analyzed
9.8
reputeinfosystems

The ARForms WordPress plugin is vulnerable to PHP Object Injection via deserialization of untrusted input, potentially allowing code execution if a PO...

2026-08-16
CVE-2024-13507
Analyzed
7.5
paoltaia

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via t...

2025-07-28
CVE-2024-13342
Analyzed
8.1
Pluggabl

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_orde...

2025-08-29
CVE-2024-13174
Analyzed
8.6
E1 Informatics Web Application

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web Application allows SQL Inject...

2025-09-16
CVE-2024-13151
Analyzed
10
Authorization Bypass Through Auto Service Software

Authorization Bypass Through User-Controlled SQL Primary Key, CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje...

2025-09-18
CVE-2024-13150
Analyzed
9.8
Fayton Software and Consulting Services fayton.pro ERP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software and Consulting Services fayton.P...

2025-09-29
CVE-2024-13149
Analyzed
9.8
Arma Store Armalife

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized...

2025-09-16
CVE-2024-13068
Analyzed
7.3
Akinsoft LimonDesk

Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing

2025-09-03
CVE-2024-12925
Analyzed
7.3
Akınsoft QR Menü

Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting

2025-09-02
CVE-2024-12918
Analyzed
8.8
Agito Computer Health4All

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Health4All allows SQL Injection

2026-06-02
CVE-2024-12916
Analyzed
8.8
Agito Computer Life4All

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Life4All allows SQL Injection

2026-06-02
CVE-2024-12913
Analyzed
8.8
Megatek Communication System Azora Wireless Network Management

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Netw...

2025-09-16
CVE-2024-12651
Analyzed
8.5
PTT HGS Mobile App

Exposed Dangerous Method or Function vulnerability in PTT Inc

2026-06-02
CVE-2024-12612
Analyzed
7.5
dasinfomedia School Management System for Wordpress

The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters across multiple AJAX action in a...

2025-08-17
CVE-2024-12367
Analyzed
8.6
Vegagrup Software Vega Master

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing

2025-09-16
CVE-2024-11976
Analyzed
7.3
BuddyPress BuddyPress

The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14

2026-01-24