21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 2401-2450 of 21637 CVEs Page 49 of 433
CVE-2026-61948
Analyzed
9.3
WordPress WPDM – Premium Packages

The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote data...

2026-07-24
CVE-2026-6194
8.8
TOTOLINK Multiple Products

A weakness has been identified in Totolink A3002MU B20211125

2026-04-14
CVE-2026-6193
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1

2026-04-14
CVE-2026-61900
Analyzed
10
Joomla jDownloads extension for Joomla

The jDownloads extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote code ex...

2026-07-21
CVE-2026-61899
Analyzed
7.5
Apache Apache Tapestry

Vulnerability in tapestry-core in Apache Tapestry 5

2026-08-11
CVE-2026-61892
Analyzed
8.8
Weintek cMT3092X firmware

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges

2026-07-25
CVE-2026-6189
7.3
HP Multiple Products

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-14
CVE-2026-61884
Analyzed
9.8
Tycon Systems TPDIN-Monitor-WEB2

The web interface of Tycon Systems TPDIN-Monitor-WEB2 fails to validate credentials, allowing unauthenticated remote attackers to bypass login and obt...

2026-07-25
CVE-2026-6188
7.3
HP Multiple Products

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-14
CVE-2026-61876
Analyzed
8.8
GitHub LuCI

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML mar...

2026-07-14
CVE-2026-61875
Analyzed
8.8
OpenWrt LuCI

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMa...

2026-07-17
CVE-2026-6187
7.3
HP Multiple Products

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-14
CVE-2026-6186
8.8
UTT Multiple Products

A security vulnerability has been detected in UTT HiPER 1200GW up to 2

2026-04-14
CVE-2026-61836
Analyzed
8.6
Directus Directus

Directus is a real-time API and App dashboard for managing SQL database content

2026-07-17
CVE-2026-6183
7.3
HP Multiple Products

A security flaw has been discovered in code-projects Simple Content Management System 1

2026-04-14
CVE-2026-61828
Analyzed
8.5
NixOS nixpkgs

Nixpkgs is a collection of software packages that can be installed with the Nix package manager

2026-07-17
CVE-2026-6182
7.3
HP Multiple Products

A vulnerability was identified in code-projects Simple Content Management System 1

2026-04-14
CVE-2026-61808
Analyzed
9.8
HKUDS LightRAG

LightRAG versions through 1.5.4 expose an unauthenticated API server, allowing remote attackers to manipulate knowledge graphs, access documents, and...

2026-08-08
CVE-2026-61684
Analyzed
8.8
Labring FastGPT

FastGPT is a knowledge-based AI application platform

2026-07-16
CVE-2026-6168
8.8
TOTOLINK Multiple Products

A flaw has been found in TOTOLINK A7000R up to 9

2026-04-13
CVE-2026-6167
7.3
HP Multiple Products

A vulnerability was detected in code-projects Faculty Management System 1

2026-04-13
CVE-2026-61666
Analyzed
8.9
Unknown websocket-driver-ruby

websocket-driver is a WebSocket protocol handler with pluggable I/O

2026-08-18
CVE-2026-6166
7.3
HP Multiple Products

A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6165
7.3
HP Multiple Products

A weakness has been identified in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6164
7.3
HP Multiple Products

A security flaw has been discovered in code-projects Lost and Found Thing Management 1

2026-04-13
CVE-2026-6163
7.3
HP Multiple Products

A vulnerability was identified in code-projects Lost and Found Thing Management 1

2026-04-13
CVE-2026-6161
7.3
HP of the

A vulnerability was determined in code-projects Simple ChatBox up to 1

2026-04-13
CVE-2026-6158
7.3
TOTOLINK Multiple Products

A flaw has been found in Totolink N300RH 6

2026-04-13
CVE-2026-61574
Analyzed
8.8
Unknown authentik

authentik is an open-source identity provider

2026-08-19
CVE-2026-6157
8.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink A800R 4

2026-04-13
CVE-2026-6156
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU allows remote OS command injection via the setIpQosRules function in the CGI handler.

2026-04-13
CVE-2026-61556
Analyzed
8.7
GitHub LiquidJS

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-08-21
CVE-2026-6155
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU is vulnerable to remote OS command injection via the setWanCfg function in the CGI handler.

2026-04-13
CVE-2026-6154
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU allows remote OS command injection via the setWizardCfg function within the CGI handler.

2026-04-13
CVE-2026-6153
7.3
HP Multiple Products

A vulnerability was identified in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6152
7.3
HP Multiple Products

A vulnerability was determined in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-61518
Analyzed
8.8
ISPConfig ispconfig3

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API

2026-08-20
CVE-2026-61515
Analyzed
9.8
Puwell Technology IP Camera

Puwell IP Camera firmware versions 2.x through 4.x contain an unauthenticated command injection vulnerability in the DebugShell interface on TCP port...

2026-08-05
CVE-2026-61514
Analyzed
9.8
Puwell Technology IP Camera

Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability, allowing unauthenticated attackers to control devic...

2026-08-05
CVE-2026-61511
Analyzed
9.8
HP vBulletin

vBulletin contains an eval injection vulnerability in the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code...

2026-07-28
CVE-2026-6151
7.3
HP Multiple Products

A vulnerability was found in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-61500
Analyzed
9.8
Rejetto HFS

Rejetto HFS uses a predictable PRNG for session-cookie signing, allowing unauthenticated attackers to forge administrator session cookies and achieve...

2026-07-14
CVE-2026-61498
Analyzed
9.8
HP Flamingo

Vitec Flamingo 4.12.2 is susceptible to unauthenticated OS command injection via the admin/ajax/gen_graphs.php endpoint due to insufficient input sani...

2026-07-14
CVE-2026-6149
Analyzed
7.3
HP Vehicle Showroom Management System

A flaw has been found in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-61486
Analyzed
9.8
Apache Apache Lucy

A stack-based buffer overflow vulnerability exists in Apache Lucy, potentially allowing attackers to execute arbitrary code.

2026-08-14
CVE-2026-61484
Analyzed
9.8
Apache Apache Lucy

Apache Lucy is vulnerable to a deserialization of untrusted data issue, potentially allowing remote code execution due to improper input handling.

2026-08-14
CVE-2026-6148
Analyzed
7.3
HP Vehicle Showroom Management System

A vulnerability was detected in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6147
Analyzed
8.8
WordPress LightSync Pro

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functio...

2026-08-05
CVE-2026-61463
Analyzed
8.8
Unknown shiori

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without...

2026-07-14
CVE-2026-61462
Analyzed
8.6
GitLab mcp-gitlab

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index

2026-07-14