23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 2451-2500 of 23295 CVEs Page 50 of 466
CVE-2026-6784
Analyzed
7.5
Unknown Multiple Products

Memory safety bugs present in Firefox 149 and Thunderbird 149

2026-04-22
CVE-2026-67822
Analyzed
9.8
Tenda W6-S

A stack-based buffer overflow in the Tenda W6-S web interface allows remote, unauthenticated attackers to trigger a crash or execute arbitrary code vi...

2026-08-01
CVE-2026-6782
Analyzed
7.5
Infor Multiple Products

Information disclosure in the IP Protection component

2026-04-22
CVE-2026-6781
Analyzed
7.5
Unknown Multiple Products

Denial-of-service in the Audio/Video: Playback component

2026-04-22
CVE-2026-6780
Analyzed
7.5
Unknown Multiple Products

Denial-of-service in the Audio/Video: Playback component

2026-04-22
CVE-2026-6776
Analyzed
7.8
Unknown Multiple Products

Incorrect boundary conditions in the WebRTC: Networking component

2026-04-22
CVE-2026-6773
Analyzed
7.5
Unknown Multiple Products

Denial-of-service due to integer overflow in the Graphics: WebGPU component

2026-04-22
CVE-2026-6772
Analyzed
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Libraries component in NSS

2026-04-22
CVE-2026-6771
Analyzed
9.8
Mitigation Multiple Products

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 14...

2026-04-22
CVE-2026-6769
Analyzed
8.8
Privilege Multiple Products

Privilege escalation in the Debugger component

2026-04-22
CVE-2026-67689
Analyzed
9.8
FineAdmin FineAdmin.Mvc

A SQL injection vulnerability in FineAdmin V1.0 allows unauthenticated remote attackers to execute arbitrary code via the field and order parameters i...

2026-08-27
CVE-2026-67688
Analyzed
9.8
ICS-Park Smart Park Management System

The ICS-Park Smart Park Management System v2.0 is vulnerable to an unrestricted file upload flaw, which allows unauthenticated remote attackers to exe...

2026-08-27
CVE-2026-67687
Analyzed
8.8
GitHub Smart Park Management System

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleControl...

2026-08-27
CVE-2026-6768
Analyzed
9.8
Mitigation Multiple Products

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

2026-04-22
CVE-2026-67678
Analyzed
9.8
GitHub DocSys

A critical file upload vulnerability in RainyGao-GitHub DocSys v.2.02.80 allows remote, unauthenticated attackers to execute arbitrary code on the hos...

2026-08-25
CVE-2026-6766
Analyzed
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Libraries component in NSS

2026-04-22
CVE-2026-67623
Analyzed
8.8
Mistral AI mistral-vibe

Mistral Vibe before 2

2026-08-06
CVE-2026-67622
Analyzed
9.9
FlowiseAI Flowise

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in its OpenAI Assistants integration that allows authenticated attack...

2026-08-07
CVE-2026-67620
Analyzed
7.7
GitHub Flowise

Flowise through 3

2026-08-09
CVE-2026-67614
Analyzed
9.8
Unknown cyberpanel

CyberPanel versions prior to 3.0.0 contain a hard-coded JWT secret in the WebTerminal service, allowing unauthenticated attackers to forge tokens and...

2026-08-14
CVE-2026-67611
Analyzed
8.1
OpenEMR OpenEMR

OpenEMR through 8

2026-08-04
CVE-2026-67610
Analyzed
8.1
OpenEMR OpenEMR

OpenEMR through 8

2026-08-04
CVE-2026-6761
Analyzed
8.8
Privilege Multiple Products

Privilege escalation in the Networking component

2026-04-22
CVE-2026-67609
Analyzed
7.8
Telenia Software TVox

Telenia Software TVox 26

2026-08-04
CVE-2026-67595
Analyzed
8.1
WebReinvent VaahCMS

VaahCMS versions 2

2026-07-30
CVE-2026-67594
Analyzed
9.8
Unknown Spikster

Spikster contains a missing authentication vulnerability in its API routing, allowing unauthenticated remote attackers to access approximately 50 sens...

2026-07-31
CVE-2026-67592
Analyzed
7.5
Apache Apache Qpid ProtonJ2

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resou...

2026-08-27
CVE-2026-6759
Analyzed
7.5
Unknown Multiple Products

Use-after-free in the Widget: Cocoa component

2026-04-22
CVE-2026-67589
Analyzed
7.5
Apache Apache Qpid ProtonJ2

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issu...

2026-08-27
CVE-2026-67588
Analyzed
7.5
Apache Apache Qpid ProtonJ2

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue aff...

2026-08-27
CVE-2026-67587
Analyzed
8.8
Apache Apache Airflow

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored...

2026-08-14
CVE-2026-67585
Analyzed
8.7
DivvyPayHQ absinthe_federation

Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abor...

2026-08-08
CVE-2026-67581
Analyzed
8.7
ZenHive mpp

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on...

2026-08-21
CVE-2026-6758
Analyzed
7.5
Unknown Multiple Products

Use-after-free in the JavaScript: WebAssembly component

2026-04-22
CVE-2026-67578
Analyzed
7.5
FURUNO FA-50

FA-50 all versions miss authentication for some configuration

2026-08-25
CVE-2026-6756
Analyzed
7.5
Google Multiple Products

Mitigation bypass in Firefox for Android

2026-04-23
CVE-2026-67552
Analyzed
7.5
Apache Apache Qpid Proton Dotnet

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects...

2026-08-27
CVE-2026-67551
Analyzed
7.5
Apache Apache Qpid Proton Dotnet

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue...

2026-08-27
CVE-2026-6754
Analyzed
7.5
JavaScript Multiple Products

Use-after-free in the JavaScript Engine component

2026-04-22
CVE-2026-67527
Analyzed
7.6
OpenProject OpenProject

OpenProject is open-source, web-based project management software

2026-08-01
CVE-2026-6750
Analyzed
8.8
Privilege Multiple Products

Privilege escalation in the Graphics: WebRender component

2026-04-22
CVE-2026-6749
Analyzed
7.5
Infor Multiple Products

Information disclosure due to uninitialized memory in the Graphics: Canvas2D component

2026-04-22
CVE-2026-6748
Analyzed
9.8
Uninitialized Multiple Products

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and T...

2026-04-22
CVE-2026-6747
Analyzed
7.5
Unknown Multiple Products

Use-after-free in the WebRTC component

2026-04-22
CVE-2026-67465
Analyzed
7.5
Apache Apache Qpid Proton Dotnet

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue aff...

2026-08-27
CVE-2026-6746
Analyzed
7.5
Unknown Multiple Products

Use-after-free in the DOM: Core & HTML component

2026-04-22
CVE-2026-67436
Analyzed
8.3
Linux monitoring-plugins

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems

2026-07-30
CVE-2026-67431
Analyzed
8.3
Model Context Protocol ruby-sdk

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients

2026-07-30
CVE-2026-67429
Analyzed
10
Unknown flyto-core

Flyto-core fails to properly validate directory paths in its file-writing modules, enabling unauthenticated path traversal and arbitrary file write op...

2026-07-30
CVE-2026-67428
Analyzed
8.5
Unknown flyto-core

Flyto2 Core is an execution kernel for automation and AI-agent workflows

2026-07-30