23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 2551-2600 of 23295 CVEs Page 52 of 466
CVE-2026-67248
Analyzed
8.7
Asus ADM

A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM

2026-07-30
CVE-2026-67244
Analyzed
8.6
Asus ADM

A format string vulnerability was found in the Notification OAuth settings of ADM

2026-07-30
CVE-2026-67243
Analyzed
8.6
Unknown freo2

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability

2026-08-04
CVE-2026-67208
Analyzed
9.8
Docker Juggle

An unauthenticated remote code execution vulnerability exists in somta Juggle through 1.6.0 due to exposed H2 database consoles with default credentia...

2026-07-31
CVE-2026-67207
Analyzed
8.8
CMS wolfcms

Wolf CMS through 0

2026-07-31
CVE-2026-67206
Analyzed
8.8
CMS wolfcms

Wolf CMS through 0

2026-07-31
CVE-2026-67201
Analyzed
8.6
Unknown v

V through 0

2026-07-30
CVE-2026-67195
Analyzed
8.8
Unknown perspective

Perspective 5

2026-08-05
CVE-2026-67192
Analyzed
8.1
Xlight Xlight FTP Server

Xlight FTP Server before 3

2026-07-30
CVE-2026-67191
Analyzed
9.8
Xlight Xlight FTP Server

A heap-based buffer overflow in Xlight FTP Server prior to 3.9.5 allows remote unauthenticated attackers to corrupt memory via a malformed SSH client...

2026-07-30
CVE-2026-66920
Analyzed
8.2
Pivotick Pivotick

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data

2026-07-29
CVE-2026-6692
Analyzed
8.8
WordPress is vulnerable

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7

2026-05-07
CVE-2026-66918
Analyzed
8.2
Pivotick Pivotick

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style

2026-07-29
CVE-2026-66917
Analyzed
8.6
Joomla JoomGallery extension for Joomla

Joomla Extension - joomgalleryfriends

2026-08-23
CVE-2026-66915
Analyzed
10
Joomla Fabrik extension for Joomla

The Fabrik extension for Joomla is vulnerable to unauthenticated remote code execution via the ajax_calc feature of the calc plugin.

2026-08-11
CVE-2026-6691
Analyzed
7.8
SAP C Driver

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before...

2026-05-07
CVE-2026-66909
Analyzed
9.8
Apache Apache CXF

Apache CXF is vulnerable to remote code execution due to insecure native Java deserialization of inbound JMS ObjectMessages without type restrictions.

2026-08-06
CVE-2026-66908
Analyzed
7.5
Apache Apache Camel

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. T...

2026-08-30
CVE-2026-66907
Analyzed
7.5
Google Apache Camel

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.1...

2026-08-30
CVE-2026-66906
Analyzed
9.1
Microsoft Apache Camel

A relative path traversal vulnerability in the Apache Camel Azure Storage Blob component allows unauthenticated attackers to write files to arbitrary...

2026-08-29
CVE-2026-66898
Analyzed
9.9
Canonical LXD

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations, potentially lead...

2026-08-13
CVE-2026-66897
Analyzed
9.9
Canonical LXD

A path traversal vulnerability in Canonical LXD allows authenticated users to escape container confinement and achieve host root code execution by ove...

2026-08-25
CVE-2026-66875
Analyzed
8.8
Quanovate Mira Firmware

In the Mira hormone monitor device firmware v1

2026-08-12
CVE-2026-66842
Analyzed
8.8
F5 BIG-IP

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request t...

2026-09-03
CVE-2026-66840
Analyzed
8.7
Xing XING CPTrans-ME-X

XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may b...

2026-09-04
CVE-2026-66839
Analyzed
8.4
Unknown NetKids iMark

NetKids iMark, provided by Integrated Systems Technologies, Inc

2026-08-05
CVE-2026-66824
Analyzed
9.2
Unknown lookyloo

A stored cross-site scripting vulnerability in lookyloo allows attackers to inject malicious scripts into the capture tree visualization page, executi...

2026-07-28
CVE-2026-66808
Analyzed
8.8
Microsoft SharePoint

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-08-12
CVE-2026-66805
Analyzed
8.8
Microsoft SharePoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-08-12
CVE-2026-66803
Analyzed
10
Microsoft Azure Cosmos DB

Improper access control in Azure Cosmos DB allows an unauthenticated remote attacker to potentially execute arbitrary code.

2026-08-19
CVE-2026-66800
Analyzed
8.6
Microsoft Azure Data Factory

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network

2026-08-22
CVE-2026-66795
Analyzed
9.1
Red Hat Multicluster Engine for Kubernetes

Improper validation of Certificate Signing Requests in the managedcluster-import-controller allows privileged service accounts to escalate privileges...

2026-08-18
CVE-2026-66792
Analyzed
9.9
Red Hat Multicluster Global Hub

A privilege escalation vulnerability in the multicloud-operators-subscription component allows users to deploy resources with elevated permissions via...

2026-08-18
CVE-2026-6679
Analyzed
8.8
Unknown wolfSSL

A heap buffer overflow could occur in the DTLS 1

2026-06-26
CVE-2026-66787
Analyzed
8.7
Kubernetes Advanced Cluster Management for Kubernetes

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes

2026-08-22
CVE-2026-66786
Analyzed
9.1
Red Hat Advanced Cluster Management for Kubernetes

A code injection vulnerability in Submariner allows authenticated attackers to achieve remote code execution as root by injecting malicious directives...

2026-09-03
CVE-2026-66780
Analyzed
9.9
Red Hat Advanced Cluster Management for Kubernetes

A flaw in the submariner-operator component allows a compromised cluster to perform MITM attacks across a cluster mesh by overwriting endpoint informa...

2026-08-19
CVE-2026-66766
Analyzed
7.5
SAP SAP S/4HANA (Manage Supply Protection)

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability

2026-08-25
CVE-2026-66763
Analyzed
7.9
Intel SAP BusinessObjects Business Intelligence Platform

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic...

2026-08-11
CVE-2026-66758
Analyzed
7.8
Red Hat GIMP (file-fits plugin)

A flaw was found in the file-fits plugin in GIMP

2026-07-28
CVE-2026-66748
Analyzed
8.8
GitHub camaleon-cms

Camaleon CMS versions 2

2026-07-29
CVE-2026-66747
Analyzed
9.8
Zbtlink CPE2801 Firmware

Multiple Zbtlink router models contain an embedded remote control implant that enables unauthenticated remote code execution with root privileges via...

2026-08-06
CVE-2026-66738
Analyzed
8.8
SPIP SPIP

SPIP before 4

2026-08-11
CVE-2026-66731
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66730
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66729
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66713
Analyzed
9.8
Apache Apache Axis2/Java

A deserialization vulnerability in the Apache Axis2/Java clustering component allows unauthenticated attackers to execute arbitrary code if the Tribes...

2026-07-29
CVE-2026-66710
Analyzed
8.1
HP e2pdf

Unauthenticated Local File Inclusion in e2pdf <= 1

2026-08-06
CVE-2026-66708
Analyzed
8.2
WordPress Total Upkeep

Unauthenticated Broken Access Control in Total Upkeep <= 1

2026-08-06
CVE-2026-66691
Analyzed
9.8
WordPress Nokri

A critical broken access control vulnerability exists in the scriptsbundle Nokri WordPress theme, which allows unauthenticated attackers to manipulate...

2026-08-14