20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 2651-2700 of 20297 CVEs Page 54 of 406
CVE-2026-56091
Analyzed
8.2
Apache Apache Shiro

When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass

2026-06-26
CVE-2026-5609
8.8
Tenda i12

A flaw has been found in Tenda i12 1

2026-04-06
CVE-2026-56086
Analyzed
8.8
Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 7

2026-07-09
CVE-2026-5608
Analyzed
8.8
Belkin F9K1122

A vulnerability was detected in Belkin F9K1122 1

2026-04-06
CVE-2026-56078
Analyzed
8.8
PraisonAI MultiAgentMonitor

PraisonAI before 1

2026-06-19
CVE-2026-56075
Analyzed
8.8
PraisonAI PraisonAI

PraisonAI before 4

2026-06-19
CVE-2026-56070
Analyzed
9.3
WordPress Advance Product Search

The Advance Product Search plugin for WordPress is susceptible to an unauthenticated SQL injection vulnerability in versions 1.4.4 and earlier.

2026-06-27
CVE-2026-56069
Analyzed
7.5
Toolset Toolset Forms

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2

2026-06-28
CVE-2026-56068
Analyzed
9.3
WordPress JetEngine

JetEngine versions 3.8.10.2 and earlier are vulnerable to an unauthenticated SQL injection, potentially allowing remote attackers to manipulate databa...

2026-06-27
CVE-2026-56067
Analyzed
9.3
Crocoblock JetSmartFilters

An unauthenticated SQL injection vulnerability in the Crocoblock JetSmartFilters plugin allows remote attackers to execute arbitrary SQL commands.

2026-06-27
CVE-2026-56064
Analyzed
8.5
Themefic Tourfic

Subscriber SQL Injection in Tourfic <= 2

2026-06-27
CVE-2026-56063
Analyzed
8.3
WordPress MailChimp Block

Unauthenticated Broken Access Control in MailChimp Block <= 1

2026-06-27
CVE-2026-56062
Analyzed
9.3
Oooorgle Quotes llama

An unauthenticated SQL injection vulnerability in the Oooorgle Quotes llama plugin allows remote attackers to execute arbitrary SQL commands via unsan...

2026-06-27
CVE-2026-56061
Analyzed
7.5
Swings Subscriptions for WooCommerce

Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1

2026-06-28
CVE-2026-56060
Analyzed
7.5
Tyche Softwares Print Invoice & Delivery Notes for WooCommerce

Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7

2026-06-28
CVE-2026-56059
Analyzed
9.9
WordPress Travel Booking

The Travel Booking WordPress plugin contains an arbitrary file upload vulnerability exploitable by authenticated subscribers.

2026-06-27
CVE-2026-56058
Analyzed
9.9
WordPress Quform

The Quform WordPress plugin is susceptible to an arbitrary file upload vulnerability exploitable by authenticated subscribers.

2026-06-27
CVE-2026-56057
Analyzed
9.8
HP Uncanny Automator Pro

A PHP Object Injection vulnerability in Uncanny Automator Pro allows attackers to execute arbitrary code via malicious serialized input.

2026-06-27
CVE-2026-56055
Analyzed
8.8
HP RealHomes

Subscriber PHP Object Injection in RealHomes <= 4

2026-06-27
CVE-2026-56053
Analyzed
8.8
HP EventPrime

Subscriber PHP Object Injection in EventPrime <= 4

2026-06-26
CVE-2026-5605
8.8
Tenda CH22

A weakness has been identified in Tenda CH22 1

2026-04-06
CVE-2026-56049
Analyzed
8.5
WordPress Post Snippets

Contributor Remote Code Execution (RCE) in Post Snippets <= 4

2026-06-26
CVE-2026-5604
8.8
Tenda CH22

A security flaw has been discovered in Tenda CH22 1

2026-04-06
CVE-2026-56038
Analyzed
8.8
Frisbii Frisbii Pay

Contributor Privilege Escalation in Frisbii Pay <= 1

2026-06-27
CVE-2026-56037
Analyzed
8.8
WordPress Themify Popup

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection

2026-07-03
CVE-2026-56036
Analyzed
9.3
WordPress 워드프레스 결제 심플페이 (WordPress Simple Pay)

An unauthenticated SQL injection vulnerability exists in the Codemstory 워드프레스 결제 심플페이 plugin, allowing remote attackers to execute arbitrary database...

2026-06-27
CVE-2026-56035
Analyzed
8.6
Cory BitFire Security

Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5

2026-06-27
CVE-2026-56034
Analyzed
9.3
Online Web Tutor Library Management System

The Library Management System by Online Web Tutor is affected by an unauthenticated SQL injection vulnerability in versions 3.5.7 and earlier.

2026-06-27
CVE-2026-56033
Analyzed
9.8
Unknown Dokan Pro

A critical unauthenticated privilege escalation vulnerability in Dokan Pro allows attackers to bypass security controls and obtain administrative acce...

2026-06-27
CVE-2026-56032
Analyzed
9.8
HP Buddyboss Platform

A PHP Object Injection vulnerability exists in the Buddyboss Platform plugin that may allow unauthenticated or low-privileged attackers to execute arb...

2026-06-27
CVE-2026-56031
Analyzed
8.1
HP Automator

Unauthenticated PHP Object Injection in Uncanny Automator <= 7

2026-06-27
CVE-2026-56030
Analyzed
9.8
WordPress Paytium

A critical unauthenticated privilege escalation vulnerability in the Paytium plugin allows remote attackers to gain unauthorized administrative privil...

2026-06-27
CVE-2026-56029
Analyzed
7.5
CorvusPay WooCommerce Payment Gateway

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2

2026-06-28
CVE-2026-56028
Analyzed
9.8
WordPress Easy Elements for Elementor

A critical unauthenticated privilege escalation vulnerability exists in the Easy Elements for Elementor plugin, allowing attackers to elevate their ac...

2026-06-27
CVE-2026-56027
Analyzed
9.9
WordPress Booster for WooCommerce

Booster for WooCommerce contains an arbitrary file upload vulnerability allowing unauthenticated remote code execution.

2026-06-27
CVE-2026-56025
Analyzed
7.5
Paymob Paymob for WooCommerce

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4

2026-06-28
CVE-2026-56018
Analyzed
7.5
Unknown JavaScript::Minifier::XS

JavaScript::Minifier::XS versions before 0

2026-06-30
CVE-2026-56017
Analyzed
7.5
Unknown JavaScript::Minifier::XS

JavaScript::Minifier::XS versions before 0

2026-06-30
CVE-2026-56015
Analyzed
9.1
TPODER Net::IP::LPM

The Perl module Net::IP::LPM allows a heap out-of-bounds read due to improper validation of prefix lengths in the add() function.

2026-07-07
CVE-2026-56012
Analyzed
8.5
David Lingren Media Library Assistant

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Bli...

2026-06-20
CVE-2026-56010
Analyzed
8.8
WordPress Abandoned Cart Pro for WooCommerce

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10

2026-06-27
CVE-2026-56008
Analyzed
8.8
WordPress Fusion Builder

Contributor Privilege Escalation in Fusion Builder <= 3

2026-06-27
CVE-2026-56004
Analyzed
10
Unknown buildservice

A shellcode injection vulnerability in the obs tar_scm source service allows attackers to execute arbitrary code via a malicious _service file.

2026-07-03
CVE-2026-56003
Analyzed
8.5
X.Org libXfont2

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfo...

2026-07-09
CVE-2026-56002
Analyzed
8.5
Linux libXfont2

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2

2026-07-09
CVE-2026-56001
Analyzed
8.5
X.Org libXfont2

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2

2026-07-09
CVE-2026-56000
Analyzed
9
X.Org xorg-x11-server

A heap use-after-free vulnerability in X.Org xorg-x11-server and xwayland allows local attackers with a GLX connection to trigger memory corruption vi...

2026-07-08
CVE-2026-55999
Analyzed
8.5
Linux xorg-server

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21

2026-07-08
CVE-2026-55997
Analyzed
8.8
Rancher Rancher

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster

2026-08-05
CVE-2026-55995
Analyzed
8.7
F5 open-iscsi

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS

2026-07-30