21745 Total CVEs
12907 AI Analyzed
307 CISA KEV
4769 Critical
All Vendors
Showing 2751-2800 of 21745 CVEs Page 56 of 435
CVE-2026-60137
KEV Analyzed
9.5
WordPress Core

WordPress Core is affected by a SQL injection vulnerability that allows unauthenticated attackers to execute unauthorized database queries.

2026-07-22
CVE-2026-60134
Analyzed
8.8
Weintek cMT3092X firmware

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges

2026-07-25
CVE-2026-6013
8.8
D-Link DIR

A vulnerability was detected in D-Link DIR-513 1

2026-04-10
CVE-2026-60122
Analyzed
7.8
Unknown gpsd

gpsd through release-3

2026-07-24
CVE-2026-60121
Analyzed
9.8
HP Flamingo

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint due to improper shell argumen...

2026-07-14
CVE-2026-6012
8.8
D-Link DIR

A security vulnerability has been detected in D-Link DIR-513 1

2026-04-10
CVE-2026-60113
Analyzed
9.8
NASA-AMMOS AIT-DSN

A missing authentication vulnerability in the NASA-AMMOS AIT-DSN Space Link Extension interface allows unauthenticated remote attackers to execute arb...

2026-07-30
CVE-2026-60112
Analyzed
9.8
NASA-AMMOS AIT-GUI

A missing authentication vulnerability in NASA-AMMOS AIT-GUI allows unauthenticated attackers to create sessions and issue arbitrary spacecraft comman...

2026-07-30
CVE-2026-60105
Analyzed
8.6
Monsta Limited Monsta FTP

Monsta FTP before 2

2026-07-09
CVE-2026-60104
Analyzed
8.7
Bitwarden Server

Bitwarden Server before 2026

2026-07-09
CVE-2026-60102
Analyzed
8.8
Horde Vfs

Horde Virtual File System (VFS) API before 3

2026-07-09
CVE-2026-60091
Analyzed
7.2
MervinPraison PraisonAI

PraisonAI before 4

2026-07-12
CVE-2026-60090
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI fails to validate the dimension argument in its knowledge-store backends, enabling SQL/CQL injection via specially crafted strings.

2026-07-12
CVE-2026-60082
9.1
HMBRAND DBI

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source r...

2026-07-20
CVE-2026-60081
7.5
HMBRAND DBI::ProfileData

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array...

2026-07-20
CVE-2026-60080
7.3
Apache Apache Fory

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted F...

2026-08-05
CVE-2026-60030
Analyzed
8.7
Joomla Quix Page Builder Pro extension for Joomla

The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control

2026-07-21
CVE-2026-60028
Analyzed
8.6
Joomla Quix Page Builder Pro extension for Joomla

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability

2026-07-21
CVE-2026-60027
Analyzed
8.7
Joomla Quix Page Builder Pro

The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements

2026-07-21
CVE-2026-60026
Analyzed
8.9
HP Quix Page Builder Pro

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution

2026-07-21
CVE-2026-60025
8.8
Joomla Events Booking extension for Joomla

The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

2026-07-23
CVE-2026-60024
9.8
Joomla Events Booking extension for Joomla

The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

2026-07-23
CVE-2026-6002
8.8
DivvyDrive Multiple Products

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc

2026-05-08
CVE-2026-6001
Analyzed
8.8
ABIS Technology Multiple Products

Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd

2026-05-13
CVE-2026-60009
Analyzed
8.8
Eclipse Foundation Eclipse Theia

In Eclipse Theia versions up to and including 1

2026-08-06
CVE-2026-60005
Analyzed
8.2
F5 NGINX Plus / NGINX Open Source

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module

2026-07-17
CVE-2026-5997
Analyzed
9.8
TOTOLINK A7100RU

A remote OS command injection vulnerability in the Totolink A7100RU CGI handler allows unauthenticated attackers to execute arbitrary system commands...

2026-04-10
CVE-2026-5996
Analyzed
9.8
TOTOLINK A7100RU

A remote OS command injection vulnerability exists in the Totolink A7100RU CGI handler, allowing unauthenticated attackers to execute arbitrary system...

2026-04-10
CVE-2026-5995
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU CGI Handler contains an OS command injection vulnerability in the setMiniuiHomeInfoShow function, allowing remote attackers to ex...

2026-04-10
CVE-2026-5994
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU CGI Handler contains an OS command injection vulnerability in the setTelnetCfg function, allowing remote attackers to execute arb...

2026-04-10
CVE-2026-59936
Analyzed
8.7
Unknown pypdf

pypdf is a free and open-source pure-python PDF library

2026-07-09
CVE-2026-59935
Analyzed
8.7
Unknown pypdf

pypdf is a free and open-source pure-python PDF library

2026-07-09
CVE-2026-5993
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU CGI Handler contains an OS command injection vulnerability in the setWiFiGuestCfg function, allowing remote attackers to execute...

2026-04-10
CVE-2026-5992
8.8
Tenda F451

A vulnerability was determined in Tenda F451 1

2026-04-10
CVE-2026-59913
Analyzed
7.8
Dell Display and Peripheral Manager (DDPM Mac)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2

2026-08-04
CVE-2026-59912
Analyzed
7.8
Dell Display and Peripheral Manager (DDPM Mac)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2

2026-08-04
CVE-2026-59910
Analyzed
7.8
Dell ObjectScale

Dell ObjectScale, versions prior to 4

2026-08-18
CVE-2026-5991
8.8
Tenda F451

A vulnerability was found in Tenda F451 1

2026-04-10
CVE-2026-59902
Analyzed
7.5
Unknown netty

Netty is an asynchronous, event-driven network application framework

2026-08-18
CVE-2026-59901
Analyzed
8.7
Unknown netty

Netty is an asynchronous, event-driven network application framework

2026-07-30
CVE-2026-5990
8.8
Tenda F451

A vulnerability has been found in Tenda F451 1

2026-04-10
CVE-2026-59893
Analyzed
7.5
Unknown sqlparse

sqlparse is a non-validating SQL parser module for Python

2026-08-18
CVE-2026-59891
Analyzed
9.6
Docker sigstore-js

A credential disclosure vulnerability in sigstore-js allows authentication keys to be transmitted to incorrect registries due to improper substring ma...

2026-07-15
CVE-2026-5989
8.8
Tenda F451

A flaw has been found in Tenda F451 1

2026-04-10
CVE-2026-59880
Analyzed
8.7
Unknown immutable-js

Immutable

2026-07-09
CVE-2026-5988
8.8
Tenda F451

A vulnerability was detected in Tenda F451 1

2026-04-10
CVE-2026-59879
Analyzed
8.7
Unknown immutable-js

Immutable

2026-07-09
CVE-2026-59874
Analyzed
8.7
Unknown node-tar

node-tar is a tar archive manipulation library for Node

2026-07-09
CVE-2026-59873
Analyzed
9.2
Unknown node-tar

The node-tar library for Node.js fails to enforce resource limits during archive extraction, allowing attackers to trigger denial-of-service via craft...

2026-07-09
CVE-2026-59866
Analyzed
9.3
Microsoft Kiota

Kiota versions prior to 1.32.5 are vulnerable to path traversal and code injection due to improper sanitization of generated client class names, names...

2026-07-17