21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 2801-2850 of 21637 CVEs Page 57 of 433
CVE-2026-59642
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59641
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59640
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-5964
Analyzed
9.8
Digiwin EasyFlow .NET

Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.

2026-04-20
CVE-2026-59639
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-59638
Analyzed
9.3
Unknown BC-JAVA

Bouncy Castle for Java has an insecure default configuration for the JSSE hostname verifier, which incorrectly enables CN-fallback.

2026-08-03
CVE-2026-5963
Analyzed
9.8
Digiwin EasyFlow .NET

Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.

2026-04-20
CVE-2026-59555
Analyzed
10
WordPress Participants Database

The Roland Barker Participants Database plugin for WordPress contains an unauthenticated arbitrary file deletion vulnerability due to improper path va...

2026-07-24
CVE-2026-59551
Analyzed
8.5
WordPress rtMedia for WordPress, BuddyPress and bbPress

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4

2026-07-28
CVE-2026-59550
Analyzed
9.3
WordPress AWP Classifieds

An unauthenticated SQL injection vulnerability in AWP Classifieds allows remote attackers to execute arbitrary SQL commands via the plugin, potentiall...

2026-07-28
CVE-2026-5955
Analyzed
9.8
Unknown BiEticaret

BiEticaret is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL commands against the database.

2026-07-10
CVE-2026-59549
Analyzed
9.3
WordPress rtMedia for WordPress, BuddyPress and bbPress

An unauthenticated SQL injection vulnerability exists in the rtMedia for WordPress plugin, allowing attackers to manipulate database queries via vulne...

2026-07-28
CVE-2026-59548
Analyzed
7.5
WordPress Byteflows Travel & Hotel Booking

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1

2026-07-28
CVE-2026-59546
Analyzed
7.4
WordPress Hide My WP Ghost

Subscriber Broken Authentication in Hide My WP Ghost <= 7

2026-07-28
CVE-2026-59545
Analyzed
8.1
Discord Discord Integration Plugin

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2

2026-07-24
CVE-2026-59544
Analyzed
9.8
HP Thrive Quiz Builder

Thrive Quiz Builder contains an unauthenticated PHP Object Injection vulnerability in versions 10.9.3.0 and below, allowing remote attackers to execut...

2026-07-24
CVE-2026-59543
Analyzed
9.9
WordPress Advanced Views

The WPLake Advanced Views WordPress plugin contains a code injection vulnerability allowing remote code execution for authenticated subscribers.

2026-07-24
CVE-2026-59542
Analyzed
7.7
WordPress Kali Forms

Subscriber Arbitrary File Deletion in Kali Forms <= 2

2026-07-24
CVE-2026-59541
Analyzed
8.8
WordPress WP BASE Booking

Subscriber Privilege Escalation in WP BASE Booking <= 6

2026-07-24
CVE-2026-59540
Analyzed
9.8
WordPress SMS Alert Order Notifications

The SMS Alert Order Notifications WordPress plugin contains an unauthenticated privilege escalation vulnerability that allows attackers to gain unauth...

2026-07-24
CVE-2026-59539
Analyzed
7.5
WordPress Paid Member Subscriptions

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3

2026-07-28
CVE-2026-59538
Analyzed
9.3
Ruben Garcia GamiPress

A critical, unauthenticated SQL injection vulnerability exists in the GamiPress plugin, enabling remote attackers to manipulate database queries.

2026-07-28
CVE-2026-59537
Analyzed
7.6
WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2

2026-07-28
CVE-2026-59536
Analyzed
7.5
WordPress CoCart – Headless ecommerce

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4

2026-07-28
CVE-2026-59535
Analyzed
7.3
WordPress Thrive Product Manager

Unauthenticated Broken Access Control in Thrive Product Manager <= 10

2026-07-28
CVE-2026-59534
Analyzed
7.5
WordPress Post My CF7 Form

Unauthenticated Broken Access Control in Post My CF7 Form <= 6

2026-07-28
CVE-2026-59533
Analyzed
9.3
WordPress Relevanssi Light

An unauthenticated SQL injection vulnerability in the Relevanssi Light WordPress plugin allows remote attackers to compromise the database.

2026-07-28
CVE-2026-59532
Analyzed
7.5
WordPress Booking and Rental Manager

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2

2026-07-28
CVE-2026-59531
Analyzed
7.5
WordPress Falcon – WordPress Optimizations & Tweaks

Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2

2026-07-28
CVE-2026-59530
Analyzed
7.5
WordPress Stripe For WooCommerce

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4

2026-07-28
CVE-2026-59529
Analyzed
7.5
WordPress Ebook Store

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6

2026-07-28
CVE-2026-59528
Analyzed
7.5
WordPress Discounted Shipping Rates

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1

2026-07-28
CVE-2026-59527
Analyzed
9.3
WordPress MapSVG

A critical SQL injection vulnerability in the MapSVG plugin for WordPress allows unauthenticated attackers to execute arbitrary SQL commands.

2026-07-28
CVE-2026-59526
Analyzed
9.3
WordPress MapSVG

MapSVG contains an unauthenticated SQL injection vulnerability in versions 8.14.0 and prior, allowing remote attackers to execute arbitrary database q...

2026-07-24
CVE-2026-59525
Analyzed
9.3
WordPress Participants Database

The Participants Database WordPress plugin before version 2.7.8.4 is susceptible to an unauthenticated SQL injection vulnerability.

2026-07-24
CVE-2026-59518
Analyzed
9.8
HP Directorist

The Directorist plugin for WordPress is vulnerable to PHP Object Injection via deserialization of untrusted data, allowing unauthenticated attackers t...

2026-07-14
CVE-2026-59515
Analyzed
9.3
WordPress AIWU

The Sergey AIWU WordPress plugin contains a Blind SQL Injection vulnerability, permitting unauthenticated attackers to execute malicious database quer...

2026-07-14
CVE-2026-59514
Analyzed
9.3
WordPress BuddyBoss Platform

The BuddyBoss Platform plugin for WordPress contains an unauthenticated SQL injection vulnerability that allows attackers to execute arbitrary databas...

2026-07-24
CVE-2026-59510
Analyzed
7.1
AIL Project AIL Framework

AIL Framework contains a path traversal vulnerability in its PDF object handling

2026-07-06
CVE-2026-59509
Analyzed
9.2
Unknown cve-search

The cve-search application is vulnerable to improper input validation in its API, allowing unauthenticated remote attackers to read arbitrary MongoDB...

2026-07-06
CVE-2026-59505
Analyzed
8.6
Priority Portal Generator addon to Priority ERP

CWE-284: Improper Access Control

2026-08-15
CVE-2026-59500
Analyzed
10
Priority Portal Generator addon to Priority ERP

The Portal Generator addon to Priority ERP is vulnerable to improper authentication, which may allow unauthorized access to the application infrastruc...

2026-08-14
CVE-2026-59499
Analyzed
8.6
Soft Solutions Portal Generator addon to Priority ERP

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

2026-08-15
CVE-2026-5947
Analyzed
7.5
Undefined Multiple Products

Undefined behavior may result due to a race condition leading to a use-after-free violation

2026-05-22
CVE-2026-5946
Analyzed
7.5
AWS have been

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `H...

2026-05-22
CVE-2026-5944
8.2
Cisco Intersight Device

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central

2026-04-29
CVE-2026-5943
7.8
Infor Multiple Products

Document structural anomalies caused inconsistencies between page element relationships and internal index states

2026-04-28
CVE-2026-5941
7.8
Arch Multiple Products

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to inva...

2026-04-28
CVE-2026-5940
7.8
Unknown Multiple Products

Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes

2026-04-28
CVE-2026-5936
8.5
Unknown Multiple Products

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations

2026-04-13