20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 2901-2950 of 20297 CVEs Page 59 of 406
CVE-2026-54690
Analyzed
8.2
Unknown datamodel-code-generator

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec

2026-07-29
CVE-2026-54680
Analyzed
9.9
Kubernetes logging-operator

The logging-operator for Kubernetes fails to properly escape input in Fluentd configuration rendering, allowing authenticated users to execute arbitra...

2026-07-30
CVE-2026-54673
Analyzed
8.2
Unknown electron-builder

electron-updater allows for automatic updates for Electron apps

2026-07-01
CVE-2026-54672
Analyzed
7.8
Unknown electron-builder

electron-updater allows for automatic updates for Electron apps

2026-07-01
CVE-2026-54666
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification

2026-07-30
CVE-2026-54664
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification

2026-07-30
CVE-2026-54662
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications

2026-07-30
CVE-2026-54661
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification

2026-07-30
CVE-2026-54658
Analyzed
9.8
Hypequery Hypequery

A SQL injection vulnerability in the Hypequery TypeScript semantic layer for ClickHouse allows unauthenticated attackers to execute arbitrary SQL comm...

2026-07-29
CVE-2026-54653
Analyzed
8.8
Unknown datamodel-code-generator

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec

2026-07-29
CVE-2026-54652
Analyzed
8.1
Unknown Frigate

Frigate is an open source network video recorder

2026-07-09
CVE-2026-54650
Analyzed
8.6
Unknown openhole

openhole exposes localhost to the internet in one command

2026-07-29
CVE-2026-5465
8.8
WordPress is vulnerable

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to...

2026-04-07
CVE-2026-5464
7.2
Google Analytics Dashboard

The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin...

2026-04-24
CVE-2026-54639
Analyzed
8.8
Style Dictionary Style Dictionary

Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4

2026-06-24
CVE-2026-5463
Analyzed
8.6
Unknown Multiple Products

Command injection vulnerability in console

2026-04-03
CVE-2026-54609
Analyzed
8.6
Unknown QTINeon

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library

2026-07-29
CVE-2026-54603
Analyzed
8.6
Ruby-OAuth oauth2

OAuth2 is a Ruby wrapper for the OAuth 2

2026-07-29
CVE-2026-54593
Analyzed
8.1
Pterodactyl Panel

Pterodactyl is a free, open-source game server management panel

2026-07-30
CVE-2026-54592
Analyzed
7.5
Unknown Oj (Optimized JSON)

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem

2026-07-01
CVE-2026-54591
Analyzed
8.1
Ronf AsyncSSH

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framew...

2026-07-09
CVE-2026-54588
Analyzed
9.6
Unknown poweradmin

Poweradmin fails to validate the HTTP_HOST header, allowing unauthenticated attackers to poison redirect URIs and hijack user authentication tokens, l...

2026-06-24
CVE-2026-54574
Analyzed
8.2
Termux proot-distro

proot-distro is a utility for managing proot containers

2026-07-30
CVE-2026-54555
Analyzed
7.8
RTK-AI RTK

rtk filters and compresses command outputs before they reach your LLM context

2026-06-24
CVE-2026-54540
Analyzed
8.8
HP Pheditor

Pheditor is a single-file editor and file manager written in PHP

2026-07-28
CVE-2026-54527
Analyzed
9.3
JupyterLab jupyterlab-git

JupyterLab Git is vulnerable to stored Cross-site Scripting (XSS) via crafted filenames, allowing JavaScript execution when a victim views the rename...

2026-07-09
CVE-2026-54526
Analyzed
8.9
Kubernetes Argo Workflows

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

2026-07-17
CVE-2026-54513
Analyzed
8.1
FasterXML jackson-databind

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor

2026-06-24
CVE-2026-54512
Analyzed
8.1
FasterXML jackson-databind

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor

2026-06-24
CVE-2026-54498
Analyzed
8.7
ViewComponent view_component

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails

2026-07-18
CVE-2026-54496
Analyzed
9.3
ZcashFoundation zebra

A critical flaw in the variable-base scalar multiplication gadget within Zcash-related components allows an attacker to produce valid proofs for Orcha...

2026-07-18
CVE-2026-54469
Analyzed
8.8
Dell Unisphere for PowerMax

Dell Unisphere for PowerMax, version(s) 10

2026-07-11
CVE-2026-54466
Analyzed
9.2
Unknown websocket-driver-node

A vulnerability in the websocket-driver-node frame parsing logic allows remote attackers to cause integer overflows and payload misinterpretation by s...

2026-07-18
CVE-2026-54458
Analyzed
9.6
WWBN AVideo

A stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin of AVideo allows unauthenticated attackers to hijack administrative sessions v...

2026-07-16
CVE-2026-54424
Analyzed
8.4
Microsoft Parsec

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege

2026-07-04
CVE-2026-54423
Analyzed
8.2
OpenStack Ironic

In OpenStack Ironic before 37

2026-07-10
CVE-2026-54420
KEV Analyzed
8.5
Linux cPanel plugin

LiteSpeed cPanel plugin before 2

2026-06-14
CVE-2026-54418
Analyzed
8.1
GitHub Leantime

Leantime through 3

2026-08-05
CVE-2026-54414
Analyzed
9.8
HP FileRise

FileRise is vulnerable to path traversal via the shared-folder upload endpoint, allowing an attacker with a valid upload link to overwrite system file...

2026-06-20
CVE-2026-54413
Analyzed
8.2
Unknown iso14229

driftregion iso14229 through 0

2026-06-15
CVE-2026-54412
Analyzed
8.2
LiamBindle MQTT-C

LiamBindle MQTT-C through version 1

2026-06-15
CVE-2026-54410
Analyzed
8.6
Unknown nanoMODBUS

nanoMODBUS through v1

2026-06-15
CVE-2026-54408
Analyzed
8.6
Ubiquiti UniFi Protect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authe...

2026-07-03
CVE-2026-54407
Analyzed
8.6
Ubiquiti UniFi Protect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authe...

2026-07-03
CVE-2026-54406
Analyzed
8.7
Ubiquiti UniFi Network Application

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi...

2026-07-03
CVE-2026-54404
Analyzed
8.8
Ubiquiti UniFi OS Server

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi O...

2026-07-03
CVE-2026-54403
Analyzed
8.6
Ubiquiti UniFi OS Server

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authenti...

2026-07-03
CVE-2026-54402
Analyzed
9.9
Ubiquiti UniFi OS Server

An improper input validation vulnerability in the Ubiquiti UniFi OS Server allows authenticated low-privilege network users to execute arbitrary comma...

2026-07-03
CVE-2026-54400
Analyzed
9.1
Ubiquiti UniFi Access Application

An Improper Access Control vulnerability in the Ubiquiti UniFi Access Application allows an authenticated attacker with high privileges to escalate th...

2026-07-03
CVE-2026-54371
Analyzed
7.1
N/A (Project: attr) attr

attr before version 2

2026-06-30