21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 2901-2950 of 21637 CVEs Page 59 of 433
CVE-2026-5908
8.8
Google Chrome prior

Integer overflow in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-5907
8.1
Google Chrome prior

Insufficient data validation in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-5883
Analyzed
8.8
Google Chrome

Use after free in Media in Google Chrome prior to 147

2026-06-03
CVE-2026-5879
Analyzed
8.8
Google Chrome for Mac

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147

2026-05-27
CVE-2026-58662
Analyzed
8.7
Apache Apache Thrift

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings

2026-07-28
CVE-2026-5866
8.8
Google Chrome prior

Use after free in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-58658
Analyzed
8.2
Intel GPUStack

GPUStack through 2

2026-07-17
CVE-2026-58655
Analyzed
8.8
Grav Grav

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1

2026-07-16
CVE-2026-5865
Analyzed
8.8
Google Chrome

Type Confusion in V8 in Google Chrome prior to 147

2026-05-27
CVE-2026-58644
KEV Analyzed
9.8
Microsoft SharePoint

A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthenticated, remote attacker to execute arbitrary code.

2026-07-15
CVE-2026-58630
Analyzed
10
Microsoft Azure App Service for Linux

An improper access control flaw in Microsoft Azure App Service for Linux allows an unauthenticated, remote attacker to elevate privileges over a netwo...

2026-07-25
CVE-2026-58626
Analyzed
8.8
Microsoft Windows

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-58608
Analyzed
8.8
Microsoft Windows Print Spooler

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized a...

2026-07-15
CVE-2026-5860
Analyzed
8.8
Google Chrome

Use after free in WebRTC in Google Chrome prior to 147

2026-05-27
CVE-2026-58596
Analyzed
8.3
Microsoft Microsoft Edge (Chromium-based)

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network

2026-07-13
CVE-2026-58594
Analyzed
8.8
Microsoft Windows

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-58586
Analyzed
9.8
GitHub Image::WebP

The Perl module Image::WebP bundles a vulnerable version of libwebp, which allows remote attackers to trigger heap corruption and potential code execu...

2026-08-02
CVE-2026-5857
Analyzed
8.1
Contiki-NG Contiki-NG

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt

2026-08-08
CVE-2026-58565
Analyzed
8.8
Dell Dell Command Update (DCU)

Dell Command Update (DCU), versions prior to 5

2026-08-20
CVE-2026-5854
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU is susceptible to remote OS command injection via the setWiFiEasyCfg function, specifically through the merge argument in the CGI...

2026-04-09
CVE-2026-58534
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-5853
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU is vulnerable to remote OS command injection via the setIpv6LanCfg function, exploitable through the addrPrefixLen argument in th...

2026-04-09
CVE-2026-58525
Analyzed
8.2
Microsoft Microsoft Edge (Chromium-based)

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network

2026-07-09
CVE-2026-5852
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU allows remote OS command injection via the setIptvCfg function by manipulating the igmpVer argument in the CGI handler.

2026-04-09
CVE-2026-5851
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU is susceptible to remote OS command injection via the setUPnPCfg function, specifically through the enable parameter in the CGI h...

2026-04-09
CVE-2026-58500
Analyzed
8.2
Apple appium-mcp

MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS

2026-07-14
CVE-2026-5850
Analyzed
9.8
TOTOLINK A7100RU

The Totolink A7100RU contains an OS command injection vulnerability in the setVpnPassCfg function, allowing remote attackers to execute arbitrary syst...

2026-04-09
CVE-2026-58499
Analyzed
8.2
EverMind-AI EverOS

EverOS is a memory runtime for agents

2026-07-11
CVE-2026-58492
Analyzed
9.2
Unknown grav

The grav-plugin-database for Grav CMS is vulnerable to SQL injection via the PDO::tableExists method due to improper input sanitization.

2026-07-11
CVE-2026-58486
Analyzed
8.3
HedgeDoc HedgeDoc

HedgeDoc is an open source, real-time, collaborative, markdown notes application

2026-07-14
CVE-2026-58480
Analyzed
9.8
WordPress Blocksy Companion

The Blocksy Companion WordPress plugin is vulnerable to unauthenticated arbitrary file uploads via the save_attachments function, enabling remote code...

2026-07-09
CVE-2026-58479
Analyzed
9.8
Dan-in-CA Sustainable Irrigation Platform (SIP)

Sustainable Irrigation Platform (SIP) contains a command injection vulnerability in the cli_control plugin that allows unauthenticated attackers to ex...

2026-07-15
CVE-2026-58473
Analyzed
9.1
Intel cognee

Cognee contains an improper access control vulnerability allowing unauthenticated attackers to overwrite global LLM provider settings via the API, ena...

2026-07-08
CVE-2026-58466
Analyzed
9.8
EstrellaXD Auto_Bangumi

Auto_Bangumi contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to gain administrative access.

2026-07-03
CVE-2026-58460
Analyzed
7.7
Unknown react-native-receive-sharing-intent

react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the...

2026-07-03
CVE-2026-58459
Analyzed
7.8
F5 gpsd

gpsd through release-3

2026-07-10
CVE-2026-58457
Analyzed
9.8
Unknown M300 Wi-Fi Repeater

The Shenzhen Aitemi M300 Wi-Fi Repeater is vulnerable to unauthenticated OS command injection via the smacfilter_conf handler, allowing remote attacke...

2026-07-02
CVE-2026-58455
Analyzed
9.8
HP dockwatch

Dockwatch is vulnerable to unauthenticated OS command injection via improper session handling and unsanitized input in the composePath parameter.

2026-07-03
CVE-2026-58453
Analyzed
9.8
JAIOTlink C492A-W6 Wi-Fi IP Camera

JAIOTlink C492A-W6 IP cameras contain hard-coded default credentials that allow network-adjacent attackers to gain unauthorized administrative access.

2026-07-02
CVE-2026-58452
Analyzed
8.8
JAIOTlink C492A-W6 Wi-Fi IP Camera

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4

2026-07-02
CVE-2026-58449
Analyzed
9.8
Unknown txtai

The txtai API /reindex endpoint is vulnerable to remote code execution due to improper input validation in the function parameter, which allows arbitr...

2026-07-01
CVE-2026-58426
Analyzed
9.6
Gitea Gitea Open Source Git Server

An HMAC ambiguity in Gitea Actions Artifacts allows cross-repository data reads and cross-task state writes, compromising the integrity and confidenti...

2026-07-04
CVE-2026-58424
Analyzed
8.9
Gitea Gitea Open Source Git Server

Permanent Fork PR Workflow Approval Gate Bypass

2026-07-04
CVE-2026-58423
Analyzed
7.7
Intel Gitea Open Source Git Server

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

2026-07-04
CVE-2026-58422
Analyzed
9.8
Gitea Open Source Git Server

An improper authorization flaw in the OAuth sign-in callback mechanism allows attackers to silently re-enable previously disabled administrator accoun...

2026-07-07
CVE-2026-58421
Analyzed
7.5
Gitea Open Source Git Server

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

2026-07-07
CVE-2026-58419
Analyzed
7.5
Intel Gitea Open Source Git Server

Notification API leaks private issue metadata after access revocation

2026-07-07
CVE-2026-58409
Analyzed
9.1
HP CRM

ChurchCRM versions prior to 7.4.0 contain an unrestricted file upload vulnerability that allows an authenticated administrator to achieve remote code...

2026-07-14
CVE-2026-58399
Analyzed
8.7
Antonio Castellon module-auth

@acastellon/auth is an authentication control system for microservices

2026-07-02
CVE-2026-58389
Analyzed
8.7
Apache Apache Thrift

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings

2026-07-28