21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3051-3100 of 21637 CVEs Page 62 of 433
CVE-2026-57990
Analyzed
7.4
Microsoft Edge (Chromium-based)

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a...

2026-07-27
CVE-2026-5799
Analyzed
7.5
Unknown Ontime

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc

2026-07-07
CVE-2026-57989
Analyzed
7.4
Microsoft Edge (Chromium-based)

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network

2026-07-27
CVE-2026-57988
Analyzed
7.1
Microsoft Edge (Chromium-based)

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-57986
Analyzed
7.5
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-57985
Analyzed
7.6
Microsoft Edge (Chromium-based)

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-57984
Analyzed
7.5
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-05
CVE-2026-57983
Analyzed
8.7
Microsoft Edge

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network

2026-07-04
CVE-2026-57981
Analyzed
8.8
Microsoft Edge

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-04
CVE-2026-57977
Analyzed
7.1
Microsoft Edge (Chromium-based)

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacke...

2026-07-05
CVE-2026-57975
Analyzed
7.5
Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2026-07-05
CVE-2026-57974
Analyzed
8.8
Microsoft Edge (Chromium-based)

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network

2026-07-04
CVE-2026-57969
Analyzed
8.8
Microsoft Azure CycleCloud

Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-57955
Analyzed
8.5
SigNoz SigNoz

SigNoz through 0

2026-06-30
CVE-2026-57950
Analyzed
8.1
RuoYi ruoyi-vue-pro

ruoyi-vue-pro through 2026

2026-06-30
CVE-2026-57947
Analyzed
8.5
Pinpoint Pinpoint

Pinpoint through 3

2026-06-30
CVE-2026-57920
Analyzed
7.7
Peplink InControl

Peplink InControl 2 through 2

2026-06-28
CVE-2026-57919
Analyzed
7.8
Unknown PBackupVSS

PBackupVSS

2026-06-30
CVE-2026-57915
Analyzed
7.3
Apache Kerby

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type

2026-06-28
CVE-2026-57913
Analyzed
7.5
Johnson & Johnson Audit Tracking Management System (ATMS)

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts

2026-06-28
CVE-2026-57912
Analyzed
7.5
Johnson & Johnson Campus Recruiting

Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by inter...

2026-06-28
CVE-2026-5791
Analyzed
9.6
Infor DivvyDrive

A Cross-Site Request Forgery (CSRF) vulnerability in DivvyDrive versions 4.8.2.9 through 4.8.3.1 allows unauthorized actions to be performed on behalf...

2026-05-08
CVE-2026-57898
Analyzed
9
Eclipse Foundation Eclipse BaSyx - Java Server SDK

An unauthenticated arbitrary file write vulnerability in the Eclipse BaSyx Java Server SDK allows remote attackers to write files to the server filesy...

2026-07-14
CVE-2026-57895
Analyzed
8.5
Fuji Electric Pupsman

Incorrect default permissions issue exists in Pupsman versions prior to 3

2026-07-08
CVE-2026-5789
7.8
Arch path in

Vulnerability related to an unquoted search path in CivetWeb v1

2026-04-23
CVE-2026-57881
Analyzed
9.8
GeoVision GV-LPC2011/2211

A stack-based buffer overflow in GeoVision GV-LPC2011/2211 allows remote, unauthenticated attackers to execute arbitrary code via crafted login data.

2026-06-26
CVE-2026-57880
Analyzed
9.8
GeoVision GV-LPC2011/2211

An unauthenticated stack-based buffer overflow in the ssvr component of GeoVision GV-LPC2011/2211 allows remote attackers to execute arbitrary code vi...

2026-06-26
CVE-2026-57879
Analyzed
9.8
GeoVision GV-LPC2011/2211

An unauthenticated stack-based buffer overflow in the ssvr component of GeoVision GV-LPC2011/2211 allows remote attackers to execute arbitrary code vi...

2026-06-26
CVE-2026-57878
Analyzed
9.8
GeoVision GV-LPC2011/2211

An unauthenticated stack-based buffer overflow in the thttpd component of GeoVision GV-LPC2011/2211 allows remote attackers to execute arbitrary code...

2026-06-26
CVE-2026-57877
Analyzed
8.6
GeoVision GV-LPC2011/GV-LPC2211

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1

2026-06-26
CVE-2026-5787
8.9
Unknown EPMM before

An Improper Certificate Validation in Ivanti EPMM before versions 12

2026-05-08
CVE-2026-57867
Analyzed
8.8
MicroRealEstate MicroRealEstate

MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management

2026-07-07
CVE-2026-57862
Analyzed
8.5
Kanboard Kanboard

Kanboard 1

2026-07-31
CVE-2026-57860
Analyzed
7.8
Tailcall ForgeCode

ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's

2026-07-18
CVE-2026-5786
8.8
Ivanti EPMM before EPMM before

An Improper Access Control vulnerability in Ivanti EPMM before versions 12

2026-05-08
CVE-2026-57858
Analyzed
8.9
GitHub Cal.com Self-Hosted (Cal.diy)

Cal

2026-08-13
CVE-2026-57856
Analyzed
8.8
Cockpit HQ Cockpit CMS

Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api)

2026-07-14
CVE-2026-57855
Analyzed
8.8
Cockpit HQ Cockpit CMS

Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api)

2026-07-14
CVE-2026-57851
Analyzed
7.8
Unknown KernCoreLib64.sys

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64

2026-07-08
CVE-2026-57850
Analyzed
8.3
RustDesk RustDesk

RustDesk before 1

2026-07-11
CVE-2026-5785
8.1
Unknown PAM360 versions

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQ...

2026-04-17
CVE-2026-5784
8.8
DivvyDrive Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc

2026-05-08
CVE-2026-57834
Analyzed
10
Apache Apache Traffic Server

Apache Traffic Server is susceptible to request smuggling attacks when processing malformed chunked HTTP messages.

2026-07-29
CVE-2026-57832
Analyzed
8.7
Joomla EDocman extension for Joomla

The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection

2026-07-15
CVE-2026-57831
Analyzed
8.7
Joomla DP Calendar extension for Joomla

The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection

2026-07-15
CVE-2026-57830
Analyzed
8.8
Joomla Helix Ultimate extension for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion

2026-07-13
CVE-2026-5783
Analyzed
7.6
Beyaz Computer Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trad...

2026-05-21
CVE-2026-57829
Analyzed
8.7
Joomla Helix Ultimate extension for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS

2026-07-13
CVE-2026-57828
Analyzed
9
Joomla Phoca Download

The Phoca Download extension for Joomla contains an authenticated file upload vulnerability that allows registered users to upload executable files an...

2026-07-12
CVE-2026-57827
Analyzed
10
Joomla RSFiles

The RSFiles extension for Joomla is vulnerable to an unauthenticated arbitrary file upload, allowing remote attackers to execute malicious code on the...

2026-07-12