21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3151-3200 of 21637 CVEs Page 64 of 433
CVE-2026-57707
Analyzed
9.3
WordPress Simple Business Directory Pro

The Simple Business Directory Pro plugin for WordPress is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary databas...

2026-07-14
CVE-2026-57705
Analyzed
7.5
Nexcess Event Tickets

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels

2026-07-14
CVE-2026-57702
Analyzed
9.3
WordPress Amelia

The Amelia WordPress plugin contains a Blind SQL Injection vulnerability, allowing unauthenticated attackers to execute arbitrary SQL commands.

2026-07-14
CVE-2026-57700
Analyzed
10
Daan.dev OMGF Pro

OMGF Pro contains an unrestricted file upload vulnerability that allows an attacker to upload malicious files, potentially leading to remote code exec...

2026-06-26
CVE-2026-57697
Analyzed
7.5
WordPress ProfileGrid

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allo...

2026-07-14
CVE-2026-57692
Analyzed
9.8
WordPress PrivateContent

LCweb PrivateContent is vulnerable to an incorrect privilege assignment flaw, potentially allowing an attacker to escalate privileges within the appli...

2026-07-02
CVE-2026-57688
Analyzed
8.2
Gurmehub POS Entegratör

Unauthenticated Broken Access Control in POS Entegratör <= 3

2026-07-03
CVE-2026-57687
Analyzed
8.5
Hiroaki Custom Field Template

Contributor SQL Injection in Custom Field Template <= 2

2026-07-03
CVE-2026-57683
Analyzed
9.3
WordPress WP Fast Total Search

An unauthenticated SQL injection vulnerability exists in Epsiloncool WP Fast Total Search versions 1.80.280 and earlier, allowing remote attackers to...

2026-07-03
CVE-2026-5768
Analyzed
8.8
Unknown Multiple Products

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or autho...

2026-05-30
CVE-2026-57679
Analyzed
9.3
Ahmadgb GeekyBot

GeekyBot is susceptible to an unauthenticated SQL injection vulnerability, allowing remote attackers to manipulate database queries.

2026-07-03
CVE-2026-57677
Analyzed
9.8
HP Payment Gateway for WooCommerce

An unauthenticated PHP object injection vulnerability exists in the Novalnet Payment Gateway for WooCommerce plugin, allowing potential remote code ex...

2026-07-03
CVE-2026-57667
Analyzed
8.5
WordPress Groundhogg

Sales Representative SQL Injection in Groundhogg <= 4

2026-06-27
CVE-2026-57663
Analyzed
8.5
WordPress Recipe Maker For Your Food Blog

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8

2026-06-27
CVE-2026-57662
Analyzed
8.5
Wasiliy Contest Gallery

Contributor SQL Injection in Contest Gallery <= 30

2026-06-27
CVE-2026-57659
Analyzed
8.8
Stranger Paid Memberships Pro - Add Member From Admin

Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0

2026-06-27
CVE-2026-57655
Analyzed
8.2
WordPress Child Theme Wizard

Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1

2026-06-27
CVE-2026-57653
Analyzed
8.5
WordPress WP Job Portal

Contributor SQL Injection in WP Job Portal <= 2

2026-06-27
CVE-2026-57647
Analyzed
7.5
Palo Alto Panorama Viewer – 360 Degree Image + Video Viewer

Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1

2026-06-28
CVE-2026-57645
Analyzed
8.1
Tribulant Newsletters

newsletters_subscribers Broken Access Control in Newsletters <= 4

2026-06-27
CVE-2026-57644
Analyzed
8.5
WordPress Restaurant Menu

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2

2026-06-27
CVE-2026-57643
Analyzed
8.5
Themes WP Post Author

Contributor SQL Injection in WP Post Author <= 3

2026-06-27
CVE-2026-57642
Analyzed
8.5
BestWebSoft Gallery

Contributor SQL Injection in Gallery <= 4

2026-06-27
CVE-2026-57636
Analyzed
8.5
WordPress wpForo Forum

Contributor SQL Injection in wpForo Forum <= 3

2026-06-27
CVE-2026-57631
Analyzed
7.6
Ays Popup box

Administrator SQL Injection in Popup box <= 6

2026-06-28
CVE-2026-57628
Analyzed
7.6
WordPress WP All Import

Administrator SQL Injection in WP All Import <= 4

2026-06-28
CVE-2026-57625
Analyzed
9.6
ASE Admin and Site Enhancements (ASE) Pro

An unauthenticated Cross-Site Scripting (XSS) vulnerability in ASE Pro allows attackers to inject malicious scripts into the web interface.

2026-07-03
CVE-2026-57624
Analyzed
10
Creative Themes Blocksy Companion Pro

An unauthenticated remote code execution vulnerability in Blocksy Companion Pro allows attackers to execute arbitrary commands on the server.

2026-07-03
CVE-2026-57623
Analyzed
9
BoldGrid W3 Total Cache

An unauthenticated arbitrary code execution vulnerability exists in BoldGrid W3 Total Cache versions 2.9.4 and earlier, allowing remote attackers to e...

2026-07-03
CVE-2026-57621
Analyzed
9.8
HP Booktics

An unauthenticated PHP object injection vulnerability in the Booktics plugin allows remote attackers to execute arbitrary code on affected systems.

2026-07-03
CVE-2026-5760
Analyzed
9.8
Unknown Multiple Products

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loade...

2026-04-21
CVE-2026-57584
Analyzed
8.7
HP cphalcon

Phalcon is a high-performance, full-stack PHP framework

2026-07-11
CVE-2026-57574
Analyzed
7.4
Unknown misskey

Misskey is an open source, federated social media platform

2026-07-12
CVE-2026-57573
Analyzed
8.6
Unknown crawl4ai

Crawl4AI is an open-source LLM-friendly web crawler and scraper

2026-07-07
CVE-2026-57572
Analyzed
10
Docker Crawl4ai

Crawl4ai is vulnerable to command injection via the Docker API, allowing unauthenticated attackers to execute arbitrary commands on the host by inject...

2026-07-07
CVE-2026-57571
Analyzed
9.6
Unknown crawl4ai

A path traversal vulnerability in crawl4ai allows attackers to perform arbitrary file writes by injecting malicious filenames during the crawling proc...

2026-07-07
CVE-2026-5757
Analyzed
7.5
Intel Ollama

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server...

2026-06-28
CVE-2026-57532
Analyzed
8.8
Unknown pretix

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the brows...

2026-06-26
CVE-2026-57527
Analyzed
8.8
OWASP ZAP ViewState add-on

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxie...

2026-06-27
CVE-2026-5752
Analyzed
9.3
Unknown Multiple Products

Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traver...

2026-04-15
CVE-2026-57518
Analyzed
8.8
Pagekit Pagekit CMS

Pagekit CMS 1

2026-06-27
CVE-2026-57517
Analyzed
9.8
HP Control Web Panel

Control Web Panel is vulnerable to unauthenticated blind SQL injection, allowing remote attackers to achieve remote code execution via arbitrary file...

2026-07-02
CVE-2026-57516
Analyzed
8.8
Anyscale Ray

Ray prior to 2

2026-07-02
CVE-2026-57510
Analyzed
8.8
SuperPlane superplane

SuperPlane before 0

2026-07-29
CVE-2026-57498
Analyzed
9.6
Unknown coolify

Coolify versions prior to 4.0.0-beta.474 contain an authorization flaw where Livewire web UI components fail to validate resource ownership, enabling...

2026-06-30
CVE-2026-57495
Analyzed
8.2
Unknown @agenticmail/core, @agenticmail/claudecode, @agenticmail/codex, @agenticmail/openclaw

AgenticMail gives AI agents real email addresses and phone numbers

2026-07-21
CVE-2026-57485
Analyzed
8.5
Stirling-Tools Stirling-PDF

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files

2026-08-18
CVE-2026-57480
Analyzed
8.7
Parse Community parse-server

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node

2026-07-09
CVE-2026-57456
Analyzed
8.4
Vim Vim

Vim is an open source, command line text editor

2026-06-26
CVE-2026-57433
Analyzed
9.8
HAARG Storable

The Storable module for Perl contains a signed integer overflow when deserializing SX_HOOK records, potentially leading to denial of service or arbitr...

2026-07-18