20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 3201-3250 of 20297 CVEs Page 65 of 406
CVE-2026-52704
Analyzed
10
Edgar Rojas WooCommerce PDF Invoice Builder

A code injection vulnerability in the WooCommerce PDF Invoice Builder plugin allows unauthenticated remote attackers to perform remote code inclusion.

2026-06-16
CVE-2026-52703
Analyzed
9.6
WordPress FastDup

An unauthenticated path traversal vulnerability exists in the FastDup plugin for WordPress, allowing attackers to access sensitive files.

2026-06-16
CVE-2026-52700
Analyzed
8.5
Subscriber WCMultiShipping

Subscriber SQL Injection in WCMultiShipping <= 3

2026-06-16
CVE-2026-5270
Analyzed
9.8
CIENA Navigator NCS, MCP, and Blue Planet

An authentication bypass vulnerability in Ciena Navigator NCS and Blue Planet products allows unauthenticated attackers to manipulate HTTP requests to...

2026-07-18
CVE-2026-52697
Analyzed
8.5
Subscriber Taskbuilder

Subscriber SQL Injection in Taskbuilder <= 5

2026-06-16
CVE-2026-5269
Analyzed
9.8
CIENA Navigator NCS, MCP, and Planner Plus OnPrem

Ciena software products contain hidden system accounts with predictable default passwords, potentially allowing unauthorized access and privilege esca...

2026-07-18
CVE-2026-5268
Analyzed
9.1
CIENA 6500 S-Series

A critical authentication bypass vulnerability in the default SFTP server component of multiple Ciena products allows remote, unauthenticated attacker...

2026-07-07
CVE-2026-52656
Analyzed
9.8
GitHub SJ4000-Air

A critical vulnerability in SJCAM SJ4000-Air cameras allows arbitrary code execution through the processing of maliciously crafted FEX files.

2026-07-27
CVE-2026-5262
8
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16

2026-04-23
CVE-2026-5258
7.3
Sanster Multiple Products

A vulnerability was found in Sanster IOPaint 1

2026-04-01
CVE-2026-5257
7.3
HP of the

A vulnerability has been found in code-projects Simple Laundry System 1

2026-04-01
CVE-2026-5256
7.3
HP of the

A flaw has been found in code-projects Simple Laundry System 1

2026-04-01
CVE-2026-52533
Analyzed
9.8
D-Link DIR-1253

A privilege escalation vulnerability in D-Link DIR-1253 allows unauthenticated attackers to manipulate the etc/shadow component file to gain unauthori...

2026-07-18
CVE-2026-52474
7.5
Unknown Multiple Products

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

2026-08-04
CVE-2026-52472
Analyzed
9.8
GitHub Wgcloud

A SQL injection vulnerability in Wgcloud 3.6.4 allows unauthenticated remote attackers to escalate privileges via the PortInfoMapper.xml file.

2026-07-31
CVE-2026-52470
Analyzed
9.8
Crocus Crocus

An SQL injection vulnerability in the Crocus RecordStateMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and...

2026-07-31
CVE-2026-52469
Analyzed
9.8
Crocus Crocus

An SQL injection vulnerability in the Crocus DeviceInfoMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and...

2026-07-31
CVE-2026-52466
Analyzed
9.8
Open Library Foundation VuFind

Open Library Foundation VuFind v11.0.3 and v4.1 suffer from an incorrect access control vulnerability where requests continue processing despite faile...

2026-08-06
CVE-2026-52439
9.8
Unknown Multiple Products

An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism

2026-08-03
CVE-2026-5242
Analyzed
8.8
MIA Technology MIA Technology Inc (Software)

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc

2026-06-16
CVE-2026-5238
7.3
HP of the

A weakness has been identified in itsourcecode Payroll Management System 1

2026-04-01
CVE-2026-5237
7.3
HP of the

A security flaw has been discovered in itsourcecode Payroll Management System 1

2026-04-01
CVE-2026-52349
Analyzed
7.8
Menyoo MenyooSP

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary c...

2026-07-29
CVE-2026-52348
Analyzed
9.8
Unknown cool-admin-java

A SQL injection vulnerability in the order() method of CrudOption.java within cool-admin-java 8.0.0 allows unauthenticated attackers to compromise the...

2026-07-22
CVE-2026-5231
7.2
WordPress is vulnerable

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and includin...

2026-04-18
CVE-2026-5229
Analyzed
9.8
WordPress is vulnerable

The Form Notify plugin for WordPress suffers from an authentication bypass vulnerability due to improper verification of user-controlled cookie data d...

2026-05-15
CVE-2026-5228
Analyzed
8.8
Kurt Software Studio WriteUp Mobile App

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Co...

2026-06-05
CVE-2026-52203
Analyzed
7.5
MCMS MCMS

An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.

2026-07-22
CVE-2026-52199
9.1
Unknown Multiple Products

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

2026-07-23
CVE-2026-5219
Analyzed
8.3
Unknown E-Commerce Pack

Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd

2026-07-31
CVE-2026-5217
7.2
WordPress is vulnerable

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Sc...

2026-04-12
CVE-2026-5214
8.8
D-Link DNS

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L,...

2026-04-01
CVE-2026-5213
8.8
D-Link DNS

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-...

2026-04-01
CVE-2026-5212
8.8
D-Link DNS

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-...

2026-04-01
CVE-2026-5211
8.8
D-Link DNS

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR...

2026-04-01
CVE-2026-52101
9.1
Linux Multiple Products

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote func...

2026-07-20
CVE-2026-52100
7.5
Linux Multiple Products

Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the...

2026-07-20
CVE-2026-5210
7.3
Unknown Multiple Products

A vulnerability was detected in SourceCodester Leave Application System 1

2026-04-01
CVE-2026-5208
8.2
Unknown Multiple Products

Command injection in alerts in CoolerControl/coolercontrold <4

2026-04-09
CVE-2026-5204
8.8
Tenda CH22

A vulnerability was determined in Tenda CH22 1

2026-04-01
CVE-2026-5201
7.5
Unknown Multiple Products

A flaw was found in the gdk-pixbuf library

2026-04-01
CVE-2026-5200
Analyzed
8.8
WordPress plugin for

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authoriza...

2026-05-20
CVE-2026-5198
7.3
HP of the

A vulnerability was determined in code-projects Student Membership System 1

2026-04-01
CVE-2026-5195
7.3
Membership Multiple Products

A flaw has been found in code-projects Student Membership System 1

2026-04-01
CVE-2026-51937
Analyzed
7.5
SAP Oneblog

An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the...

2026-07-11
CVE-2026-51926
Analyzed
7.5
HP FSM Client

An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability wa...

2026-07-15
CVE-2026-51925
8.1
HP Multiple Products

A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm...

2026-07-15
CVE-2026-51924
8.1
HP Multiple Products

An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component

2026-07-15
CVE-2026-51923
Analyzed
8.1
Unknown Client

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code...

2026-07-15
CVE-2026-5192
7.5
WordPress is vulnerable

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and in...

2026-05-05