21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3251-3300 of 21637 CVEs Page 66 of 433
CVE-2026-57247
Analyzed
7.8
Foxit Foxit PDF Editor / Foxit PDF Reader

The application re-enters the document structure via field processing and deletes the current page, and then continues using the field objects obtaine...

2026-07-08
CVE-2026-57246
Analyzed
7.8
Foxit Foxit PDF Editor and Reader

When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signatur...

2026-07-08
CVE-2026-57245
Analyzed
7.8
Foxit Foxit PDF Editor / Foxit PDF Reader

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation rel...

2026-07-08
CVE-2026-57244
Analyzed
7.8
Foxit Foxit PDF Editor

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure...

2026-07-08
CVE-2026-57242
Analyzed
7.8
Foxit Foxit PDF Editor

The application opens the PDF, and JavaScript modifies the form

2026-07-08
CVE-2026-57240
Analyzed
7.8
Foxit Foxit PDF Editor

When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in inva...

2026-07-08
CVE-2026-57239
Analyzed
8.2
Foxit Foxit PDF Editor

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to...

2026-07-08
CVE-2026-57238
Analyzed
7.8
Foxit Foxit PDF Editor / PDF Reader

After the application opened the PDF, JavaScript deleted the form field object

2026-07-08
CVE-2026-57237
Analyzed
7.8
Foxit Foxit PDF Editor / PDF Reader

When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by th...

2026-07-08
CVE-2026-57233
Analyzed
8.1
Notepad++ Notepad++

Notepad++ is a free and open-source source code editor

2026-08-18
CVE-2026-57231
Analyzed
7.5
Red Hat Podman

Podman is a tool for managing OCI containers and pods

2026-06-28
CVE-2026-57220
Analyzed
7.5
RabbitMQ RabbitMQ Server

RabbitMQ is a messaging and streaming broker

2026-07-12
CVE-2026-5722
Analyzed
9.8
WordPress is vulnerable

An authentication bypass vulnerability in MoreConvert Pro for WordPress allows unauthenticated attackers to hijack administrator accounts by manipulat...

2026-05-05
CVE-2026-57219
Analyzed
8.7
RabbitMQ RabbitMQ Server

RabbitMQ is a messaging and streaming broker

2026-07-11
CVE-2026-57206
Analyzed
8.6
Microsoft SimpleChat

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions

2026-07-17
CVE-2026-5718
8.1
WordPress is vulnerable

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including...

2026-04-18
CVE-2026-57172
Analyzed
8.3
DataEase DataEase

DataEase is an open source data visualization and analysis tool

2026-07-08
CVE-2026-57156
Analyzed
8.6
FreeRDP FreeRDP

FreeRDP is a free implementation of the Remote Desktop Protocol

2026-07-11
CVE-2026-5712
8
Unknown Multiple Products

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit th...

2026-04-30
CVE-2026-57111
Analyzed
7.5
Apache Apache Helix REST

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through...

2026-07-13
CVE-2026-57106
Analyzed
10
Microsoft Microsoft Purview Data Governance

A server-side request forgery (SSRF) vulnerability in Microsoft Purview Data Governance allows unauthorized attackers to elevate privileges.

2026-07-25
CVE-2026-57104
Analyzed
8.8
Microsoft Azure Storage Explorer

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elev...

2026-08-12
CVE-2026-57102
Analyzed
8.8
Microsoft Visual Studio Code

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a net...

2026-07-15
CVE-2026-57100
Analyzed
9.9
Microsoft Entra Provisioning Service

A Server-Side Request Forgery (SSRF) vulnerability in the Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate p...

2026-07-03
CVE-2026-5710
7.5
WordPress is vulnerable

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versi...

2026-04-18
CVE-2026-57094
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-57092
Analyzed
9.9
Microsoft Windows

A use after free vulnerability in the Windows VMSwitch component allows an authenticated attacker to elevate privileges over a network.

2026-07-15
CVE-2026-57090
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-5709
8.8
Unknown and Engineering

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024

2026-04-07
CVE-2026-57087
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-5708
8.8
Unknown and Engineering

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026

2026-04-07
CVE-2026-57077
Analyzed
7.7
TODDR YAML::Syck

YAML::Syck versions before 1

2026-07-18
CVE-2026-57076
Analyzed
7.8
TODDR YAML::Syck

YAML::Syck versions before 1

2026-07-18
CVE-2026-57075
Analyzed
9.1
TODDR YAML::Syck

An out-of-bounds read vulnerability in the YAML::Syck Perl module allows attackers to access adjacent memory regions through crafted binary YAML nodes...

2026-07-21
CVE-2026-57074
Analyzed
9.1
GitHub XML::Bare

XML::Bare versions through 0.53 for Perl are susceptible to an out-of-bounds read vulnerability when processing malformed or truncated XML strings.

2026-07-21
CVE-2026-57073
Analyzed
9.1
CODECHILD HTML::Bare

HTML::Bare versions through 0.04 for Perl contain an out-of-bounds read vulnerability in the parserc_parse function due to improper handling of charac...

2026-07-21
CVE-2026-5707
8.8
Unknown and Engineering

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025

2026-04-07
CVE-2026-56876
Analyzed
8.1
Unknown extract-zip

extract-zip does not validate symlink targets when extracting zip archives

2026-06-27
CVE-2026-5687
8.8
Tenda CX12L

A weakness has been identified in Tenda CX12L 16

2026-04-07
CVE-2026-5686
8.8
Tenda CX12L

A security flaw has been discovered in Tenda CX12L 16

2026-04-07
CVE-2026-56852
7.5
Unknown golang.org/x/text/unicode/norm

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

2026-08-04
CVE-2026-5685
8.8
Tenda CX12L

A vulnerability was identified in Tenda CX12L 16

2026-04-07
CVE-2026-56846
Analyzed
7.5
Node.js Node

A flaw in Node

2026-08-04
CVE-2026-56845
Analyzed
7.5
Rocket.Chat Rocket.Chat

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem

2026-08-04
CVE-2026-56843
Analyzed
9.9
Webpros Plesk

WebPros Plesk contains an authorization flaw in the XML-RPC API that allows authenticated customers to access cross-tenant data and plaintext FTP cred...

2026-07-08
CVE-2026-56841
Analyzed
8.8
Ubiquiti UniFi Protect Application

A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Appl...

2026-07-03
CVE-2026-5684
8
Tenda CX12L

A vulnerability was determined in Tenda CX12L 16

2026-04-07
CVE-2026-56811
Analyzed
8.7
PhoenixFramework Phoenix

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix

2026-07-08
CVE-2026-56810
Analyzed
8.7
Elixir-Mint Mint

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint

2026-07-07
CVE-2026-56808
Analyzed
8.6
AVTECH DGM3103SCT

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with...

2026-06-30