23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 3401-3450 of 23295 CVEs Page 69 of 466
CVE-2026-6271
Analyzed
9.8
WordPress is vulnerable

The Career Section WordPress plugin is vulnerable to arbitrary file upload due to missing file type validation, enabling remote code execution.

2026-05-14
CVE-2026-6270
Analyzed
9.1
Fastify @fastify/middie

The @fastify/middie package fails to inherit middleware in child plugin scopes, leading to an authentication bypass for unauthenticated requests.

2026-04-17
CVE-2026-62677
Analyzed
8.8
Unknown omnigent

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

2026-08-22
CVE-2026-62675
Analyzed
8.8
GitHub omnigent

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

2026-08-22
CVE-2026-6267
Analyzed
8.5
GitLab GitLab CE/EE

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10

2026-07-30
CVE-2026-62666
Analyzed
8.8
Unknown grav-plugin-api

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

2026-08-20
CVE-2026-6266
Analyzed
8.3
AAP Multiple Products

A flaw was found in the AAP gateway

2026-05-05
CVE-2026-6264
Analyzed
9.8
Unknown Multiple Products

A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The atta...

2026-04-14
CVE-2026-62631
Analyzed
8.8
Oracle Reports Developer

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication)

2026-08-19
CVE-2026-62623
Analyzed
8.8
Oracle Reports Developer

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication)

2026-08-19
CVE-2026-62619
Analyzed
8.8
Oracle Reports Developer

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication)

2026-08-19
CVE-2026-62612
Analyzed
8.8
Oracle Reports Developer

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication)

2026-08-19
CVE-2026-6261
Analyzed
8.8
WordPress is vulnerable

The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28

2026-05-06
CVE-2026-62608
Analyzed
9.9
Oracle Oracle Reports Developer

A critical vulnerability in Oracle Reports Developer enables low privileged attackers to compromise the system via CORBA.

2026-08-19
CVE-2026-62588
Analyzed
9.9
Oracle Siebel CRM Integration

A critical vulnerability in Oracle Siebel CRM Integration allows low privileged attackers to achieve full system takeover via HTTP requests.

2026-08-19
CVE-2026-6257
Analyzed
9.1
HP directives that

Vvveb CMS v1.0.8 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file ren...

2026-04-21
CVE-2026-62534
Analyzed
8.8
Oracle Oracle Applications Framework

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities)

2026-07-22
CVE-2026-62516
Analyzed
8.8
Oracle Demantra Demand Management

Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security)

2026-07-22
CVE-2026-62512
Analyzed
9.9
Oracle Siebel CRM Cloud Applications

A critical vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows low privileged attackers to compromise t...

2026-08-19
CVE-2026-62500
Analyzed
8.8
Oracle Oracle Hyperion Infrastructure Technology

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events)

2026-08-19
CVE-2026-62498
Analyzed
8.8
Oracle Flow Manufacturing

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations)

2026-07-22
CVE-2026-62496
Analyzed
8.8
Oracle Yard Management

Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations)

2026-07-22
CVE-2026-6249
Analyzed
8.8
HP webshell with

Vvveb CMS 1

2026-04-21
CVE-2026-6248
Analyzed
8.1
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3

2026-04-21
CVE-2026-62478
Analyzed
8.8
Oracle Oracle Public Sector Financials

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

2026-07-22
CVE-2026-62476
Analyzed
8.8
Oracle Oracle Public Sector Payroll

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations)

2026-07-22
CVE-2026-62464
Analyzed
8.8
Oracle Oracle Payroll

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations)

2026-07-22
CVE-2026-62462
Analyzed
8.8
Oracle Oracle Work in Process

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations)

2026-08-19
CVE-2026-62452
Analyzed
9.9
Oracle Siebel CRM Cloud Applications

An unauthenticated vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows remote attackers to access, modi...

2026-08-19
CVE-2026-62450
Analyzed
8.8
Oracle Oracle Flow Manufacturing

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations)

2026-08-19
CVE-2026-62447
Analyzed
8.8
Oracle Oracle Trade Management

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV)

2026-07-22
CVE-2026-62427
Analyzed
8.8
Xen Xen

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2026-08-17
CVE-2026-62426
Analyzed
8.8
Xen Xen

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2026-08-17
CVE-2026-62422
Analyzed
10
JetBrains YouTrack

JetBrains YouTrack is affected by an authentication bypass vulnerability allowing unauthenticated attackers to gain administrative access via direct d...

2026-07-15
CVE-2026-62420
Analyzed
9.9
Canonical LXD

An authorization bypass in Canonical LXD allows authenticated attackers to skip project security checks during cross-project migrations by masqueradin...

2026-08-13
CVE-2026-62414
Analyzed
9.1
Joomla Page Builder CK extension for Joomla

The Page Builder CK extension for Joomla contains an improper access control vulnerability that permits unauthenticated users to view or interact with...

2026-07-28
CVE-2026-62392
Analyzed
8.8
Apache Kylin

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin

2026-07-15
CVE-2026-62391
Analyzed
8.1
Apache Kyuubi

The security fix for CVE-2025-66518 is incomplete

2026-08-01
CVE-2026-62390
Analyzed
9.8
Apache Apache Kylin

Apache Kylin is susceptible to an SQL injection vulnerability via a backend API used for refreshing table catalogs.

2026-07-15
CVE-2026-62388
Analyzed
7.5
NLTK Project NLTK

NLTK versions before 3

2026-08-23
CVE-2026-62384
Analyzed
7.5
NLTK Project NLTK

NLTK versions before 3

2026-08-23
CVE-2026-62357
Analyzed
8.8
HP dragonfly

Dragonfly is an in-memory data store built for modern application workloads

2026-08-19
CVE-2026-62354
Analyzed
7.7
Apache NiFi

Authorization handling for Parameter Context validation requests in Apache NiFi 1

2026-08-04
CVE-2026-6235
Analyzed
9.8
WordPress plugin for

The Sendmachine for WordPress plugin is vulnerable to an authorization bypass, allowing unauthenticated attackers to modify SMTP configurations.

2026-04-23
CVE-2026-62349
Analyzed
8.3
Unknown TDengine

TDengine is an open source, time-series database optimized for Internet of Things devices

2026-07-17
CVE-2026-62328
Analyzed
7.5
Unknown 9Router

9Router through version 0

2026-07-14
CVE-2026-62327
Analyzed
9.1
Unknown 9Router

The decolua 9Router /api/usage/stats endpoint lacks authentication, allowing unauthenticated attackers to retrieve plaintext API keys for connected AI...

2026-07-14
CVE-2026-62316
Analyzed
8.8
Microsoft UFO

Microsoft UFO open-source framework for intelligent automation across devices and platforms

2026-08-22
CVE-2026-62312
Analyzed
8.8
Unknown 9router

9Router is an AI router & token saver

2026-07-16
CVE-2026-62296
Analyzed
7.5
HAPI FHIR org.hl7.fhir.core

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

2026-08-09