21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3501-3550 of 21637 CVEs Page 71 of 433
CVE-2026-55978
Analyzed
8.4
HP CatchPulse

An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter com...

2026-08-06
CVE-2026-55971
Analyzed
9.3
Apache Apache Thrift

A heap-based buffer overflow vulnerability in Apache Thrift C++ bindings allows remote attackers to execute arbitrary code or cause a crash via specia...

2026-07-28
CVE-2026-55969
Analyzed
8.7
Apache Apache Thrift

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings

2026-07-28
CVE-2026-55968
Analyzed
8.7
Apache Apache Thrift

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node

2026-07-28
CVE-2026-55961
Analyzed
8.2
Unknown wolfSSL

wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer

2026-06-26
CVE-2026-55960
Analyzed
8.2
Unknown wolfSSL

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X

2026-06-26
CVE-2026-55958
Analyzed
8.3
Renesas TSIP (Trusted Secure IP)

Out-of-bounds write in the Renesas TSIP TLS 1

2026-06-26
CVE-2026-55953
Analyzed
9.1
Erlang OTP

Erlang/OTP TLS 1.2 and earlier clients fail to verify the server-selected cipher suite against the offered list, allowing on-path attackers to perform...

2026-07-28
CVE-2026-55952
Analyzed
8.2
Erlang OTP (Open Telecom Platform)

The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1

2026-07-03
CVE-2026-55950
Analyzed
8.7
Erlang OTP

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker...

2026-07-03
CVE-2026-55944
Analyzed
9.8
Microsoft Dynamics NAV 2018

An insecure deserialization vulnerability in Microsoft Dynamics NAV 2018 allows an unauthenticated attacker to execute arbitrary code remotely.

2026-07-15
CVE-2026-55884
Analyzed
9.2
Unknown tilt

Tilt versions 0.20.8 through 0.37.3 lack authentication on the HUD HTTP server, allowing unauthenticated remote attackers to invoke internal resources...

2026-07-11
CVE-2026-55883
Analyzed
8.3
Kubernetes Tilt

Tilt defines dev environments as code for microservice apps on Kubernetes

2026-07-11
CVE-2026-55882
Analyzed
8.3
Kubernetes Tilt

Tilt defines dev environments as code for microservice apps on Kubernetes

2026-07-11
CVE-2026-55879
Analyzed
9.3
OpenReplay OpenReplay

A stored Cross-Site Scripting (XSS) vulnerability in the OpenReplay tracking SDK allows unauthenticated attackers to execute malicious scripts in the...

2026-07-11
CVE-2026-55878
Analyzed
7.8
Symfony UX

Symfony UX is a JavaScript ecosystem for Symfony

2026-07-09
CVE-2026-55852
Analyzed
8.6
Frappe Frappe

Frappe is a full-stack web application framework

2026-07-11
CVE-2026-55849
Analyzed
8.5
CycloneDX cyclonedx-node-npm

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects

2026-07-09
CVE-2026-55844
Analyzed
7.5
Home Assistant Core

Home Assistant is open source home automation software that puts local control and privacy first

2026-06-30
CVE-2026-5584
7.3
Fosowl Multiple Products

A vulnerability has been found in Fosowl agenticSeek 0

2026-04-06
CVE-2026-55830
Analyzed
8.3
Unknown RestrictedPython

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment

2026-07-09
CVE-2026-55827
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP is a free implementation of the Remote Desktop Protocol

2026-07-12
CVE-2026-55814
Analyzed
7.5
Apache Apache Ranger

Missing Authentication in Apache Ranger Download APIs on versions <= 2

2026-08-11
CVE-2026-55810
Analyzed
8.1
Drupal Plotly.js Graphing

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. Thi...

2026-07-15
CVE-2026-55809
Analyzed
9.8
HP Flag attendance field

An object injection vulnerability in the Drupal Flag attendance field module allows unauthorized modification of object attributes via improperly hand...

2026-07-12
CVE-2026-55794
Analyzed
8.7
Craft CMS Craft CMS

Craft CMS is a content management system (CMS)

2026-07-02
CVE-2026-55789
Analyzed
8.5
Unknown logto

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

2026-07-11
CVE-2026-55773
Analyzed
8.8
Unknown cedar-java

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions

2026-07-14
CVE-2026-55772
Analyzed
8.8
Unknown cedar-java

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions

2026-07-14
CVE-2026-55771
Analyzed
8.8
Unknown cedar-java

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions

2026-07-14
CVE-2026-5577
7.3
Infor Multiple Products

A vulnerability has been found in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a

2026-04-06
CVE-2026-55768
Analyzed
8.7
Unknown goaccess

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser

2026-07-31
CVE-2026-55762
Analyzed
8.1
Rocket.Chat Rocket.Chat

Rocket

2026-06-25
CVE-2026-5575
7.3
HP of the

A vulnerability was detected in SourceCodester/jkev Record Management System 1

2026-04-06
CVE-2026-55741
Analyzed
8.8
Cotonti Cotonti

Cotonti 1

2026-06-18
CVE-2026-55739
Analyzed
8.2
Unknown Crater

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($mod...

2026-08-05
CVE-2026-55738
Analyzed
8.8
Microtar Microtar

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar

2026-06-18
CVE-2026-55735
Analyzed
8.2
Ueberauth Guardian

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged t...

2026-08-02
CVE-2026-55732
Analyzed
8.7
Loytec LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L...

2026-07-25
CVE-2026-55730
Analyzed
8.7
Loytec LWEB-802

Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5

2026-07-25
CVE-2026-5573
Analyzed
7.3
Technostrobe HI-LED-WR120-G2

A weakness has been identified in Technostrobe HI-LED-WR120-G2 5

2026-04-06
CVE-2026-55729
Analyzed
7.7
Loytec LWEB-802

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5

2026-07-25
CVE-2026-55727
Analyzed
7.5
Genetec Inc. Genetec Security Center

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5

2026-07-07
CVE-2026-55723
Analyzed
8.3
F5 NGINX Ingress Controller

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the c...

2026-07-17
CVE-2026-55721
Analyzed
9.3
Intel Storage Concentrator

StoneFly Storage Concentrator is vulnerable to unauthenticated SQL injection via cookie values in login.pl and debug.pl, allowing for sensitive data e...

2026-07-01
CVE-2026-5570
Analyzed
7.3
Technostrobe HI-LED-WR120-G2

A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5

2026-04-06
CVE-2026-55698
Analyzed
8.8
Unknown pnpm

pnpm is a package manager

2026-06-26
CVE-2026-5569
Analyzed
7.3
Technostrobe HI-LED-WR120-G2

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5

2026-04-06
CVE-2026-55687
Analyzed
7.5
Espressif ESP-IDF

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework

2026-07-12
CVE-2026-55685
Analyzed
8.7
Unknown react-router

React Router is a router for React

2026-07-28