23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 3551-3600 of 23391 CVEs Page 72 of 468
CVE-2026-6197
Analyzed
8.8
Tenda F456

A flaw has been found in Tenda F456 1

2026-04-14
CVE-2026-61967
Analyzed
9.8
WordPress miniorange otp verification

An unauthenticated privilege escalation vulnerability in the miniOrange OTP Verification plugin for WordPress versions 5.5.1 and below allows attacker...

2026-08-14
CVE-2026-61962
Analyzed
10
WordPress WP BASE Booking

The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute mali...

2026-08-14
CVE-2026-6196
Analyzed
8.8
Tenda F456

A vulnerability was detected in Tenda F456 1

2026-04-14
CVE-2026-61955
Analyzed
7.6
WordPress گرویتی فرم فارسی (Persian Gravity Forms)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms al...

2026-07-14
CVE-2026-61953
Analyzed
7.2
WordPress Simple Link Directory Pro

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15

2026-07-28
CVE-2026-61951
Analyzed
9.8
WordPress TrueBooker

TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.

2026-07-24
CVE-2026-61950
Analyzed
9.3
WordPress TrueBooker

The TrueBooker plugin for WordPress is vulnerable to an unauthenticated SQL injection, allowing remote attackers to extract sensitive data via crafted...

2026-07-24
CVE-2026-6195
Analyzed
9.8
TOTOLINK Multiple Products

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file...

2026-04-14
CVE-2026-61949
Analyzed
9.3
WordPress Bookly

The Bookly WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 27.7 and prior, enabling attackers to execute arbitrar...

2026-07-24
CVE-2026-61948
Analyzed
9.3
WordPress WPDM – Premium Packages

The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote data...

2026-07-24
CVE-2026-6194
Analyzed
8.8
TOTOLINK Multiple Products

A weakness has been identified in Totolink A3002MU B20211125

2026-04-14
CVE-2026-6193
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1

2026-04-14
CVE-2026-61900
Analyzed
10
Joomla jDownloads extension for Joomla

The jDownloads extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote code ex...

2026-07-21
CVE-2026-61899
Analyzed
7.5
Apache Apache Tapestry

Vulnerability in tapestry-core in Apache Tapestry 5

2026-08-11
CVE-2026-61892
Analyzed
8.8
Weintek cMT3092X firmware

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges

2026-07-25
CVE-2026-6189
Analyzed
7.3
HP Multiple Products

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-14
CVE-2026-61884
Analyzed
9.8
Tycon Systems TPDIN-Monitor-WEB2

The web interface of Tycon Systems TPDIN-Monitor-WEB2 fails to validate credentials, allowing unauthenticated remote attackers to bypass login and obt...

2026-07-25
CVE-2026-6188
Analyzed
7.3
HP Multiple Products

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-14
CVE-2026-61876
Analyzed
8.8
GitHub LuCI

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML mar...

2026-07-14
CVE-2026-61875
Analyzed
8.8
OpenWrt LuCI

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMa...

2026-07-17
CVE-2026-6187
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1

2026-04-14
CVE-2026-6186
Analyzed
8.8
UTT Multiple Products

A security vulnerability has been detected in UTT HiPER 1200GW up to 2

2026-04-14
CVE-2026-61836
Analyzed
8.6
Directus Directus

Directus is a real-time API and App dashboard for managing SQL database content

2026-07-17
CVE-2026-6183
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in code-projects Simple Content Management System 1

2026-04-14
CVE-2026-61828
Analyzed
8.5
NixOS nixpkgs

Nixpkgs is a collection of software packages that can be installed with the Nix package manager

2026-07-17
CVE-2026-61824
Analyzed
8.2
Unknown defuddle

Defuddle cleans up HTML pages

2026-08-22
CVE-2026-6182
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in code-projects Simple Content Management System 1

2026-04-14
CVE-2026-61808
Analyzed
9.8
HKUDS LightRAG

LightRAG versions through 1.5.4 expose an unauthenticated API server, allowing remote attackers to manipulate knowledge graphs, access documents, and...

2026-08-08
CVE-2026-61699
Analyzed
8.1
Slack nebula-mesh

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a...

2026-09-05
CVE-2026-61684
Analyzed
8.8
Labring FastGPT

FastGPT is a knowledge-based AI application platform

2026-07-16
CVE-2026-6168
Analyzed
8.8
TOTOLINK Multiple Products

A flaw has been found in TOTOLINK A7000R up to 9

2026-04-13
CVE-2026-6167
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in code-projects Faculty Management System 1

2026-04-13
CVE-2026-61666
Analyzed
8.9
Unknown websocket-driver-ruby

websocket-driver is a WebSocket protocol handler with pluggable I/O

2026-08-18
CVE-2026-6166
Analyzed
7.3
HP Multiple Products

A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-6165
Analyzed
7.3
HP Multiple Products

A weakness has been identified in code-projects Vehicle Showroom Management System 1

2026-04-13
CVE-2026-61641
Analyzed
8.1
Unknown Wallos

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incomi...

2026-09-01
CVE-2026-61640
Analyzed
8.5
HP Wallos

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in in...

2026-09-01
CVE-2026-6164
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in code-projects Lost and Found Thing Management 1

2026-04-13
CVE-2026-61639
Analyzed
8.5
HP Wallos

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extrac...

2026-09-01
CVE-2026-61638
Analyzed
8.2
HP Wallos

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.ph...

2026-09-01
CVE-2026-6163
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in code-projects Lost and Found Thing Management 1

2026-04-13
CVE-2026-6161
Analyzed
7.3
HP of the

A vulnerability was determined in code-projects Simple ChatBox up to 1

2026-04-13
CVE-2026-6158
Analyzed
7.3
TOTOLINK Multiple Products

A flaw has been found in Totolink N300RH 6

2026-04-13
CVE-2026-61574
Analyzed
8.8
Unknown authentik

authentik is an open-source identity provider

2026-08-19
CVE-2026-6157
Analyzed
8.8
TOTOLINK Multiple Products

A vulnerability was detected in Totolink A800R 4

2026-04-13
CVE-2026-6156
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU allows remote OS command injection via the setIpQosRules function in the CGI handler.

2026-04-13
CVE-2026-61556
Analyzed
8.7
GitHub LiquidJS

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-08-21
CVE-2026-6155
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU is vulnerable to remote OS command injection via the setWanCfg function in the CGI handler.

2026-04-13
CVE-2026-6154
Analyzed
9.8
TOTOLINK A7100RU

Totolink A7100RU allows remote OS command injection via the setWizardCfg function within the CGI handler.

2026-04-13