21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3651-3700 of 21637 CVEs Page 74 of 433
CVE-2026-54998
Analyzed
8.8
Microsoft Exchange Online

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network

2026-07-03
CVE-2026-54990
Analyzed
9.8
Microsoft Windows 11 / Windows Server 2025

A heap-based buffer overflow in the Microsoft Windows Remote Desktop Client allows an unauthenticated remote attacker to execute arbitrary code over t...

2026-07-15
CVE-2026-54982
Analyzed
8.8
Microsoft Windows

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacen...

2026-07-15
CVE-2026-5496
7.8
Unknown Multiple Products

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability

2026-04-11
CVE-2026-5495
7.8
Unknown Multiple Products

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

2026-04-11
CVE-2026-5494
7.8
Unknown Multiple Products

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

2026-04-11
CVE-2026-5493
7.8
Unknown Multiple Products

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

2026-04-11
CVE-2026-54919
Analyzed
7.4
Unknown cpp-httplib

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library

2026-07-12
CVE-2026-54917
Analyzed
7.8
SeaweedFS SeaweedFS

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables

2026-06-27
CVE-2026-54904
Analyzed
8.2
Unknown concurrent-ruby

concurrent-ruby is a modern concurrency tools for Ruby

2026-06-25
CVE-2026-5490
Analyzed
8.8
DriveLock DriveLock

DriveLock SQL Injection Privilege Escalation Vulnerability

2026-07-30
CVE-2026-54892
Analyzed
8.7
Elixir Plug

Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service

2026-06-24
CVE-2026-54890
Analyzed
8.2
Erlang OTP OTP

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Ove...

2026-07-28
CVE-2026-5485
Analyzed
7.8
Unknown might allow

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2

2026-04-04
CVE-2026-54849
Analyzed
9.3
WordPress Wishlist for WooCommerce

Premmerce Wishlist for WooCommerce contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries...

2026-06-26
CVE-2026-54848
Analyzed
8.3
APIExperts APIExperts Square for WooCommerce

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Dat...

2026-06-26
CVE-2026-54847
Analyzed
7.5
Stylish Cost Calculator Stylish Cost Calculator

Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8

2026-06-28
CVE-2026-54846
Analyzed
7.5
Unknown Syncee Premium Dropshipping & Wholesale

Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1

2026-06-28
CVE-2026-54845
Analyzed
8.1
PluginUs.Net MDTF (WordPress Plugin)

Unauthenticated Local File Inclusion in MDTF <= 1

2026-06-27
CVE-2026-54843
Analyzed
9.3
WordPress MDTF

The MDTF plugin for WordPress contains an unauthenticated SQL injection vulnerability in versions 1.3.7 and earlier, allowing remote attackers to exec...

2026-06-26
CVE-2026-54842
Analyzed
8.1
WordPress Royal MCP

Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels

2026-06-27
CVE-2026-54840
Analyzed
7.3
Tribulant Newsletters

Unauthenticated Broken Access Control in Newsletters <= 4

2026-06-28
CVE-2026-54839
Analyzed
7.5
Intel Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups

Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2

2026-06-28
CVE-2026-54838
Analyzed
8.5
WordPress WC Vendors Marketplace

Subscriber SQL Injection in WC Vendors Marketplace <= 2

2026-06-26
CVE-2026-54837
Analyzed
7.5
Syed Intranet & Private Site – All-In-One Intranet

Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1

2026-06-28
CVE-2026-54836
Analyzed
9.3
YMC YMC Filter

YMC Filter is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL commands via specially crafted input.

2026-06-26
CVE-2026-54835
Analyzed
7.5
Rustaurius Five Star Restaurant Menu

Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2

2026-06-28
CVE-2026-54834
Analyzed
7.5
Object Object Cache 4 everyone

Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2

2026-06-28
CVE-2026-54833
Analyzed
7.4
Unknown Enable CORS

Unauthenticated Backdoor in Enable CORS <= 2

2026-06-28
CVE-2026-54832
Analyzed
7.5
WordPress Gutenverse Companion

Unauthenticated Broken Access Control in Gutenverse Companion <= 2

2026-06-28
CVE-2026-54831
Analyzed
9.3
WordPress GeoDirectory

GeoDirectory versions 2.8.162 and earlier are susceptible to an unauthenticated SQL injection vulnerability, enabling database manipulation by remote...

2026-06-27
CVE-2026-5483
8.5
Red Hat Openshift AI

A flaw was found in odh-dashboard in Red Hat Openshift AI

2026-04-11
CVE-2026-54827
Analyzed
9.3
WordPress Real Estate 7

Real Estate 7 contains an unauthenticated SQL injection vulnerability in versions 3.5.9 and earlier, allowing remote attackers to manipulate database...

2026-06-27
CVE-2026-54826
Analyzed
7.6
PSM SupportCandy

Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3

2026-06-28
CVE-2026-54825
Analyzed
9.3
WordPress wpDataTables

The wpDataTables plugin for WordPress contains an unauthenticated SQL injection vulnerability that enables remote attackers to manipulate database que...

2026-06-27
CVE-2026-54824
Analyzed
7.5
WordPress Ads by WPQuads

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3

2026-06-28
CVE-2026-54823
Analyzed
9.9
HP Widget Options

A critical vulnerability in the MarketingFire Widget Options plugin allows contributor-level users to execute arbitrary code on the server.

2026-06-26
CVE-2026-54822
Analyzed
8.5
SALESmanago SALESmanago & Leadoo

Subscriber SQL Injection in SALESmanago & Leadoo <= 3

2026-06-26
CVE-2026-54820
Analyzed
9.3
WordPress JetBooking

An unauthenticated SQL injection vulnerability in the JetBooking plugin for WordPress allows remote attackers to execute arbitrary SQL queries and acc...

2026-06-27
CVE-2026-54818
Analyzed
8.5
VeronaLabs Slimstat Analytics

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL I...

2026-06-18
CVE-2026-54813
Analyzed
8.5
Brainstorm Force SureDash

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injec...

2026-06-18
CVE-2026-54805
Analyzed
8.8
Falang Falang Multilanguage

Subscriber Privilege Escalation in Falang multilanguage <= 1

2026-06-18
CVE-2026-54795
Analyzed
8.8
Dell OpenManage Enterprise

Dell OpenManage Enterprise, versions prior to 4

2026-08-20
CVE-2026-54782
Analyzed
10
CoreWCF CoreWCF

CoreWCF fails to properly validate SAML token signatures when using federated bindings, allowing unauthenticated attackers to impersonate arbitrary pr...

2026-07-09
CVE-2026-5478
8.1
WordPress is vulnerable

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3

2026-04-21
CVE-2026-54771
Analyzed
8.1
Unknown langroid

Langroid is a framework for building large-language-model-powered applications

2026-07-10
CVE-2026-54769
Analyzed
10
Langroid Langroid

Langroid versions prior to 0.65.2 contain a sandbox escape vulnerability in its TableChatAgent and VectorStore capabilities, allowing unauthenticated...

2026-07-10
CVE-2026-54763
Analyzed
7.8
Traefik Traefik

Traefik is an HTTP reverse proxy and load balancer

2026-07-07
CVE-2026-54760
Analyzed
9.3
Unknown langroid

Langroid contains an SQL injection vulnerability where bypassable regex blocklists allow attackers to execute restricted PostgreSQL functions despite...

2026-07-10
CVE-2026-54759
Analyzed
8.7
SiYuan SiYuan Note

SiYuan is an open-source personal knowledge management system

2026-06-25