21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3701-3750 of 21637 CVEs Page 75 of 433
CVE-2026-54758
Analyzed
7.8
Notepad++ Notepad++

Notepad++ is a free and open-source source code editor

2026-08-18
CVE-2026-54737
Analyzed
7.3
Unknown defaults-deep

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency

2026-08-02
CVE-2026-54736
Analyzed
8.2
HP cphalcon

Phalcon is a high-performance, full-stack PHP framework

2026-07-11
CVE-2026-54735
Analyzed
10
Unknown prebid-server

A server-side request forgery vulnerability in Prebid Server allows unauthenticated attackers to force the server to make requests to unintended desti...

2026-07-30
CVE-2026-54733
Analyzed
9.3
Microsoft O365-Moodle

The Microsoft 365 Integration plugin for Moodle fails to verify JWT signatures in the Teams SSO endpoint, allowing unauthenticated attackers to forge...

2026-07-17
CVE-2026-54729
Analyzed
8.7
HackingRepo dssrf-js

DSSRF is a Node

2026-08-01
CVE-2026-54727
Analyzed
8.2
Unknown proot-distro

proot-distro is a utility for managing proot containers

2026-07-30
CVE-2026-54725
Analyzed
9.6
Kubernetes Vault-secrets-webhook

A server-side request forgery vulnerability in the bank-vaults vault-secrets-webhook allows attackers to redirect ServiceAccount JWTs to arbitrary, at...

2026-08-01
CVE-2026-54722
Analyzed
8.7
HackingRepo dssrf-js

DSSRF is a Node

2026-07-31
CVE-2026-54693
Analyzed
8.2
Unknown zitadel

ZITADEL is an open source identity management platform

2026-07-30
CVE-2026-54691
Analyzed
8.2
Unknown datamodel-code-generator

datamodel-code-generator generates Python data models from schema definitions

2026-07-29
CVE-2026-54690
Analyzed
8.2
Unknown datamodel-code-generator

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec

2026-07-29
CVE-2026-54680
Analyzed
9.9
Kubernetes logging-operator

The logging-operator for Kubernetes fails to properly escape input in Fluentd configuration rendering, allowing authenticated users to execute arbitra...

2026-07-30
CVE-2026-54673
Analyzed
8.2
Unknown electron-builder

electron-updater allows for automatic updates for Electron apps

2026-07-01
CVE-2026-54672
Analyzed
7.8
Unknown electron-builder

electron-updater allows for automatic updates for Electron apps

2026-07-01
CVE-2026-54666
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification

2026-07-30
CVE-2026-54664
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification

2026-07-30
CVE-2026-54662
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications

2026-07-30
CVE-2026-54661
Analyzed
8.3
Unknown swagger-typescript-api

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification

2026-07-30
CVE-2026-54658
Analyzed
9.8
Hypequery Hypequery

A SQL injection vulnerability in the Hypequery TypeScript semantic layer for ClickHouse allows unauthenticated attackers to execute arbitrary SQL comm...

2026-07-29
CVE-2026-54653
Analyzed
8.8
Unknown datamodel-code-generator

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec

2026-07-29
CVE-2026-54652
Analyzed
8.1
Unknown Frigate

Frigate is an open source network video recorder

2026-07-09
CVE-2026-54650
Analyzed
8.6
Unknown openhole

openhole exposes localhost to the internet in one command

2026-07-29
CVE-2026-5465
8.8
WordPress is vulnerable

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to...

2026-04-07
CVE-2026-5464
7.2
Google Analytics Dashboard

The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin...

2026-04-24
CVE-2026-54639
Analyzed
8.8
Style Dictionary Style Dictionary

Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4

2026-06-24
CVE-2026-5463
Analyzed
8.6
Unknown Multiple Products

Command injection vulnerability in console

2026-04-03
CVE-2026-54609
Analyzed
8.6
Unknown QTINeon

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library

2026-07-29
CVE-2026-54603
Analyzed
8.6
Ruby-OAuth oauth2

OAuth2 is a Ruby wrapper for the OAuth 2

2026-07-29
CVE-2026-54593
Analyzed
8.1
Pterodactyl Panel

Pterodactyl is a free, open-source game server management panel

2026-07-30
CVE-2026-54592
Analyzed
7.5
Unknown Oj (Optimized JSON)

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem

2026-07-01
CVE-2026-54591
Analyzed
8.1
Ronf AsyncSSH

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framew...

2026-07-09
CVE-2026-54588
Analyzed
9.6
Unknown poweradmin

Poweradmin fails to validate the HTTP_HOST header, allowing unauthenticated attackers to poison redirect URIs and hijack user authentication tokens, l...

2026-06-24
CVE-2026-54574
Analyzed
8.2
Termux proot-distro

proot-distro is a utility for managing proot containers

2026-07-30
CVE-2026-54555
Analyzed
7.8
RTK-AI RTK

rtk filters and compresses command outputs before they reach your LLM context

2026-06-24
CVE-2026-54540
Analyzed
8.8
HP Pheditor

Pheditor is a single-file editor and file manager written in PHP

2026-07-28
CVE-2026-54527
Analyzed
9.3
JupyterLab jupyterlab-git

JupyterLab Git is vulnerable to stored Cross-site Scripting (XSS) via crafted filenames, allowing JavaScript execution when a victim views the rename...

2026-07-09
CVE-2026-54526
Analyzed
8.9
Kubernetes Argo Workflows

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes

2026-07-17
CVE-2026-54513
Analyzed
8.1
FasterXML jackson-databind

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor

2026-06-24
CVE-2026-54512
Analyzed
8.1
FasterXML jackson-databind

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor

2026-06-24
CVE-2026-54498
Analyzed
8.7
ViewComponent view_component

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails

2026-07-18
CVE-2026-54496
Analyzed
9.3
ZcashFoundation zebra

A critical flaw in the variable-base scalar multiplication gadget within Zcash-related components allows an attacker to produce valid proofs for Orcha...

2026-07-18
CVE-2026-54469
Analyzed
8.8
Dell Unisphere for PowerMax

Dell Unisphere for PowerMax, version(s) 10

2026-07-11
CVE-2026-54466
Analyzed
9.2
Unknown websocket-driver-node

A vulnerability in the websocket-driver-node frame parsing logic allows remote attackers to cause integer overflows and payload misinterpretation by s...

2026-07-18
CVE-2026-54458
Analyzed
9.6
WWBN AVideo

A stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin of AVideo allows unauthenticated attackers to hijack administrative sessions v...

2026-07-16
CVE-2026-54449
Analyzed
8.8
Unknown LangBot

LangBot is a global IM bot platform designed for LLMs

2026-08-21
CVE-2026-54424
Analyzed
8.4
Microsoft Parsec

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege

2026-07-04
CVE-2026-54423
Analyzed
8.2
OpenStack Ironic

In OpenStack Ironic before 37

2026-07-10
CVE-2026-54420
KEV Analyzed
8.5
Linux cPanel plugin

LiteSpeed cPanel plugin before 2

2026-06-14
CVE-2026-54418
Analyzed
8.1
GitHub Leantime

Leantime through 3

2026-08-05