21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3801-3850 of 21637 CVEs Page 77 of 433
CVE-2026-54218
Analyzed
8.8
AMD TeamDavid

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox

2026-08-08
CVE-2026-54209
Analyzed
8.9
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the f...

2026-08-08
CVE-2026-54208
Analyzed
8.5
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write i...

2026-08-08
CVE-2026-54204
Analyzed
7.7
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC...

2026-08-09
CVE-2026-54202
Analyzed
8.5
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality

2026-08-08
CVE-2026-54200
Analyzed
8.4
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc

2026-08-08
CVE-2026-54185
Analyzed
8.5
Cornerstone Cornerstone Page Builder

Subscriber SQL Injection in Cornerstone < 7

2026-06-18
CVE-2026-5416
Analyzed
8.8
Managed Ethernet Managed Ethernet Switch

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulne...

2026-06-17
CVE-2026-54159
Analyzed
10
HP ps_facetedsearch

A PHP object injection vulnerability in the PrestaShop ps_facetedsearch module allows unauthenticated attackers to achieve remote code execution via a...

2026-07-18
CVE-2026-54158
Analyzed
9.9
SiYuan SiYuan

A critical XSS vulnerability in SiYuan's attribute-view cell renderer allows attackers to inject malicious scripts, leading to remote code execution o...

2026-06-25
CVE-2026-54157
Analyzed
9
LobeHub LobeHub

LobeHub prior to 2.1.57 contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /webapi/proxy endpoint, allowing arbitrary...

2026-06-24
CVE-2026-5415
Analyzed
8.8
Google Advanced Google reCAPTCHA (WP Captcha PRO)

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authen...

2026-06-07
CVE-2026-54149
Analyzed
8.8
Unknown MaxKB

MaxKB is an open-source AI assistant for enterprise

2026-07-11
CVE-2026-54133
Analyzed
9.8
HP jmespath.php

The jmespath.php library fails to sanitize input when using the compiler runtime, allowing for remote code execution via crafted JMESPath expressions.

2026-06-13
CVE-2026-54121
Analyzed
8.8
Microsoft Active Directory Certificate Services (AD CS)

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-54120
Analyzed
9.9
Microsoft Surface Management Services

Improper input validation in Microsoft Surface Management Services allows an authorized attacker to execute code over a network.

2026-07-26
CVE-2026-5412
Analyzed
9.9
Unknown Juju

Juju contains an authorization flaw in the Controller facade that allows authenticated users to extract sensitive cloud credentials.

2026-04-11
CVE-2026-54118
Analyzed
8.8
Microsoft SQL Server

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-54117
Analyzed
8.8
Microsoft SQL Server

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-5411
Analyzed
8.8
Google Advanced Google reCAPTCHA (WP Captcha PRO)

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitr...

2026-06-07
CVE-2026-54107
Analyzed
8.8
Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate...

2026-07-15
CVE-2026-54104
Analyzed
8.8
Microsoft EPDS & CBCA EDS

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Do...

2026-06-19 Patch
CVE-2026-54100
Analyzed
8.3
Microsoft OpenShift Container Platform (Windows Machine Config Operator)

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform

2026-06-23
CVE-2026-54099
Analyzed
8.8
Microsoft OpenShift Container Platform (Windows Machine Config Operator)

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform

2026-06-23
CVE-2026-54096
Analyzed
8.4
File Browser File Browser

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

2026-06-26
CVE-2026-54090
Analyzed
8.7
File Browser File Browser

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

2026-06-26
CVE-2026-54089
Analyzed
9.1
File Browser File Browser

File Browser is vulnerable to an authentication bypass via forged HTTP headers when configured with proxy authentication, allowing unauthenticated att...

2026-06-26
CVE-2026-54088
Analyzed
9.3
Unknown filebrowser

File Browser contains a pre-authentication command injection vulnerability in the Hook Authentication feature, allowing unauthenticated remote code ex...

2026-06-26
CVE-2026-54079
Analyzed
8.7
Unknown veraPDF-validation

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair

2026-07-30
CVE-2026-54078
Analyzed
8.7
Unknown veraPDF-validation

veraPDF validation model is an implementation of the veraPDF validation model

2026-07-30
CVE-2026-54074
Analyzed
7.8
TinaCMS TinaCMS

Tina is a headless content management system

2026-07-03
CVE-2026-54069
Analyzed
9.2
SiYuan SiYuan Note

The SiYuan kernel HTTP server improperly trusts browser extension origins, allowing unauthenticated administrative API access and potential data exfil...

2026-06-25
CVE-2026-54067
Analyzed
9.9
SiYuan SiYuan

A cross-site scripting (XSS) vulnerability in SiYuan's CSS snippet rendering allows attackers to execute arbitrary JavaScript, leading to remote code...

2026-06-25
CVE-2026-54063
Analyzed
7.5
Microsoft Excelize

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

2026-07-12
CVE-2026-54061
Analyzed
9.1
Unknown Dgraph

Dgraph Alpha exposes RPCs for external snapshot imports on the public gRPC port without authentication, allowing unauthenticated remote attackers to o...

2026-07-09
CVE-2026-54060
Analyzed
7.5
Python Pillow Pillow

Pillow is a Python imaging library

2026-07-07
CVE-2026-54059
Analyzed
7.5
Python-Pillow Pillow

Pillow is a Python imaging library

2026-07-07
CVE-2026-54052
Analyzed
9.9
Unknown n8n-mcp

A multi-tenancy authorization bypass in n8n-mcp allows authenticated tenants to access, modify, or delete sensitive workflow backups belonging to othe...

2026-07-16
CVE-2026-54051
Analyzed
9.9
Jovancoding Network-AI

A flaw in the Network-AI agent sandbox allows authenticated users to bypass command allowlists, leading to arbitrary OS command execution.

2026-07-21
CVE-2026-5405
7.8
Unknown Multiple Products

RDP protocol dissector crash in Wireshark 4

2026-05-01
CVE-2026-54030
Analyzed
8
Unknown LibreChat

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers

2026-06-27
CVE-2026-5403
7.8
Unknown Multiple Products

SBC codec crash in Wireshark 4

2026-05-01
CVE-2026-5402
8.8
Unknown Multiple Products

TLS protocol dissector heap overflow in Wireshark 4

2026-04-30
CVE-2026-54018
Analyzed
7.7
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-06-24
CVE-2026-54011
Analyzed
8.7
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-06-24
CVE-2026-54010
Analyzed
8.3
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-06-24
CVE-2026-54008
Analyzed
8.5
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-06-24
CVE-2026-54003
Analyzed
9.1
Unknown kirby

Kirby CMS incorrectly trusts reverse proxy headers for IP verification, allowing unauthenticated attackers to bypass local-IP checks and perform unaut...

2026-07-10
CVE-2026-54002
Analyzed
8.5
GetKirby Kirby

Kirby is an open-source content management system

2026-07-10
CVE-2026-53994
Analyzed
7.5
ProFTPD ProFTPD

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user

2026-07-19