21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 351-400 of 21637 CVEs Page 8 of 433
CVE-2026-8411
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9 before 9

2026-05-27
CVE-2026-8410
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9 before 9

2026-05-27
CVE-2026-8409
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9 before 9

2026-05-27
CVE-2026-8402
Analyzed
9.8
Unknown SYSGUARD 6001

Eksagate SYSGUARD 6001 is vulnerable to a Blind SQL injection attack, allowing unauthenticated attackers to potentially extract database information v...

2026-07-01
CVE-2026-8400
Analyzed
8.1
IBM WebSphere Application Server

IBM WebSphere Application Server 8

2026-08-06
CVE-2026-8398
KEV Analyzed
9.8
AVB Disc Soft DAEMON Tools Lite

A supply chain compromise of DAEMON Tools Lite resulted in the distribution of trojanized binaries signed with a legitimate certificate.

2026-05-15
CVE-2026-8396
Analyzed
7.5
Netcad Software NetGIS

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc

2026-07-19
CVE-2026-8389
Analyzed
8.8
Mozilla Firefox

JIT miscompilation in the JavaScript Engine: JIT component

2026-06-07
CVE-2026-8377
Analyzed
8.2
Unknown Access Control System (GKS)

Missing Authorization vulnerability in Armiya Information Technologies Ltd

2026-07-07
CVE-2026-8365
Analyzed
8.8
HP Blocksy Theme for WordPress

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V...

2026-06-10
CVE-2026-8364
Analyzed
9.8
Gladinet Triofox Cloud Server Agent

The Gladinet Triofox Cloud Server Agent exposes multiple sensitive endpoints on TCP port 7878, potentially facilitating remote exploitation.

2026-05-28
CVE-2026-8363
Analyzed
9.8
Gladinet WOSDeviceDropFolder

A stack-based buffer overflow exists in WOSDeviceDropFolder.dll when processing long URL paths, potentially allowing remote code execution.

2026-05-28
CVE-2026-8362
Analyzed
9.8
Unknown WOSDefaultHttpModule

A stack-based buffer overflow in WOSDefaultHttpModule.dll allows for potential arbitrary code execution when processing long URL paths.

2026-05-28
CVE-2026-8350
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9

2026-05-27
CVE-2026-8339
Analyzed
8.7
Black Duck Coverity Connect

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024

2026-07-30
CVE-2026-8321
Analyzed
7.3
Unknown Multiple Products

A vulnerability was detected in inkeep agents 0

2026-05-12
CVE-2026-8307
Analyzed
9.8
Webbeyaz Web Design Mediküm Web

Mediküm Web is susceptible to a critical SQL injection vulnerability, allowing unauthorized attackers to execute arbitrary SQL commands against the ba...

2026-07-09
CVE-2026-8305
Analyzed
7.3
F5 Multiple Products

A vulnerability was detected in OpenClaw up to 2026

2026-05-12
CVE-2026-8297
Analyzed
9.8
Unknown GisLab Laboratory Management System

GisLab Laboratory Management System is vulnerable to SQL injection due to improper neutralization of special elements in SQL commands, allowing unauth...

2026-07-18
CVE-2026-8260
Analyzed
8.8
D-Link DCS

A vulnerability was found in D-Link DCS-935L up to 1

2026-05-11
CVE-2026-8247
Analyzed
7.7
WatchGuard Fireware OS

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbi...

2026-07-03
CVE-2026-8234
Analyzed
8.8
Unknown Multiple Products

A security vulnerability has been detected in EFM ipTIME A8004T 14

2026-05-10
CVE-2026-8216
Analyzed
7.3
Canias Multiple Products

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8

2026-05-10
CVE-2026-8206
Analyzed
9.8
WordPress Kirki Plugin

The Kirki plugin for WordPress is vulnerable to unauthenticated privilege escalation via an account takeover flaw in the password reset process.

2026-06-02
CVE-2026-8182
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-08-06
CVE-2026-8181
Analyzed
9.8
Google Analytics Alternative

The Burst Statistics WordPress plugin contains an authentication bypass flaw allowing unauthenticated attackers to impersonate administrators via impr...

2026-05-14
CVE-2026-8179
Analyzed
8.8
IBM Aspera High

IBM Aspera High-Speed Transfer Endpoint 3

2026-05-28
CVE-2026-8178
Analyzed
8.1
Unknown Multiple Products

An issue exists in Amazon Redshift JDBC Driver versions prior to 2

2026-05-09
CVE-2026-8177
Analyzed
7.5
Unknown Multiple Products

XML::LibXML versions through 2

2026-05-12
CVE-2026-8175
Analyzed
9.8
IBM Aspera High-Speed Transfer

A buffer overflow in the IBM Aspera High-Speed Transfer component could lead to denial of service, authentication bypass, or remote code execution.

2026-05-28
CVE-2026-8170
Analyzed
8.7
Extreme Switch Engine (EXOS)

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links o...

2026-07-21
CVE-2026-8169
Analyzed
8.7
Extreme Switch Engine (EXOS)

ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function

2026-07-21
CVE-2026-8163
Analyzed
8.8
WordPress Infility Global Plugin

The Infility Global WordPress plugin before 2

2026-06-24
CVE-2026-8157
Analyzed
8.8
WordPress Vitepos

The Vitepos WordPress plugin before 3

2026-06-23
CVE-2026-8153
Analyzed
9.8
Universal Robots PolyScope

Universal Robots PolyScope contains an OS command injection vulnerability in the Dashboard Server interface.

2026-05-09
CVE-2026-8148
7.8
Microsoft Multiple Products

NAVER MYBOX Explorer for Windows before 3

2026-05-09
CVE-2026-8147
Analyzed
8.1
MLflow MLflow

In MLflow versions prior to 3

2026-07-03
CVE-2026-8138
8.8
Tenda CX12L

A vulnerability was found in Tenda CX12L 16

2026-05-08
CVE-2026-8137
8.8
TOTOLINK Multiple Products

A vulnerability has been found in Totolink X5000R 9

2026-05-08
CVE-2026-8111
Analyzed
8.8
Endpoint Endpoint Manager

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exec...

2026-05-13
CVE-2026-8095
Analyzed
8.1
WordPress Frontend File Manager Plugin

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23

2026-06-28
CVE-2026-8093
8.1
Unknown Multiple Products

Memory safety bugs present in Thunderbird 150

2026-05-09
CVE-2026-8092
8.1
Thunderbird Multiple Products

Memory safety bugs present in Thunderbird ESR 140

2026-05-09
CVE-2026-8082
Analyzed
7.5
WordPress bpost-shipping-platform

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce ord...

2026-07-26
CVE-2026-8079
Analyzed
8.7
Progress Flowmon

In Progress Flowmon versions prior to 12

2026-07-03
CVE-2026-8073
Analyzed
7.5
WordPress is vulnerable

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...

2026-05-20
CVE-2026-8071
Analyzed
8.8
WordPress Anti-Spam by CleanTalk plugin

The Anti-Spam by CleanTalk

2026-06-11
CVE-2026-8056
Analyzed
8.8
IBM Langflow OSS

IBM Langflow OSS 1

2026-07-18
CVE-2026-8053
Analyzed
8.8
MongoDB Server

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bo...

2026-05-14
CVE-2026-8043
Analyzed
9.6
Ivanti Xtraction before

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arb...

2026-05-13