23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 4001-4050 of 23295 CVEs Page 81 of 466
CVE-2026-59243
Analyzed
9.8
Microsoft Apache Airflow FAB provider

The Apache Airflow FAB provider fails to verify Azure AD OAuth ID token signatures, allowing unauthenticated attackers to bypass authentication and ga...

2026-07-30
CVE-2026-59239
Analyzed
8.6
Roskus Prospero Flow CRM

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5

2026-07-28
CVE-2026-59235
Analyzed
8.7
Roskus Prospero Flow CRM

Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController

2026-07-16
CVE-2026-59233
Analyzed
8.7
Roskus Prospero Flow CRM

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5

2026-08-11
CVE-2026-59224
Analyzed
8
Unknown open-webui

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

2026-07-10
CVE-2026-59221
Analyzed
7.7
Unknown open-webui

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

2026-07-11
CVE-2026-59216
Analyzed
7.7
Open WebUI Open WebUI

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

2026-07-11
CVE-2026-59208
Analyzed
7.6
Unknown n8n

n8n is an open source workflow automation platform

2026-07-11
CVE-2026-59204
Analyzed
8.7
Python Pillow Pillow

Pillow is a Python imaging library

2026-07-15
CVE-2026-59195
Analyzed
8.2
Unknown pnpm

pnpm is a package manager

2026-07-07
CVE-2026-59190
Analyzed
8.7
GetGrav Grav Admin Plugin

grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages

2026-07-11
CVE-2026-59173
Analyzed
7.5
Apache Apache Traffic Server

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 1...

2026-07-23
CVE-2026-59161
Analyzed
8.7
Microsoft excelize

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

2026-07-11
CVE-2026-59151
Analyzed
9.6
Unknown prowler

Prowler is vulnerable to cross-tenant account takeover due to improper validation of SAML assertions within its authentication flow.

2026-07-11
CVE-2026-5915
Analyzed
8.1
Google Chrome prior

Insufficient validation of untrusted input in WebML in Google Chrome prior to 147

2026-04-10
CVE-2026-59148
Analyzed
8.8
Mockoon Mockoon

Mockoon provides way to design and run mock APIs

2026-07-10
CVE-2026-59147
Analyzed
9.8
EGOR Data::DisjointSet::Shared

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-...

2026-07-31
CVE-2026-59146
Analyzed
7.8
EGOR Data::SpatialHash::Shared

Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph...

2026-08-04
CVE-2026-59145
Analyzed
9.1
EGOR Data::Intern::Shared

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The at...

2026-08-03
CVE-2026-59144
Analyzed
9.8
EGOR Data::RingBuffer::Shared

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time v...

2026-07-31
CVE-2026-59142
Analyzed
9.1
EGOR Data::HashMap::Shared

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attac...

2026-08-07
CVE-2026-59140
Analyzed
9.1
EGOR Data::SortedSet::Shared

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. T...

2026-08-07
CVE-2026-5914
Analyzed
8.8
Google Chrome prior

Type Confusion in CSS in Google Chrome prior to 147

2026-04-10
CVE-2026-59139
Analyzed
9.1
EGOR Data::ReqRep::Shared

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The...

2026-08-07
CVE-2026-59133
Analyzed
8.8
Microsoft Windows App Client for Windows Desktop

Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a ne...

2026-08-12
CVE-2026-59124
Analyzed
9.8
Microsoft Windows App Client for Windows Desktop

A deserialization vulnerability in the Microsoft High Performance Computing Pack allows unauthenticated remote attackers to execute arbitrary code on...

2026-08-12
CVE-2026-5912
Analyzed
8.8
Google Chrome prior

Integer overflow in WebRTC in Google Chrome prior to 147

2026-04-10
CVE-2026-59115
Analyzed
9.9
Microsoft Microsoft Entra Provisioning Service

A path traversal flaw in the SyncFabric component of Microsoft Entra Provisioning Service allows an authorized attacker to elevate privileges over a n...

2026-08-27
CVE-2026-59113
Analyzed
8.8
Microsoft Visual Studio Code

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network

2026-08-12
CVE-2026-59111
Analyzed
9.3
Apple eObčanka-Identifikace

An OS command injection vulnerability in eObčanka-Identifikace on macOS allows attackers to execute arbitrary commands via unsanitized URL parameters...

2026-09-01
CVE-2026-59109
Analyzed
8.8
Zalktis Zalktis

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices

2026-08-14
CVE-2026-5910
Analyzed
8.8
Google Chrome prior

Integer overflow in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-59099
Analyzed
9.1
Apereo CAS

A cryptographic flaw in Apereo CAS allows unauthenticated attackers to decrypt webflow conversation states by exploiting AES-GCM initialization vector...

2026-07-03
CVE-2026-59095
Analyzed
7.7
LobeHub LobeChat

LobeChat before 2

2026-07-03
CVE-2026-59093
Analyzed
8.8
Weaviate Weaviate

Weaviate before 1

2026-07-03
CVE-2026-59092
Analyzed
7.7
JuiceFS JuiceFS

JuiceFS through 1

2026-07-03
CVE-2026-59091
Analyzed
7.3
Red Hat Red Hat Enterprise Linux (GIMP plugins)

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files

2026-08-11
CVE-2026-59090
Analyzed
8.4
Red Hat Red Hat Enterprise Linux (GIMP PSD plugin)

A flaw was found in GIMP's PSD file format plugin

2026-08-11
CVE-2026-5909
Analyzed
8.8
Google Chrome prior

Integer overflow in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-59087
Analyzed
7.8
Red Hat Image Manipulation Program

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader

2026-08-11
CVE-2026-59083
Analyzed
9.1
Apache Apache Tomcat

A URL encoding vulnerability in Apache Tomcat's RewriteValve allows unauthenticated attackers to bypass security constraints by manipulating hex-encod...

2026-07-16
CVE-2026-5908
Analyzed
8.8
Google Chrome prior

Integer overflow in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-5907
Analyzed
8.1
Google Chrome prior

Insufficient data validation in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-5883
Analyzed
8.8
Google Chrome

Use after free in Media in Google Chrome prior to 147

2026-06-03
CVE-2026-5879
Analyzed
8.8
Google Chrome for Mac

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147

2026-05-27
CVE-2026-58662
Analyzed
8.7
Apache Apache Thrift

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings

2026-07-28
CVE-2026-5866
Analyzed
8.8
Google Chrome prior

Use after free in Media in Google Chrome prior to 147

2026-04-10
CVE-2026-58658
Analyzed
8.2
Intel GPUStack

GPUStack through 2

2026-07-17
CVE-2026-58655
Analyzed
8.8
Grav Grav

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1

2026-07-16
CVE-2026-5865
Analyzed
8.8
Google Chrome

Type Confusion in V8 in Google Chrome prior to 147

2026-05-27