21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4001-4050 of 21637 CVEs Page 81 of 433
CVE-2026-52800
Analyzed
8.8
Gogs Gogs

Gogs is an open source self-hosted Git service

2026-06-25
CVE-2026-5280
8.8
Google Chrome prior

Use after free in WebCodecs in Google Chrome prior to 146

2026-04-02
CVE-2026-52798
Analyzed
8.9
Intel Gogs

Gogs is an open source self-hosted Git service

2026-06-25
CVE-2026-52797
Analyzed
8.5
Intel Gogs

Gogs is an open source self-hosted Git service

2026-06-25
CVE-2026-52792
Analyzed
8.7
Unknown algernon

Algernon is a small self-contained pure-Go web server

2026-08-21
CVE-2026-5279
8.8
Google Chrome prior

Object corruption in V8 in Google Chrome prior to 146

2026-04-02
CVE-2026-52785
Analyzed
9.9
Unknown openproject

OpenProject contains a SQL injection vulnerability in the timestamps functionality, allowing authenticated attackers to execute arbitrary SQL queries...

2026-06-27
CVE-2026-52784
Analyzed
8.8
OpenProject OpenProject

OpenProject is open-source, web-based project management software

2026-06-27
CVE-2026-52783
Analyzed
8.2
Intel OpenProject

OpenProject is open-source, web-based project management software

2026-06-27
CVE-2026-52782
Analyzed
9.9
Unknown openproject

OpenProject contains an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated project administrators to hijack project folde...

2026-06-27
CVE-2026-52780
Analyzed
9.6
Intel OpenProject

OpenProject is vulnerable to cache store poisoning, which can be leveraged by attackers to achieve Remote Code Execution on the host system.

2026-06-27
CVE-2026-5278
8.8
Google Chrome on

Use after free in Web MIDI in Google Chrome on Android prior to 146

2026-04-02
CVE-2026-52778
Analyzed
9.8
HP YesWiki

YesWiki is vulnerable to an unsafe execution flaw in the Bazar form field calculator, allowing potential arbitrary PHP code execution and ReDoS attack...

2026-06-09
CVE-2026-5277
7.5
Microsoft Chrome on

Integer overflow in ANGLE in Google Chrome on Windows prior to 146

2026-04-02
CVE-2026-52758
Analyzed
8.8
Intel Ghidra

Ghidra before 12

2026-06-11
CVE-2026-52754
Analyzed
8.8
Unknown Ghidra

Ghidra before 12

2026-06-11
CVE-2026-52751
Analyzed
8.8
Intel Ghidra

Ghidra before 12

2026-06-11
CVE-2026-5275
8.8
Google Chrome on

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146

2026-04-02
CVE-2026-52747
Analyzed
8.6
Apache ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx

2026-07-11
CVE-2026-52746
Analyzed
7.5
Unknown jsonata

JSONata is a JSON query and transformation language

2026-07-19
CVE-2026-5274
8.8
Google Chrome prior

Integer overflow in Codecs in Google Chrome prior to 146

2026-04-02
CVE-2026-52720
Analyzed
8.8
GStreamer librfb (RFB/VNC client)

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client)

2026-06-16
CVE-2026-5272
Analyzed
8.8
Google Chrome prior

Heap buffer overflow in GPU in Google Chrome prior to 146

2026-04-02
CVE-2026-52704
Analyzed
10
Edgar Rojas WooCommerce PDF Invoice Builder

A code injection vulnerability in the WooCommerce PDF Invoice Builder plugin allows unauthenticated remote attackers to perform remote code inclusion.

2026-06-16
CVE-2026-52703
Analyzed
9.6
WordPress FastDup

An unauthenticated path traversal vulnerability exists in the FastDup plugin for WordPress, allowing attackers to access sensitive files.

2026-06-16
CVE-2026-52700
Analyzed
8.5
Subscriber WCMultiShipping

Subscriber SQL Injection in WCMultiShipping <= 3

2026-06-16
CVE-2026-5270
Analyzed
9.8
CIENA Navigator NCS, MCP, and Blue Planet

An authentication bypass vulnerability in Ciena Navigator NCS and Blue Planet products allows unauthenticated attackers to manipulate HTTP requests to...

2026-07-18
CVE-2026-52697
Analyzed
8.5
Subscriber Taskbuilder

Subscriber SQL Injection in Taskbuilder <= 5

2026-06-16
CVE-2026-5269
Analyzed
9.8
CIENA Navigator NCS, MCP, and Planner Plus OnPrem

Ciena software products contain hidden system accounts with predictable default passwords, potentially allowing unauthorized access and privilege esca...

2026-07-18
CVE-2026-5268
Analyzed
9.1
CIENA 6500 S-Series

A critical authentication bypass vulnerability in the default SFTP server component of multiple Ciena products allows remote, unauthenticated attacker...

2026-07-07
CVE-2026-52656
Analyzed
9.8
GitHub SJ4000-Air

A critical vulnerability in SJCAM SJ4000-Air cameras allows arbitrary code execution through the processing of maliciously crafted FEX files.

2026-07-27
CVE-2026-5262
8
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16

2026-04-23
CVE-2026-5258
7.3
Sanster Multiple Products

A vulnerability was found in Sanster IOPaint 1

2026-04-01
CVE-2026-5257
7.3
HP of the

A vulnerability has been found in code-projects Simple Laundry System 1

2026-04-01
CVE-2026-5256
7.3
HP of the

A flaw has been found in code-projects Simple Laundry System 1

2026-04-01
CVE-2026-52533
Analyzed
9.8
D-Link DIR-1253

A privilege escalation vulnerability in D-Link DIR-1253 allows unauthenticated attackers to manipulate the etc/shadow component file to gain unauthori...

2026-07-18
CVE-2026-52476
7.5
Unknown Multiple Products

SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DatacenterQ...

2026-08-12
CVE-2026-52474
7.5
Unknown Multiple Products

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

2026-08-04
CVE-2026-52472
Analyzed
9.8
GitHub Wgcloud

A SQL injection vulnerability in Wgcloud 3.6.4 allows unauthenticated remote attackers to escalate privileges via the PortInfoMapper.xml file.

2026-07-31
CVE-2026-52470
Analyzed
9.8
Crocus Crocus

An SQL injection vulnerability in the Crocus RecordStateMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and...

2026-07-31
CVE-2026-52469
Analyzed
9.8
Crocus Crocus

An SQL injection vulnerability in the Crocus DeviceInfoMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and...

2026-07-31
CVE-2026-52466
Analyzed
9.8
Open Library Foundation VuFind

Open Library Foundation VuFind v11.0.3 and v4.1 suffer from an incorrect access control vulnerability where requests continue processing despite faile...

2026-08-06
CVE-2026-52439
9.8
Unknown Multiple Products

An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism

2026-08-03
CVE-2026-5242
Analyzed
8.8
MIA Technology MIA Technology Inc (Software)

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc

2026-06-16
CVE-2026-5238
7.3
HP of the

A weakness has been identified in itsourcecode Payroll Management System 1

2026-04-01
CVE-2026-5237
7.3
HP of the

A security flaw has been discovered in itsourcecode Payroll Management System 1

2026-04-01
CVE-2026-52349
Analyzed
7.8
Menyoo MenyooSP

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary c...

2026-07-29
CVE-2026-52348
Analyzed
9.8
Unknown cool-admin-java

A SQL injection vulnerability in the order() method of CrudOption.java within cool-admin-java 8.0.0 allows unauthenticated attackers to compromise the...

2026-07-22
CVE-2026-5231
7.2
WordPress is vulnerable

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and includin...

2026-04-18
CVE-2026-5229
Analyzed
9.8
WordPress is vulnerable

The Form Notify plugin for WordPress suffers from an authentication bypass vulnerability due to improper verification of user-controlled cookie data d...

2026-05-15