22050 Total CVEs
13182 AI Analyzed
308 CISA KEV
4858 Critical
All Vendors
Showing 4051-4100 of 22050 CVEs Page 82 of 441
CVE-2026-54283
Analyzed
7.5
Kludex Starlette

Starlette is a lightweight ASGI framework/toolkit

2026-06-23
CVE-2026-54281
Analyzed
8.7
NestJS Nest Framework

Nest is a framework for building scalable Node

2026-06-23
CVE-2026-54271
Analyzed
8.2
Unknown protobufjs-cli

protobufjs-cli is the command line add-on for protobuf

2026-06-23
CVE-2026-54268
Analyzed
8.2
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-54267
Analyzed
8.6
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-54266
Analyzed
8.8
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-54264
Analyzed
8.3
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-5426
7.5
Unknown Multiple Products

Hard-coded ASP

2026-04-18
CVE-2026-54257
Analyzed
9.3
Electron Electron Framework

Electron versions 42.3.1 through 42.3.3 are vulnerable to heap buffer underflow and overflow due to incorrect byte length calculations in the Node.js...

2026-06-24
CVE-2026-5425
Analyzed
7.2
WordPress is vulnerable

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions...

2026-04-05
CVE-2026-54234
Analyzed
7.5
HP vLLM

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs

2026-07-07
CVE-2026-54232
Analyzed
8.8
Unknown vLLM Inference Engine

vLLM is an inference and serving engine for large language models (LLMs)

2026-06-23
CVE-2026-5423
Analyzed
8.2
Unknown graphql

@neo4j/graphql library versions prior to 7

2026-08-06
CVE-2026-54218
Analyzed
8.8
AMD TeamDavid

Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox

2026-08-08
CVE-2026-54209
Analyzed
8.9
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the f...

2026-08-08
CVE-2026-54208
Analyzed
8.5
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write i...

2026-08-08
CVE-2026-54204
Analyzed
7.7
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC...

2026-08-09
CVE-2026-54202
Analyzed
8.5
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality

2026-08-08
CVE-2026-54200
Analyzed
8.4
AMD TeamDavid

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc

2026-08-08
CVE-2026-54185
Analyzed
8.5
Cornerstone Cornerstone Page Builder

Subscriber SQL Injection in Cornerstone < 7

2026-06-18
CVE-2026-5416
Analyzed
8.8
Managed Ethernet Managed Ethernet Switch

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulne...

2026-06-17
CVE-2026-54159
Analyzed
10
HP ps_facetedsearch

A PHP object injection vulnerability in the PrestaShop ps_facetedsearch module allows unauthenticated attackers to achieve remote code execution via a...

2026-07-18
CVE-2026-54158
Analyzed
9.9
SiYuan SiYuan

A critical XSS vulnerability in SiYuan's attribute-view cell renderer allows attackers to inject malicious scripts, leading to remote code execution o...

2026-06-25
CVE-2026-54157
Analyzed
9
LobeHub LobeHub

LobeHub prior to 2.1.57 contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /webapi/proxy endpoint, allowing arbitrary...

2026-06-24
CVE-2026-5415
Analyzed
8.8
Google Advanced Google reCAPTCHA (WP Captcha PRO)

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authen...

2026-06-07
CVE-2026-54149
Analyzed
8.8
Unknown MaxKB

MaxKB is an open-source AI assistant for enterprise

2026-07-11
CVE-2026-54133
Analyzed
9.8
HP jmespath.php

The jmespath.php library fails to sanitize input when using the compiler runtime, allowing for remote code execution via crafted JMESPath expressions.

2026-06-13
CVE-2026-54121
Analyzed
8.8
Microsoft Active Directory Certificate Services (AD CS)

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-54120
Analyzed
9.9
Microsoft Surface Management Services

Improper input validation in Microsoft Surface Management Services allows an authorized attacker to execute code over a network.

2026-07-26
CVE-2026-5412
Analyzed
9.9
Unknown Juju

Juju contains an authorization flaw in the Controller facade that allows authenticated users to extract sensitive cloud credentials.

2026-04-11
CVE-2026-54118
Analyzed
8.8
Microsoft SQL Server

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-54117
Analyzed
8.8
Microsoft SQL Server

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-5411
Analyzed
8.8
Google Advanced Google reCAPTCHA (WP Captcha PRO)

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitr...

2026-06-07
CVE-2026-54107
Analyzed
8.8
Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate...

2026-07-15
CVE-2026-54104
Analyzed
8.8
Microsoft EPDS & CBCA EDS

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Do...

2026-06-19 Patch
CVE-2026-54100
Analyzed
8.3
Microsoft OpenShift Container Platform (Windows Machine Config Operator)

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform

2026-06-23
CVE-2026-54099
Analyzed
8.8
Microsoft OpenShift Container Platform (Windows Machine Config Operator)

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform

2026-06-23
CVE-2026-54096
Analyzed
8.4
File Browser File Browser

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

2026-06-26
CVE-2026-54090
Analyzed
8.7
File Browser File Browser

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

2026-06-26
CVE-2026-54089
Analyzed
9.1
File Browser File Browser

File Browser is vulnerable to an authentication bypass via forged HTTP headers when configured with proxy authentication, allowing unauthenticated att...

2026-06-26
CVE-2026-54088
Analyzed
9.3
Unknown filebrowser

File Browser contains a pre-authentication command injection vulnerability in the Hook Authentication feature, allowing unauthenticated remote code ex...

2026-06-26
CVE-2026-54079
Analyzed
8.7
Unknown veraPDF-validation

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair

2026-07-30
CVE-2026-54078
Analyzed
8.7
Unknown veraPDF-validation

veraPDF validation model is an implementation of the veraPDF validation model

2026-07-30
CVE-2026-54074
Analyzed
7.8
TinaCMS TinaCMS

Tina is a headless content management system

2026-07-03
CVE-2026-54071
Analyzed
7.8
Unknown BabelDOC

BabelDOC is a document translation tool

2026-08-23
CVE-2026-54069
Analyzed
9.2
SiYuan SiYuan Note

The SiYuan kernel HTTP server improperly trusts browser extension origins, allowing unauthenticated administrative API access and potential data exfil...

2026-06-25
CVE-2026-54067
Analyzed
9.9
SiYuan SiYuan

A cross-site scripting (XSS) vulnerability in SiYuan's CSS snippet rendering allows attackers to execute arbitrary JavaScript, leading to remote code...

2026-06-25
CVE-2026-54063
Analyzed
7.5
Microsoft Excelize

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

2026-07-12
CVE-2026-54061
Analyzed
9.1
Unknown Dgraph

Dgraph Alpha exposes RPCs for external snapshot imports on the public gRPC port without authentication, allowing unauthenticated remote attackers to o...

2026-07-09
CVE-2026-54060
Analyzed
7.5
Python Pillow Pillow

Pillow is a Python imaging library

2026-07-07