21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4101-4150 of 21637 CVEs Page 83 of 433
CVE-2026-5150
7.3
HP of the

A security vulnerability has been detected in code-projects Accounting System 1

2026-03-31
CVE-2026-5147
7.3
Unknown Multiple Products

A security flaw has been discovered in YunaiV yudao-cloud up to 2026

2026-03-31
CVE-2026-5144
8.8
WordPress is vulnerable

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-04-11
CVE-2026-5141
Analyzed
8.8
TUBITAK BILGEM Institute Pardus

Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research...

2026-04-30
CVE-2026-5140
Analyzed
8.8
TUBITAK BILGEM Institute Pardus

Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus allows Au...

2026-04-30
CVE-2026-51380
9.8
Tenda Multiple Products

Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially ex...

2026-07-21
CVE-2026-5136
Analyzed
8.8
Red Hat Red Hat Satellite

A flaw was found in Foreman

2026-07-02
CVE-2026-51346
Analyzed
9.1
StudIP StudIP

A SQL injection vulnerability in the store() functions of StudIP allows remote unauthenticated attackers to execute arbitrary code and retrieve sensit...

2026-08-18
CVE-2026-5134
Analyzed
9.8
Unknown CMS

An SQL injection vulnerability exists in Loca Software Informatics Technology Ltd. CMS, allowing unauthenticated attackers to execute arbitrary SQL co...

2026-08-06
CVE-2026-51304
Analyzed
7.5
SQLite SQLite

sqlite 3

2026-08-15
CVE-2026-51303
Analyzed
9.8
SQLite SQLite

A use-after-free vulnerability in the SQLite core parsing component allows remote attackers to trigger a crash, leak sensitive memory, or achieve arbi...

2026-07-28
CVE-2026-51302
9.8
Unknown Multiple Products

SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluation logic. The sqlite3ReleaseTempReg function improperly releases tempo...

2026-08-16
CVE-2026-51300
9.1
Unknown Multiple Products

A use-after-free vulnerability exists in the expression parsing and memory management logic of SQLite 3.41. After invoking sqlite3ExprDelete to releas...

2026-08-17
CVE-2026-5130
8.8
WordPress was vulnerable

The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1

2026-03-31
CVE-2026-51297
Analyzed
8.8
GitHub SQLite

sqlite 3

2026-07-28
CVE-2026-51296
Analyzed
7.5
SQLite SQLite

SQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQLite JSON module. The parsed JSON object is freed at line 3555, while line 3575...

2026-08-18
CVE-2026-51291
Analyzed
9.8
SQLite SQLite

A use-after-free vulnerability in the jsonCacheInsert function of SQLite 3.41 may lead to application crashes or arbitrary code execution.

2026-07-31
CVE-2026-5128
Analyzed
10
Arch steam-trader

ArthurFiorette steam-trader 2.1.1 is vulnerable to unauthenticated sensitive information exposure, leaking Steam account credentials and 2FA secrets v...

2026-03-31
CVE-2026-51275
Analyzed
8.8
Unknown ESP32-audioI2S

In schreibfaul1 ESP32-audioI2S 3

2026-07-29
CVE-2026-51274
Analyzed
8.8
Unknown ESP32-audioI2S

In schreibfaul1 ESP32-audioI2S 3

2026-07-29
CVE-2026-51272
Analyzed
9.8
Unknown ESP32-audioI2S

A heap-based buffer overflow in the schreibfaul1 ESP32-audioI2S library allows for potential code execution or denial of service via malformed input d...

2026-07-31
CVE-2026-5127
8.8
WordPress is vulnerable

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserial...

2026-05-08
CVE-2026-51269
Analyzed
8.8
Unknown ESP32-audioI2S

schreibfaul1 ESP32-audioI2S 3

2026-07-29
CVE-2026-51267
Analyzed
9.8
GitHub ESP32-audioI2S

The schreibfaul1 ESP32-audioI2S 3.4.5 library is susceptible to a heap-based buffer overflow in the URL path concatenation module, allowing for remote...

2026-07-29
CVE-2026-51266
Analyzed
9.8
Unknown ESP32-audioI2S

The schreibfaul1 ESP32-audioI2S 3.4.5 library contains a heap-based buffer overflow in its HTTP header construction logic due to insufficient size val...

2026-07-29
CVE-2026-51263
Analyzed
9.8
Unknown ESP32-audioI2S

The Audio::openai_speech function in schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to a heap buffer overflow due to improper validation of externall...

2026-07-29
CVE-2026-51259
Analyzed
9.8
GitHub ESP32-audioI2S

An integer overflow in the buffer size calculation for schreibfaul1 ESP32-audioI2S 3.4.5 results in heap memory corruption, enabling denial of service...

2026-07-29
CVE-2026-51252
Analyzed
9.8
GitHub ESP32-audioI2S

A buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote attackers to execute code...

2026-07-29
CVE-2026-51244
Analyzed
7.5
GitHub ESP32-audioI2S

schreibfaul1 ESP32-audioI2S 3

2026-08-15
CVE-2026-51235
Analyzed
8.8
GitHub LibRaw

LibRaw 0

2026-07-28
CVE-2026-5118
Analyzed
9.8
WordPress Divi Form Builder

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated users to register as administrators.

2026-05-22
CVE-2026-5113
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2

2026-05-02
CVE-2026-5112
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-51119
Analyzed
9.1
Invixium IXM WEB

Invixium IXM WEB v.2.3.85.25 contains a privilege escalation vulnerability in the /SystemUsers/CreateAppUser component that allows unauthorized users...

2026-07-11
CVE-2026-5111
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5110
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-5109
7.2
WordPress is vulnerable

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2

2026-05-02
CVE-2026-51080
Analyzed
9.8
Proxmox libpve-storage-perl

The Proxmox libpve-storage-perl library contains an XML External Entity (XXE) vulnerability that could lead to unauthorized data disclosure or service...

2026-07-18
CVE-2026-51031
Analyzed
7.5
FlareSolverr FlareSolverr

FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker t...

2026-07-27
CVE-2026-51027
Analyzed
9.9
HP FileThingie

FileThingie version 2.5.7 contains a vulnerability in the ft2.php component that allows a remote, authenticated attacker to obtain sensitive informati...

2026-07-21
CVE-2026-5100
Analyzed
7.5
WordPress is vulnerable

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4

2026-05-05
CVE-2026-50884
Analyzed
8.8
Statping-ng statping-ng

Incorrect access control in statping-ng v0

2026-06-17
CVE-2026-5087
7.5
Unknown Multiple Products

PAGI::Middleware::Session::Store::Cookie versions through 0

2026-04-02
CVE-2026-5085
Analyzed
9.1
Unknown Multiple Products

Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the...

2026-04-14
CVE-2026-5081
Analyzed
9.1
Apache mod

The Apache::Session::Generate::ModUniqueId module generates insecure session IDs using predictable environment variables, allowing for potential sessi...

2026-05-07
CVE-2026-50768
Analyzed
9.8
Unknown ImageMaster

T-Systems International GmbH ImageMaster version 9.14.2.8.1 contains a file upload vulnerability in the add attachments feature, allowing remote unaut...

2026-08-18
CVE-2026-5076
Analyzed
9.8
WordPress ARMember Premium Plugin

The ARMember Premium plugin for WordPress stores plaintext password reset keys, allowing unauthenticated attackers to reset user passwords and hijack...

2026-06-03
CVE-2026-50759
7.5
Unknown Multiple Products

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints wit...

2026-08-04
CVE-2026-50758
8.1
Unknown Multiple Products

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

2026-08-04
CVE-2026-50757
7.8
Unknown Multiple Products

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-s...

2026-08-04