23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 4151-4200 of 23295 CVEs Page 84 of 466
CVE-2026-5816
Analyzed
8
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2026-04-23
CVE-2026-58159
Analyzed
8.2
Apache Apache Traffic Server

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors

2026-07-30
CVE-2026-58157
Analyzed
8.7
Apache Apache Traffic Server

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections

2026-07-30
CVE-2026-58154
Analyzed
8.9
Apache Apache Traffic Server

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers

2026-07-29
CVE-2026-58153
Analyzed
8.3
Apache Apache Traffic Server

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1

2026-07-29
CVE-2026-58150
Analyzed
10
Apache Apache Traffic Server

Apache Traffic Server fails to properly reject Transfer-Encoding headers in HTTP/2 requests, enabling downgrade-based request smuggling.

2026-07-29
CVE-2026-5815
Analyzed
8.8
D-Link DIR

A vulnerability was detected in D-Link DIR-645 1

2026-04-09
CVE-2026-58148
Analyzed
8.7
Joomla ChronoForms extension for Joomla

The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability

2026-07-18
CVE-2026-58143
Analyzed
8.8
HP Cotonti

Cotonti Siena 0

2026-07-10
CVE-2026-58138
Analyzed
9.8
Orkes Conductor

Orkes Conductor is vulnerable to unauthenticated remote code execution via malicious workflow definitions that exploit improperly configured GraalVM e...

2026-07-01
CVE-2026-58127
Analyzed
9.8
Hyland PACSgear MediaWriter

Hyland PACSgear MediaWriter is vulnerable to unauthenticated remote code execution via a .NET Remoting TCP service, allowing arbitrary file read/write...

2026-07-02
CVE-2026-58126
Analyzed
9.8
Hyland PACSgear PACS Scan

Hyland PACSgear PACS Scan is vulnerable to unauthenticated remote code execution via a .NET Remoting TCP service, allowing attackers to gain SYSTEM-le...

2026-07-02
CVE-2026-58123
Analyzed
9.8
Unknown hermes-webui

Hermes WebUI contains an unauthenticated remote code execution vulnerability in its embedded terminal API, allowing attackers to execute arbitrary she...

2026-07-10
CVE-2026-58122
Analyzed
9.1
Unknown hermes-webui

An authentication bypass vulnerability in Hermes WebUI allows attackers to spoof X-Forwarded-For headers to circumvent IP restrictions and perform una...

2026-07-10
CVE-2026-58116
Analyzed
9.8
Unknown LlamaFactory

LlamaFactory allows unauthenticated attackers with WebUI access to execute arbitrary Python code by providing a malicious model path.

2026-07-01
CVE-2026-58115
Analyzed
10
Siemens SIMATIC IoT2050 Advanced

A missing authentication vulnerability in the Node-RED interface of Siemens SIMATIC IoT2050 Advanced devices allows unauthenticated remote attackers t...

2026-08-12
CVE-2026-58102
Analyzed
9.1
JONASBN Crypt::OpenSSL::X509

Crypt::OpenSSL::X509 for Perl is vulnerable to a heap out-of-bounds read via a long certificate extension OID, potentially leading to sensitive inform...

2026-07-16
CVE-2026-58101
Analyzed
7.5
JONASBN Crypt::OpenSSL::X509

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an ex...

2026-07-16
CVE-2026-58097
Analyzed
7.8
FreeBSD FreeBSD

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A l...

2026-09-01
CVE-2026-58096
Analyzed
9.8
FreeBSD FreeBSD

The LcpDecodeConfig function in FreeBSD fails to validate the length of endpoint discriminator options, leading to an out-of-bounds write vulnerabilit...

2026-08-27
CVE-2026-58095
Analyzed
9.8
FreeBSD FreeBSD

A heap-based buffer overflow in the mp_Enddisc function of FreeBSD allows unauthenticated remote attackers to cause a crash or execute arbitrary code...

2026-08-27
CVE-2026-58094
Analyzed
7.8
FreeBSD FreeBSD

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after cre...

2026-09-02
CVE-2026-58093
Analyzed
7
FreeBSD FreeBSD

The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalid...

2026-08-31
CVE-2026-58092
Analyzed
8.1
FreeBSD FreeBSD

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of t...

2026-09-01
CVE-2026-58091
Analyzed
7.8
FreeBSD FreeBSD

The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync gr...

2026-09-01
CVE-2026-58090
Analyzed
7.8
FreeBSD FreeBSD

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them....

2026-09-01
CVE-2026-5809
Analyzed
7.1
WordPress is vulnerable

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3

2026-04-12
CVE-2026-58089
Analyzed
7.8
FreeBSD FreeBSD

When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted...

2026-08-31
CVE-2026-58080
Analyzed
8.8
Eclipse Foundation Eclipse Milo

In Eclipse Milo versions 1

2026-08-05
CVE-2026-58078
Analyzed
8.7
Joomla Quix Page Builder Pro

The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection

2026-07-16
CVE-2026-58077
Analyzed
8.7
Joomla 4Analytics extension for Joomla

The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS

2026-07-16
CVE-2026-58075
Analyzed
8.7
Veeam ONE

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges local...

2026-08-05
CVE-2026-58074
Analyzed
8.6
Veeam ONE

A vulnerability allowing a high-privileged user to execute arbitrary code on the server

2026-08-05
CVE-2026-58071
Analyzed
8.2
Veeam Service Provider Console

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator duri...

2026-08-05
CVE-2026-5807
Analyzed
7.5
Progress operation slot

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or reke...

2026-04-17
CVE-2026-58067
Analyzed
8.7
Veeam Service Provider Console

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service

2026-08-05
CVE-2026-58066
Analyzed
9.8
Rocket.Chat Rocket.Chat

A vulnerability in Rocket.Chat's SAML SSO implementation allows unauthenticated attackers to bypass authentication and impersonate arbitrary users via...

2026-07-30
CVE-2026-58065
Analyzed
8.1
Apache Apache Airflow Git provider

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An a...

2026-07-18
CVE-2026-58062
Analyzed
9.3
Unknown BC-JAVA

Bouncy Castle for Java fails to properly bind stapled OCSP responses to the checked certificate, allowing for potential validation bypasses.

2026-08-03
CVE-2026-58061
Analyzed
8.7
Unknown BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-58060
Analyzed
8.7
Unknown BC-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-58059
Analyzed
8.7
Unknown BC-JAVA

In Bouncy Castle for Java before 1

2026-08-03
CVE-2026-58056
Analyzed
7.6
RustDesk RustDesk

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session...

2026-06-28
CVE-2026-58054
Analyzed
7.2
MyBB MyBB

MyBB 1

2026-06-28
CVE-2026-58053
Analyzed
9.9
Docker act_runner

A container escape vulnerability in Gitea act_runner allows authenticated users to gain root access to the host machine by manipulating container opti...

2026-06-28
CVE-2026-58050
Analyzed
7
Unknown libssh2

libssh2 through 1

2026-06-29
CVE-2026-58049
Analyzed
8.6
FFmpeg FFmpeg

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc

2026-06-28
CVE-2026-58048
Analyzed
9.4
WebPros cPanel

A SQL injection vulnerability in cPanel allows authenticated users with low privileges to execute arbitrary SQL commands in the root context when rena...

2026-08-01
CVE-2026-58046
Analyzed
9.9
WebPros Plesk

A blind SQL injection vulnerability in the Plesk XML-RPC API allows an authenticated low-privileged user to read arbitrary data from the Plesk databas...

2026-07-30
CVE-2026-5804
Analyzed
8.4
Unknown Multiple Products

An improper authentication vulnerability was discovered in the Motorola Factory Test component (com

2026-05-20