21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4151-4200 of 21637 CVEs Page 84 of 433
CVE-2026-50756
7.5
Unknown Multiple Products

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

2026-08-04
CVE-2026-50755
9.8
Unknown Multiple Products

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

2026-07-31
CVE-2026-50751
KEV Analyzed
9.5
Check Point Security Gateway

Check Point Security Gateway is affected by an improper authentication vulnerability that is currently being exploited in the wild.

2026-06-09
CVE-2026-50748
Analyzed
9.9
Ubiquiti UniFi Access Application

Improper input validation in the UniFi Access Application allows low-privileged network attackers to perform command injection and execute arbitrary c...

2026-07-03
CVE-2026-50747
Analyzed
9.9
Ubiquiti UniFi Talk Application

Authenticated SQL injection vulnerabilities in the UniFi Talk Application allow low-privileged network attackers to escalate privileges on the host de...

2026-07-03
CVE-2026-50746
Analyzed
10
Ubiquiti UniFi Connect Application

An improper access control vulnerability in the UniFi Connect Application allows unauthenticated network attackers to execute arbitrary commands on th...

2026-07-03
CVE-2026-50741
Analyzed
8.8
Revive Adserver

Bypass to the fix for CVE-2026-34916

2026-06-26
CVE-2026-50733
Analyzed
8.8
Markdown Preview Enhanced Markdown Preview Enhanced

Markdown Preview Enhanced before 0

2026-06-07
CVE-2026-50692
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50687
Analyzed
8.8
Microsoft Windows

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50670
Analyzed
8.8
Microsoft Windows Kernel

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-5067
Analyzed
9.8
Zephyr HTTP Server

A memory corruption vulnerability in the Zephyr HTTP server WebSocket upgrade path allows unauthenticated remote attackers to trigger denial of servic...

2026-06-09
CVE-2026-50666
Analyzed
8.8
Microsoft Windows

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network

2026-07-15
CVE-2026-50663
Analyzed
8.8
Microsoft Age of Empires II: Definitive Edition Game

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network

2026-07-15
CVE-2026-5065
Analyzed
8.8
IBM Controller

IBM Controller 11

2026-05-28
CVE-2026-50644
Analyzed
8.6
SOPlanning SOPlanning

SOPlanning is vulnerable to SQL injection in the audit retention configuration

2026-07-10
CVE-2026-50637
Analyzed
8.2
CPAN (Metrics::Any) Metrics::Any::Adapter::Statsd

Metrics::Any::Adapter::Statsd versions before 0

2026-06-12
CVE-2026-50636
Analyzed
8.8
Oracle Multiple Products

The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), wh...

2026-06-10
CVE-2026-50635
Analyzed
8.8
LimeSurvey LimeSurvey

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it

2026-06-10
CVE-2026-50633
Analyzed
8.1
Apache CXF

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able...

2026-06-14
CVE-2026-50632
Analyzed
8.1
Apache CXF

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whic...

2026-06-14
CVE-2026-5063
7.2
WordPress plugin for

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in...

2026-05-04
CVE-2026-50622
Analyzed
8.8
Apache Apache Atlas

Description: Missing Authorization in Apache Atlas

2026-07-30
CVE-2026-50602
Analyzed
8.5
Acer Planet9 background service

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 ba...

2026-08-17
CVE-2026-5059
Analyzed
9.8
AWS CLI Command

The aws-mcp-server is vulnerable to remote code execution via AWS CLI command injection, allowing attackers to execute arbitrary system commands witho...

2026-04-11
CVE-2026-5058
Analyzed
9.8
AWS aws-mcp-server

The aws-mcp-server is vulnerable to remote code execution via command injection due to improper validation of user-supplied input in the allowed comma...

2026-04-11
CVE-2026-50574
Analyzed
8.3
Unknown yt-dlp

yt-dlp is a command-line audio/video downloader

2026-06-24
CVE-2026-50570
Analyzed
8.5
Kubernetes Fission

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes

2026-06-12
CVE-2026-50566
Analyzed
9.9
Kubernetes Fission Framework

An RBAC flaw in Fission allows tenants to run privileged containers under high-privilege service accounts, enabling container-sandbox escape and clust...

2026-06-11
CVE-2026-50564
Analyzed
9.9
Kubernetes Fission (Kubernetes Framework)

Fission prior to 1.24.0 contains a vulnerability in its Environment CRD that allows for privilege escalation by propagating insecure podspec fields wi...

2026-06-11
CVE-2026-50563
Analyzed
9.9
Kubernetes Fission Framework

A privilege management flaw in Fission’s Container Executor allows tenants to supply arbitrary pod specifications, creating potential for unauthorized...

2026-06-11
CVE-2026-50556
Analyzed
8.6
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-50555
Analyzed
8.6
Google Angular

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

2026-06-23
CVE-2026-50551
Analyzed
9.9
SiYuan SiYuan

A stored cross-site scripting (XSS) vulnerability in the SiYuan Attribute View allows for remote code execution (RCE) within the Electron desktop clie...

2026-06-25
CVE-2026-5055
7.8
Arch Path Element

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

2026-04-11
CVE-2026-50549
Analyzed
9.3
Intel Cursor

A path canonicalization flaw in the Cursor AI code editor allows malicious agents to bypass sandbox restrictions and write arbitrary files, facilitati...

2026-06-26
CVE-2026-50548
Analyzed
9.3
Cursor Cursor

A sandbox escape vulnerability in the Cursor AI code editor allows malicious agents to write arbitrary files outside the workspace, leading to non-san...

2026-06-26
CVE-2026-50545
Analyzed
9.9
Kubernetes Fission Framework

A validation flaw in Fission’s pod specification handling allows for the propagation of dangerous fields, leading to unauthorized control over generat...

2026-06-11
CVE-2026-5054
Analyzed
7.8
Unknown Multiple Products

NoMachine External Control of File Path Local Privilege Escalation Vulnerability

2026-04-11
CVE-2026-5053
7.1
Unknown Multiple Products

NoMachine External Control of File Path Arbitrary File Deletion Vulnerability

2026-04-12
CVE-2026-50529
Analyzed
8.7
Intel DataEase

DataEase is an open source data visualization and analysis tool

2026-07-08
CVE-2026-50523
Analyzed
7.8
Microsoft PowerShell

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute c...

2026-08-16
CVE-2026-50522
KEV Analyzed
9.8
Microsoft SharePoint

A deserialization vulnerability in Microsoft SharePoint allows an unauthenticated attacker to execute code over a network.

2026-07-15
CVE-2026-50521
Analyzed
8.3
Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network

2026-07-03
CVE-2026-50518
Analyzed
9.8
Microsoft Windows Server

A heap-based buffer overflow in the Windows DHCP Server service allows an unauthenticated, remote attacker to execute arbitrary code.

2026-07-15
CVE-2026-50517
Analyzed
9.9
Microsoft Microsoft 365 Copilot

A deserialization of untrusted data vulnerability in Microsoft 365 Copilot allows an authorized attacker to execute code over a network.

2026-07-25
CVE-2026-5050
7.5
Google Pay gateway

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions u...

2026-04-17
CVE-2026-50489
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50477
Analyzed
8.8
Microsoft Windows

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally

2026-07-15
CVE-2026-50474
Analyzed
8.8
Microsoft Windows

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2026-07-15