21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4251-4300 of 21637 CVEs Page 86 of 433
CVE-2026-50151
Analyzed
7.5
Unknown oras-go

oras-go is a Go library for managing OCI artifacts

2026-07-19
CVE-2026-50148
Analyzed
10
Intel metabase

A critical vulnerability in Metabase allows users with database connection permissions to achieve remote code execution via a flaw in the Snowflake JD...

2026-07-16
CVE-2026-50146
Analyzed
7.1
WithAstro Astro

Astro is a web framework

2026-06-23
CVE-2026-50137
Analyzed
8.2
Budibase Budibase

Budibase is an open-source low-code platform

2026-06-27
CVE-2026-50136
Analyzed
7.4
Budibase Budibase

Budibase is an open-source low-code platform

2026-06-28
CVE-2026-50132
Analyzed
7.3
Budibase Budibase

Budibase is an open-source low-code platform

2026-06-28
CVE-2026-50131
Analyzed
8.6
Fedify Fedify (TypeScript library)

Fedify is a TypeScript library for building federated server apps powered by ActivityPub

2026-06-11
CVE-2026-50130
Analyzed
8.8
Pi-hole Pi-hole

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software

2026-07-15
CVE-2026-5012
7.3
Infor Multiple Products

A flaw has been found in elecV2 elecV2P up to 3

2026-03-29
CVE-2026-50110
Analyzed
9.2
StoneFly Storage Concentrator

StoneFly Storage Concentrator stores hardcoded, reversible credentials for internal services within a configuration file, enabling potential unauthori...

2026-07-01
CVE-2026-50101
Analyzed
8.1
Naxclow Smart Home Devices

Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot

2026-06-14
CVE-2026-50090
Analyzed
9.3
Aqara Cloud OAuth

A redirect bypass vulnerability in the Aqara Cloud OAuth endpoint allows attackers to perform credential theft and phishing by exploiting weak domain...

2026-06-13
CVE-2026-50088
Analyzed
8.2
Aqara Aqara Developer Portal

The Aqara Developer Portal (developer

2026-06-13
CVE-2026-50087
Analyzed
8.2
Aqara IAM/SSO Gateway

The Aqara IAM/SSO gateway (gw-builder

2026-06-13
CVE-2026-50086
Analyzed
10
GitHub IAM/SSO gateway

The Aqara IAM/SSO gateway contains a critical flaw that exposes cryptographic signing keys, allowing unauthenticated attackers to perform unauthorized...

2026-06-13
CVE-2026-50085
Analyzed
8.6
Aqara Board service (op-test)

The Aqara Board service (op-test

2026-06-13
CVE-2026-50084
Analyzed
9.6
Aqara Cloud Production API

The Aqara Cloud Production API suffers from a missing authorization vulnerability, allowing any valid developer token to access any user account.

2026-06-13
CVE-2026-50043
Analyzed
8.6
Seiko SkyBridge MB-A100/MB-A110

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110

2026-07-01
CVE-2026-5004
Analyzed
8.8
Wavlink WL-WN579X3-C

A vulnerability was determined in Wavlink WL-WN579X3-C 231124

2026-03-29
CVE-2026-50027
Analyzed
9.8
Unknown mcp-memory-service

The mcp-memory-service package contains a critical authentication bypass vulnerability in the /api/documents/* routes, allowing unauthenticated remote...

2026-08-15
CVE-2026-50023
Analyzed
8.3
Unknown yt-dlp

yt-dlp is a command-line audio/video downloader

2026-06-24
CVE-2026-5002
7.3
LG Multiple Products

A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054

2026-03-29
CVE-2026-50016
Analyzed
8.8
Intel pnpm

pnpm is a package manager

2026-06-26
CVE-2026-50011
Analyzed
7.5
Netty Netty

Netty is a network application framework for development of protocol servers and clients

2026-06-15
CVE-2026-50010
Analyzed
7.5
Netty Netty

Netty is a network application framework for development of protocol servers and clients

2026-06-15
CVE-2026-5001
7.3
LG Multiple Products

A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054

2026-03-29
CVE-2026-50003
Analyzed
9.8
OFFIS DCMTK Toolkit

A path traversal vulnerability in the DCMTK Toolkit allows a malicious server to force a client to write files to arbitrary locations on the host syst...

2026-07-01
CVE-2026-5000
7.3
LG Multiple Products

A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054

2026-03-29
CVE-2026-49998
Analyzed
8.2
Centrifugal Centrifugo

Centrifugo is an open-source scalable real-time messaging server

2026-07-17
CVE-2026-49991
Analyzed
8.6
RustFS RustFS

RustFS is a distributed object storage system built in Rust

2026-06-27
CVE-2026-49989
Analyzed
7.1
Crate CrateDB

CrateDB is a distributed SQL database

2026-08-16
CVE-2026-49986
Analyzed
7.1
Unknown Cortex

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3

2026-08-16
CVE-2026-49984
Analyzed
7.7
Kestra Kestra

Kestra is an open-source, event-driven orchestration platform

2026-06-28
CVE-2026-49982
Analyzed
8.2
Raszi node-tmp

tmp is a temporary file and directory creator for node

2026-06-12
CVE-2026-49980
Analyzed
9.8
Rclone Rclone

Rclone’s remote control daemon (rcd) allows unauthenticated Remote Code Execution by processing malicious GET/HEAD requests that trigger local command...

2026-06-25
CVE-2026-4998
Analyzed
7.3
Unknown Multiple Products

A weakness has been identified in Sinaptik AI PandasAI up to 3

2026-03-29
CVE-2026-49972
Analyzed
8.8
Plank laravel-mediable

Laravel-Mediable before 7

2026-07-14
CVE-2026-49970
Analyzed
8.8
Plank laravel-mediable

Laravel-Mediable before 7

2026-07-14
CVE-2026-4996
Analyzed
7.3
Unknown Multiple Products

A vulnerability was identified in Sinaptik AI PandasAI up to 0

2026-03-29
CVE-2026-49959
Analyzed
8.8
Hermes WebUI

Hermes WebUI before version 0

2026-06-10
CVE-2026-4990
7.3
Unknown Multiple Products

A security vulnerability has been detected in chatwoot up to 4

2026-03-29
CVE-2026-49877
Analyzed
8.1
Apache Apache ActiveMQ

Improper Authorization vulnerability in Apache ActiveMQ

2026-07-01
CVE-2026-4987
7.5
WordPress is vulnerable

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up...

2026-03-29
CVE-2026-49869
Analyzed
10
Kestra Kestra

Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary wor...

2026-06-27
CVE-2026-49864
Analyzed
8.6
Unknown wetty

wetty provides terminal access in browser over http/https

2026-08-15
CVE-2026-49852
Analyzed
8.7
Unknown joserfc

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards

2026-07-18
CVE-2026-49851
Analyzed
8.7
Lepture Mistune

Mistune is a Python Markdown parser with renderers and plugins

2026-06-25
CVE-2026-49841
Analyzed
9.8
FreeSWITCH FreeSWITCH

A heap overflow vulnerability in the FreeSWITCH mod_verto module allows unauthenticated attackers to trigger memory corruption via crafted HTTP reques...

2026-06-10
CVE-2026-4984
8.2
Twilio integration webhook

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'

2026-03-28
CVE-2026-49827
Analyzed
9.8
HP WebErpMesv2

WebErpMesv2 versions 1.19 and prior are vulnerable to unauthenticated remote code execution via arbitrary PHP file uploads in the HR Expense scan_file...

2026-08-14