20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 4251-4300 of 20297 CVEs Page 86 of 406
CVE-2026-45399
Analyzed
7.1
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-17
CVE-2026-45398
Analyzed
7.5
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-17
CVE-2026-45395
Analyzed
7.2
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-17
CVE-2026-45392
Analyzed
8.7
Cribl Stream

DOM-based cross-site scripting (XSS) in Cribl Stream before 4

2026-06-04
CVE-2026-45375
Analyzed
9
SiYuan SiYuan

A stored Cross-Site Scripting (XSS) vulnerability in the SiYuan Marketplace allows attackers to execute arbitrary HTML/JS via malicious package metada...

2026-05-15
CVE-2026-45372
Analyzed
9.9
Unknown cpp-httplib

cpp-httplib is vulnerable to header injection because it performs validity checks before percent-decoding, allowing attackers to inject CRLF sequences...

2026-05-30
CVE-2026-45370
Analyzed
7.7
Unknown Multiple Products

python-utcp is the python implementation of UTCP

2026-05-16
CVE-2026-45369
Analyzed
8.3
Unknown Multiple Products

python-utcp is the python implementation of UTCP

2026-05-15
CVE-2026-45368
Analyzed
8.4
Unknown kirby

Kirby is an open-source content management system

2026-07-17
CVE-2026-4536
7.3
Cloud Multiple Products

A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1

2026-03-22
CVE-2026-45350
Analyzed
7.1
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-17
CVE-2026-4535
8.8
Tenda FH451

A vulnerability has been found in Tenda FH451 1

2026-03-22
CVE-2026-45349
Analyzed
7.1
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-17
CVE-2026-45348
Analyzed
8.7
Unknown Multiple Products

pyLoad is a free and open-source download manager written in Python

2026-05-29
CVE-2026-4534
8.8
Tenda FH451

A flaw has been found in Tenda FH451 1

2026-03-22
CVE-2026-45338
Analyzed
7.7
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45336
Analyzed
10
StratonWebDesigners HireFlow

HireFlow versions 1.3 and earlier contain a hard-coded secret key in app.py, allowing unauthenticated attackers to forge session cookies and bypass au...

2026-07-17
CVE-2026-45331
Analyzed
8.5
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45325
Analyzed
8.2
Unknown go

Gestor de Oferta is a web application for managing mobility service offerings

2026-07-17
CVE-2026-45321
KEV Analyzed
9.6
GitHub Actions OIDC

GitHub Actions OIDC was exploited to publish malicious npm packages by chaining multiple vulnerabilities, including cache poisoning and token extracti...

2026-05-12
CVE-2026-45320
Analyzed
8.7
DataEase DataEase

DataEase is an open source data visualization and analysis tool

2026-07-16
CVE-2026-45315
Analyzed
8.7
Intel Open WebUI

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45312
Analyzed
9.9
RAGFlow RAGFlow

A Jinja2 template injection vulnerability in RAGFlow's prompt generator allows authenticated users to execute arbitrary OS commands on the server.

2026-05-30
CVE-2026-45309
Analyzed
8.2
Unknown asyncssh

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framew...

2026-07-18
CVE-2026-45305
Analyzed
8.7
HP Symfony / Yaml

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

2026-07-15
CVE-2026-45304
Analyzed
8.7
HP Symfony / Yaml

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

2026-07-15
CVE-2026-45303
Analyzed
7.7
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45301
Analyzed
8.1
Intel Multiple Products

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline

2026-05-16
CVE-2026-45298
Analyzed
8.6
Docker containers

Dozzle is a realtime log viewer for docker containers

2026-05-29
CVE-2026-45293
Analyzed
8.6
HP WordPress-Coding-Standards

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions

2026-07-29
CVE-2026-4529
Analyzed
8.8
HP Multiple Products

A vulnerability was identified in D-Link DHP-1320 1

2026-03-22
CVE-2026-45288
Analyzed
9.8
Arch APIs interpolated

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-suppli...

2026-05-29
CVE-2026-4528
7.3
Unknown Multiple Products

A vulnerability was determined in trueleaf ApiFlow 0

2026-03-22
CVE-2026-45270
Analyzed
8.7
GitHub ci4ms

CI4MS is a CodeIgniter 4-based content management system skeleton

2026-07-21
CVE-2026-45260
Analyzed
8.1
Pimcore Pimcore

Pimcore is an Open Source Data & Experience Management Platform

2026-07-18
CVE-2026-45257
Analyzed
7.8
FreeBSD FreeBSD

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify

2026-06-27
CVE-2026-45255
Analyzed
7.5
Unknown Multiple Products

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the...

2026-05-22
CVE-2026-45253
Analyzed
8.4
Unknown Multiple Products

ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls

2026-05-22
CVE-2026-45251
Analyzed
7.8
Unknown Multiple Products

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor

2026-05-22
CVE-2026-45250
Analyzed
7.8
Unknown Multiple Products

The setcred(2) system call is only available to privileged users

2026-05-22
CVE-2026-4525
7.5
Unknown Multiple Products

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault...

2026-04-17
CVE-2026-45247
KEV Analyzed
9.8
HP Full Page Cache Warmer for Magento 2

Mirasvit Full Page Cache Warmer for Magento 2 contains a PHP object injection vulnerability allowing unauthenticated RCE via the CacheWarmer cookie.

2026-05-27
CVE-2026-45245
Analyzed
7.4
Unknown Multiple Products

Summarize prior to 0

2026-05-19
CVE-2026-45242
Analyzed
7.1
Unknown Multiple Products

Summarize prior to 0

2026-05-19
CVE-2026-45233
Analyzed
8.1
HTMLy CMS

HTMLy CMS through 3

2026-06-27
CVE-2026-45230
Analyzed
9.1
DumbAssets DumbAssets

DumbAssets contains a path traversal vulnerability in the file deletion API that allows unauthenticated attackers to delete arbitrary files, resulting...

2026-05-19
CVE-2026-45229
Analyzed
8.8
Drive Multiple Products

Quark Drive before 0

2026-05-14
CVE-2026-45227
Analyzed
8.8
Heym Multiple Products

Heym before 0

2026-05-13
CVE-2026-45224
Analyzed
7.1
Crabbox Multiple Products

Crabbox before 0

2026-05-12
CVE-2026-45223
Analyzed
8.8
Crabbox Multiple Products

Crabbox before 0

2026-05-12