21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4351-4400 of 21637 CVEs Page 88 of 433
CVE-2026-49420
Analyzed
8.8
FreeBSD FreeBSD

The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer,...

2026-08-20
CVE-2026-49402
Analyzed
8.1
Deno Land Deno

Deno is a JavaScript, TypeScript, and WebAssembly runtime

2026-06-24
CVE-2026-49368
Analyzed
8.7
YouTrack Multiple Products

In JetBrains YouTrack before 2026

2026-05-30
CVE-2026-49352
Analyzed
9.8
GitHub 9router

9Router contains a hardcoded fallback JWT secret in its authentication routing and middleware, allowing unauthenticated attackers to forge authenticat...

2026-07-16
CVE-2026-4935
8.6
WordPress plugin before

The OttoKit: All-in-One Automation Platform WordPress plugin before 1

2026-05-09
CVE-2026-49340
Analyzed
8.1
Unknown gonic

gonic is a music streaming server / free-software subsonic server API implementation

2026-06-21
CVE-2026-49332
Analyzed
8.5
Red Hat OpenShift Container Platform 4

A flaw was found in openshift/oauth-proxy

2026-07-29
CVE-2026-49298
Analyzed
8.8
Kubernetes Airflow

A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worke...

2026-06-03
CVE-2026-49297
Analyzed
8.1
Google Apache Airflow Google provider

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket l...

2026-07-07
CVE-2026-49291
Analyzed
8.1
MCP mcp-memory-service

mcp-memory-service is a semantic memory layer for AI applications

2026-06-21
CVE-2026-49286
Analyzed
8.1
HP PhpWeasyPrint

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page

2026-06-21
CVE-2026-49284
Analyzed
7.1
HP SimpleSAMLphp

SimpleSAMLphp versions before 1

2026-07-19
CVE-2026-49283
Analyzed
8.7
HP SAML2

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality

2026-08-21
CVE-2026-49269
Analyzed
8.6
Apple M1 GPU

Apple M1 GPUs retain register file data between compute shader dispatches from different processes

2026-06-25
CVE-2026-49261
Analyzed
10
MariaDB MariaDB Server

A command injection vulnerability in MariaDB server allows shell command execution via the joiner node name when the `wsrep_notify_cmd` configuration...

2026-06-12
CVE-2026-49260
Analyzed
8.2
HP PhpWeasyPrint

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page

2026-06-21
CVE-2026-49258
Analyzed
8.8
Slack nebula-mesh

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN

2026-07-29
CVE-2026-49257
Analyzed
10
Apache Pinot (via mcp-pinot)

The mcp-pinot server defaults to an unauthenticated configuration, allowing any network-adjacent attacker to execute arbitrary SQL and mutate table co...

2026-06-19
CVE-2026-49255
Analyzed
8.8
Unknown electerm

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

2026-08-20
CVE-2026-49247
Analyzed
8.8
Jellyfin Media Server

Jellyfin is an open source self hosted media server

2026-06-25
CVE-2026-49241
Analyzed
8.7
Google Angular Language Service VS Code Extension

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates

2026-06-23
CVE-2026-4924
8.2
Devolutions Multiple Products

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026

2026-04-02
CVE-2026-49238
Analyzed
8.4
Unknown Multiple Products

An issue was discovered in Canonical Multipass before version 1

2026-05-29
CVE-2026-49229
Analyzed
8.3
ActualBudget Actual

Actual is a local-first personal finance app

2026-07-08
CVE-2026-49228
Analyzed
8.8
Unknown Vvveb

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

2026-08-19
CVE-2026-49221
Analyzed
8.8
Unknown Vvveb

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

2026-08-19
CVE-2026-4922
8.1
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17

2026-04-23
CVE-2026-49213
Analyzed
8.1
Unknown typebot.io

TypeBot is a chatbot builder tool

2026-07-11
CVE-2026-49195
Analyzed
8.8
Unknown Debug Service

Unauthenticated Debug Service

2026-06-09
CVE-2026-49194
Analyzed
8.8
Unknown Unknown

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shel...

2026-06-05
CVE-2026-49191
Analyzed
9.8
Acer Connect M6E 5G Portable WiFi Router

The M3WebServer in the Acer Connect M6E 5G router hard-codes backend API keys, which are exposed via verbose error pages.

2026-06-05
CVE-2026-49190
Analyzed
8.8
Unknown Unknown

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installat...

2026-06-05
CVE-2026-49188
Analyzed
9.8
Acer Connect M6E 5G Portable WiFi Router

The ai_cmd utility on the Acer Connect M6E 5G router runs with root privileges and is vulnerable to unauthenticated command injection via popen().

2026-06-05
CVE-2026-49186
Analyzed
9.8
Acer Connect M6E 5G Portable WiFi Router

The local MQTT broker on the Acer Connect M6E 5G router fails to enforce ACLs, allowing unauthorized clients to enumerate devices and publish rogue co...

2026-06-05
CVE-2026-49185
Analyzed
9.8
Acer Connect M6E 5G Portable WiFi Router

The FieldX MDM component in the Acer Connect M6E 5G router is vulnerable to command injection via unverified payloads in the adb messaging topic.

2026-06-05
CVE-2026-49179
Analyzed
8.8
Microsoft Windows

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to exe...

2026-08-12
CVE-2026-49178
Analyzed
8.8
Microsoft Active Directory Domain Services

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-49172
Analyzed
9.8
Microsoft Windows

A heap-based buffer overflow in the Windows FTP Service allows an unauthenticated attacker to execute arbitrary code over a network.

2026-07-15
CVE-2026-49158
Analyzed
7.5
Apache Apache Thrift

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings

2026-07-28
CVE-2026-49157
Analyzed
8.8
Apache ActiveMQ

Incorrect Default Permissions vulnerability in Apache ActiveMQ

2026-06-02
CVE-2026-49143
Analyzed
8.8
BrowserStack Runner

BrowserStack Runner through 0

2026-06-03
CVE-2026-49127
Analyzed
8.6
Unknown Multiple Products

Music Player Daemon (MPD) before version 0

2026-05-29
CVE-2026-49120
Analyzed
8.5
Medplum Medplum

Medplum before 5

2026-06-04
CVE-2026-49113
Analyzed
8.5
Cornerstone Cornerstone

Subscriber Arbitrary Code Execution in Cornerstone < 7

2026-06-18
CVE-2026-49111
Analyzed
8.8
WordPress Masteriyo - LMS

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation

2026-06-16
CVE-2026-49109
Analyzed
9.8
HP Integration for Salesforce

An unauthenticated PHP Object Injection vulnerability in the CRM Perks Integration for Salesforce allows remote attackers to achieve arbitrary code ex...

2026-06-16
CVE-2026-49106
Analyzed
9.8
HP Integration for Contact Form 7 and Constant Contact

An unauthenticated PHP Object Injection vulnerability exists in the CRM Perks Integration for Contact Form 7 and Constant Contact, enabling potential...

2026-06-16
CVE-2026-49105
Analyzed
9.8
HP WP Zendesk

An unauthenticated PHP Object Injection vulnerability in the WP Zendesk integration for WordPress allows attackers to execute arbitrary code via deser...

2026-06-16
CVE-2026-49104
Analyzed
9.8
HP Integration for Keap/infusionsoft

An unauthenticated PHP Object Injection vulnerability in the CRM Perks Integration for Keap/infusionsoft allows remote attackers to perform deserializ...

2026-06-16
CVE-2026-49085
Analyzed
9.8
HP WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

An unauthenticated PHP Object Injection vulnerability exists in the WP Insightly integration plugin for various WordPress form builders, allowing pote...

2026-06-16