21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4401-4450 of 21637 CVEs Page 89 of 433
CVE-2026-49073
Analyzed
8.5
Unknown Directorist Booking

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injec...

2026-06-18
CVE-2026-49065
Analyzed
8.2
Hippoo Mobile App for WooCommerce

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1

2026-06-16
CVE-2026-49062
Analyzed
8.8
WP Engine Faust.Js

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust

2026-06-16
CVE-2026-49060
Analyzed
9.8
Hippoo Mobile Hippoo Mobile App for WooCommerce

An incorrect privilege assignment vulnerability in Hippoo Mobile App for WooCommerce allows remote attackers to perform privilege escalation.

2026-06-12
CVE-2026-4906
8.8
Tenda AC5

A vulnerability was determined in Tenda AC5 15

2026-03-27
CVE-2026-4905
8.8
Tenda AC5

A vulnerability was found in Tenda AC5 15

2026-03-27
CVE-2026-49049
Analyzed
7.5
Joomla Helix3 extension

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files...

2026-06-30
CVE-2026-49046
Analyzed
8.5
Arjun Thakur Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blin...

2026-05-29
CVE-2026-49042
Analyzed
7.3
Apache Camel

Improper Input Validation vulnerability in Apache Camel

2026-07-07
CVE-2026-4904
8.8
Tenda AC5

A vulnerability has been found in Tenda AC5 15

2026-03-27
CVE-2026-49035
Analyzed
8.1
MZ Automation libIEC61850

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request

2026-07-24
CVE-2026-49033
Analyzed
7.8
Labcenter Proteus

The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code

2026-07-08
CVE-2026-4903
8.8
Tenda AC5

A flaw has been found in Tenda AC5 15

2026-03-27
CVE-2026-4902
8.8
Tenda AC5

A vulnerability was detected in Tenda AC5 15

2026-03-27
CVE-2026-48970
Analyzed
8.1
WordPress Really Simple SSL

Unauthenticated Broken Authentication in Really Simple SSL <= 9

2026-06-16
CVE-2026-48967
Analyzed
8.5
WordPress Geo Mashup Plugin

Subscriber SQL Injection in Geo Mashup <= 1

2026-06-18
CVE-2026-48964
Analyzed
8.5
WordPress HelpDesk & Customer Ticketing System

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3

2026-06-16
CVE-2026-4896
Analyzed
8.1
WordPress is vulnerable

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct...

2026-04-04
CVE-2026-48939
KEV Analyzed
9.5
Joomla iCagenda extension for Joomla

iCagenda is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to execute arbitrary code on the server.

2026-07-11
CVE-2026-48920
Analyzed
8.8
Jenkins Email Extension

Jenkins Email Extension Plugin 1933

2026-05-28
CVE-2026-4892
Analyzed
8.4
DHCPv6 Multiple Products

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root priv...

2026-05-12
CVE-2026-48908
KEV Analyzed
9.5
Joomla SP Page Builder

JoomShaper SP Page Builder is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to execute arbitrary code.

2026-07-08
CVE-2026-48907
KEV Analyzed
9.5
Joomla Joomla Content Editor

An improper access control vulnerability in the Widget Factory Joomla Content Editor allows unauthorized users to perform restricted actions.

2026-06-17
CVE-2026-48904
Analyzed
9.8
Joomla CMS

An improper access check in the Joomla CMS `com_users` webservice endpoint allows for privilege escalation.

2026-05-27
CVE-2026-4890
Analyzed
7.5
DNSSEC validation Multiple Products

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS pac...

2026-05-12
CVE-2026-48899
Analyzed
9.8
Joomla CMS

Joomla CMS contains an improper access check in the `com_users` batch task, allowing for privilege escalation.

2026-05-27
CVE-2026-48898
Analyzed
9.8
Joomla CMS

An improper access check in the Joomla CMS `com_users` batch task allows for privilege escalation.

2026-05-27
CVE-2026-48889
Analyzed
8.8
WordPress Amelia Plugin

Subscriber Privilege Escalation in Amelia <= 2

2026-06-16
CVE-2026-48882
Analyzed
8.5
WordPress WP Time Slots Booking Form

Subscriber SQL Injection in WP Time Slots Booking Form <= 1

2026-06-16
CVE-2026-48879
Analyzed
9.8
WordPress AIWU

The AIWU plugin for WordPress is vulnerable to privilege escalation due to incorrect privilege assignment.

2026-06-02
CVE-2026-48874
Analyzed
8.5
WordPress GamiPress

Subscriber SQL Injection in GamiPress <= 7

2026-06-16
CVE-2026-4885
Analyzed
9.8
WordPress is vulnerable

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to insufficient extension filtering, enabling una...

2026-05-19
CVE-2026-48836
Analyzed
10
Easy Invoice Easy Invoice

Easy Invoice contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands on the server.

2026-06-16
CVE-2026-4883
Analyzed
9.8
WordPress is vulnerable

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to insufficient file extension blacklisting, enabling remote code ex...

2026-05-20
CVE-2026-4882
Analyzed
9.8
WordPress is vulnerable

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads, potentially leading to remote code execution.

2026-05-02
CVE-2026-48813
Analyzed
8.7
David A. Wheeler Flawfinder

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code

2026-08-12
CVE-2026-48801
Analyzed
8.7
Unknown linkify-it

linkify-it is a links recognition library with full Unicode support

2026-07-15
CVE-2026-48800
Analyzed
7.8
Notepad++ Notepad++

Notepad++ is a free and open-source source code editor

2026-06-27
CVE-2026-4880
Analyzed
9.8
WordPress is vulnerable

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege e...

2026-04-16
CVE-2026-48795
Analyzed
8.6
AdonisJS Core (BodyParser)

AdonisJS is a TypeScript-first web framework

2026-07-17
CVE-2026-48793
Analyzed
8.8
Jellyfin Jellyfin

Jellyfin is an open source self hosted media server

2026-06-25
CVE-2026-48780
Analyzed
8.2
Forem Forem

Forem is open source software for building communities

2026-06-17
CVE-2026-48778
Analyzed
7.8
Notepad++ Notepad++

Notepad++ is a free and open-source source code editor

2026-06-27
CVE-2026-48772
Analyzed
10
ProxySQL ProxySQL

A PROXY protocol v1 implementation flaw in ProxySQL allows unauthenticated attackers to spoof source IP addresses, resulting in ACL and routing bypass...

2026-06-20
CVE-2026-48765
Analyzed
9.9
Unknown typebot.io

Typebot.io versions prior to 3.17.0 contain an authorization bypass vulnerability allowing low-privilege users to perform cross-workspace OAuth creden...

2026-08-12
CVE-2026-48748
Analyzed
7.5
Netty Netty

Netty is a network application framework for development of protocol servers and clients

2026-06-15
CVE-2026-48746
Analyzed
9.1
Unknown vLLM

A vulnerability in the vLLM inference engine allows unauthenticated users to bypass OpenAI API key requirements, potentially exposing LLM services to...

2026-06-23
CVE-2026-48743
Analyzed
7.5
Envoy Proxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications

2026-06-28
CVE-2026-48732
Analyzed
8.8
Warp Warp

Warp is an agentic development environment

2026-06-25
CVE-2026-48725
Analyzed
8.1
Warp Warp

Warp is an agentic development environment

2026-06-25