23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 401-450 of 23295 CVEs Page 9 of 466
CVE-2026-84757
Analyzed
8.2
WordPress WP Compress

Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.

2026-09-04
CVE-2026-84753
Analyzed
9.8
HP Mail Mint

A critical PHP object injection vulnerability in the Mail Mint plugin allows unauthenticated attackers to execute arbitrary code.

2026-09-04
CVE-2026-84752
Analyzed
8.8
HP RTMKit

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

2026-09-04
CVE-2026-84736
Analyzed
8.3
Apple Eclipse aeriOS

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certi...

2026-09-04
CVE-2026-84715
Analyzed
8.8
MythicalLTD FeatherPanel

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to...

2026-09-02
CVE-2026-84700
Analyzed
8.6
OpenAtomFoundation PikiwiDB (Pika)

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default c...

2026-09-02
CVE-2026-84699
Analyzed
9.1
Unknown Team Password Manager

Team Password Manager contains an authentication bypass vulnerability in the local password reset flow, allowing unauthenticated attackers to reset pa...

2026-09-02
CVE-2026-84695
Analyzed
8.7
BookStack BookStack

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content a...

2026-09-02
CVE-2026-84694
Analyzed
8.8
Docker Coolify

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated at...

2026-09-02
CVE-2026-84673
Analyzed
8.8
Jenkins Jenkins Customizable Header Plugin

Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data bind...

2026-09-03
CVE-2026-84672
Analyzed
8.8
Microsoft Microsoft Entra ID (previously Azure AD) Plugin

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique ob...

2026-09-03
CVE-2026-84671
Analyzed
8.8
Jenkins Jenkins File Parameter Plugin

Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system throug...

2026-09-03
CVE-2026-84670
Analyzed
8.8
Jenkins Jenkins Performance Plugin

Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performan...

2026-09-03
CVE-2026-84669
Analyzed
8.8
Jenkins Jenkins Allure Plugin

A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure repo...

2026-09-03
CVE-2026-84668
Analyzed
8.8
Jenkins Jenkins SAML Plugin

Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowi...

2026-09-03
CVE-2026-84650
Analyzed
8.8
Jenkins Jenkins

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit con...

2026-09-03
CVE-2026-84649
Analyzed
8.8
Jenkins Jenkins

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.57...

2026-09-03
CVE-2026-84648
Analyzed
8.8
Jenkins Jenkins

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) result...

2026-09-03
CVE-2026-84647
Analyzed
8.8
Jenkins Jenkins

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler d...

2026-09-03
CVE-2026-84645
Analyzed
8.8
Jenkins Jenkins

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration f...

2026-09-03
CVE-2026-8461
Analyzed
8.8
FFmpeg libavcodec

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases...

2026-06-19
CVE-2026-8457
Analyzed
9.8
Apple WooCommerce - Social Login

The WooCommerce - Social Login plugin is vulnerable to authentication bypass via forged Apple ID tokens and exposed security nonces, allowing attacker...

2026-08-02
CVE-2026-8452
KEV Analyzed
8.8
NetScaler ADC and Gateway

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applianc...

2026-07-01
CVE-2026-8451
Analyzed
8.8
NetScaler ADC and Gateway

Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as...

2026-07-01
CVE-2026-8449
Analyzed
8.8
Linux ksmbd contains

Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissio...

2026-05-13
CVE-2026-84482
Analyzed
8.8
GitHub AVideo

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to...

2026-09-02
CVE-2026-84480
Analyzed
9.8
HP AVideo

WWBN AVideo fails to validate password recovery token expiration, allowing unauthenticated attackers to reuse expired tokens to reset user passwords a...

2026-09-02
CVE-2026-84479
Analyzed
9.1
WWBN AVideo

WWBN AVideo improperly relies on the User-Agent header for authentication security, allowing attackers to bypass two-factor authentication and securit...

2026-09-02
CVE-2026-84452
Analyzed
8.6
Microsoft WinML CLI

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/mode...

2026-09-03
CVE-2026-8445
Analyzed
9.8
EmilStenstrom justhtml

A failure to properly escape HTML characters in the justhtml library when converting to Markdown allows for sanitizer bypass and potential cross-site...

2026-08-24
CVE-2026-8444
Analyzed
8.8
WordPress WP Review Slider Pro

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in...

2026-06-16
CVE-2026-8443
Analyzed
8.8
WordPress WP Review Slider Pro

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_cha...

2026-06-16
CVE-2026-84381
Analyzed
8.1
Pydantic HTTPX2

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and...

2026-09-04
CVE-2026-84372
Analyzed
9.8
HP Predis

Predis PHP client pipeline handling is vulnerable to CRLF injection, allowing unauthenticated attackers to execute unauthorized Redis commands via mal...

2026-09-02
CVE-2026-84350
Analyzed
8.8
Google Chrome

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code o...

2026-09-03
CVE-2026-84347
Analyzed
8.8
Google Chrome

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted...

2026-09-03
CVE-2026-8434
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9 before 9

2026-05-27
CVE-2026-8433
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9 before 9

2026-05-27
CVE-2026-84326
Analyzed
8.8
Google Chrome

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a craf...

2026-09-03
CVE-2026-8432
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9 before 9

2026-05-27
CVE-2026-84304
Analyzed
8.7
Unknown gRPC-Go

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a sepa...

2026-09-02
CVE-2026-8430
Analyzed
8.1
Unknown configurations

SPIP versions prior to 4

2026-05-13
CVE-2026-8429
Analyzed
8.8
Unknown Multiple Products

SPIP versions prior to 4

2026-05-13
CVE-2026-8428
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9

2026-05-27
CVE-2026-8427
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9 before 9

2026-05-27
CVE-2026-84268
Analyzed
8.8
Red Hat gvfs

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a le...

2026-09-02
CVE-2026-8426
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9

2026-05-27
CVE-2026-84238
Analyzed
9.8
WordPress Request a Quote for WooCommerce Premium

YITH Request a Quote for WooCommerce Premium versions prior to 4.46.0 contain an unauthenticated broken access control vulnerability, allowing unautho...

2026-09-04
CVE-2026-84235
Analyzed
8.7
Rockwell Automation 1756-ENBT Module

A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module....

2026-09-02
CVE-2026-8421
Analyzed
8.8
Concrete CMS Concrete CMS

Concrete CMS 9

2026-05-27