21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4451-4500 of 21637 CVEs Page 90 of 433
CVE-2026-48721
Analyzed
8.6
Intel Warp

Warp is an agentic development environment

2026-06-25
CVE-2026-48720
Analyzed
8.8
Intel Warp Development Environment

Warp is an agentic development environment

2026-06-25
CVE-2026-48716
Analyzed
8.7
SAP nanobot

nanobot is a personal AI assistant

2026-06-20
CVE-2026-48712
Analyzed
7.5
Unknown protobuf.js

protobufjs compiles protobuf definitions into JavaScript (JS) functions

2026-06-23
CVE-2026-48704
Analyzed
8.8
Intel Warp Development Environment

Warp is an agentic development environment

2026-06-25
CVE-2026-48689
Analyzed
9.8
FastNetMon Community Edition

FastNetMon Community Edition contains an off-by-one heap-based buffer overflow in its `dynamic_binary_buffer_t` class, allowing potential RCE.

2026-05-27
CVE-2026-48686
Analyzed
9.8
FastNetMon Community Edition

FastNetMon Community Edition is vulnerable to a stack-based buffer overflow in the BGP NLRI decoder, potentially allowing RCE.

2026-05-27
CVE-2026-4868
Analyzed
8.2
GitLab has remediated

GitLab has remediated an issue in GitLab EE affecting all versions from 18

2026-05-29
CVE-2026-4867
7.5
Unknown Multiple Products

Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not...

2026-03-28
CVE-2026-4862
8.8
UTT Multiple Products

A security vulnerability has been detected in UTT HiPER 1250GW up to 3

2026-03-27
CVE-2026-48614
Analyzed
9.9
WebPros Plesk

An improper authorization vulnerability in the Plesk XML API allows authenticated users to inject configuration directives, leading to arbitrary file...

2026-07-07
CVE-2026-48612
Analyzed
8
Okta OAuth implementation

Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to...

2026-06-14
CVE-2026-48611
Analyzed
9.8
Unknown Unknown

Improper authentication checks in the OAuth implementation of the affected software allow for account hijacking, even when the feature is disabled.

2026-06-12
CVE-2026-48610
Analyzed
8.1
Ubiquiti UniFi OS

Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain...

2026-06-13
CVE-2026-4861
8.8
Unknown Multiple Products

A weakness has been identified in Wavlink WL-NU516U1 260227

2026-03-27
CVE-2026-48586
Analyzed
8.7
Apache Apache Thrift

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings

2026-07-28
CVE-2026-48584
Analyzed
9.9
Microsoft Azure Synapse

An execution with unnecessary privileges vulnerability in Azure Synapse allows authenticated attackers to escalate privileges over a network.

2026-06-20
CVE-2026-4858
Analyzed
8
Mattermost Multiple Products

Mattermost versions 11

2026-05-22
CVE-2026-4857
8.4
IdentityIQ Multiple Products

IdentityIQ 8

2026-04-16
CVE-2026-48567
Analyzed
10
Microsoft Azure HorizonDB

An authentication bypass vulnerability in Azure HorizonDB allows unauthorized attackers to spoof credentials and elevate privileges over a network.

2026-06-05
CVE-2026-48564
Analyzed
8.8
Microsoft Windows Server

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network

2026-07-15
CVE-2026-48561
Analyzed
9.6
Apple 365 Copilot for Android

Microsoft 365 Copilot for Android and iOS is susceptible to a command injection vulnerability that allows unauthorized attackers to execute code over...

2026-07-15
CVE-2026-48558
KEV Analyzed
10
SimpleHelp SimpleHelp

SimpleHelp contains an authentication bypass in the OIDC flow, allowing unauthenticated attackers to forge tokens and gain full technician access with...

2026-06-13
CVE-2026-48557
Analyzed
8.8
Unknown AddHandler configuration

Spatie Laravel Media Library before version 11

2026-05-30
CVE-2026-48528
Analyzed
9.8
NCEAS Metacat

Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in its REST API, allowing attackers to exfiltrate or modif...

2026-08-15
CVE-2026-48527
Analyzed
8.7
HP or NodeJs

HAX CMS helps manage microsite universe with PHP or NodeJs backends

2026-05-30
CVE-2026-48519
Analyzed
9.6
Langflow Langflow

Langflow contains a critical remote code execution (RCE) vulnerability in its "Shareable Playground" feature, allowing unauthenticated users to execut...

2026-06-24
CVE-2026-48508
Analyzed
8.8
Netflix lemur

Lemur manages TLS certificate creation

2026-08-19
CVE-2026-48506
Analyzed
7.5
MessagePack MessagePack-CSharp

MessagePack for C# is a MessagePack serializer for C#

2026-06-23
CVE-2026-48505
Analyzed
7.4
HP Filament

Filament is a collection of full-stack components for accelerated Laravel development

2026-06-23
CVE-2026-48502
Analyzed
8.2
MessagePack-CSharp MessagePack-CSharp

MessagePack for C# is a MessagePack serializer for C#

2026-06-23
CVE-2026-48491
Analyzed
7.8
Traefik Labs Traefik

Traefik is an HTTP reverse proxy and load balancer

2026-06-24
CVE-2026-48489
Analyzed
8.7
HP Symfony

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

2026-07-15
CVE-2026-48449
Analyzed
10
Adobe Campaign Classic

An incorrect authorization vulnerability in Adobe Campaign Classic allows unauthenticated attackers to achieve arbitrary code execution.

2026-07-30
CVE-2026-48448
Analyzed
8.6
Adobe Adobe Campaign Classic

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that...

2026-07-30
CVE-2026-48413
Analyzed
8.7
Adobe Adobe Commerce

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious...

2026-08-12
CVE-2026-4840
8.8
Netcore Multiple Products

A security flaw has been discovered in Netcore Power 15AX up to 3

2026-03-26
CVE-2026-48399
Analyzed
7.5
Adobe Adobe Campaign Classic

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass

2026-08-04
CVE-2026-48396
Analyzed
8.6
Adobe Adobe Bridge

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

2026-07-29
CVE-2026-48395
Analyzed
8.6
Adobe Adobe Bridge

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user

2026-07-29
CVE-2026-48391
Analyzed
8.2
Adobe Adobe Bridge

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user

2026-07-29
CVE-2026-48390
Analyzed
8.2
Adobe Adobe Bridge

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

2026-07-29
CVE-2026-48388
Analyzed
8.6
Adobe Photoshop Installer

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in th...

2026-07-30
CVE-2026-48373
Analyzed
7.8
Adobe Acrobat Reader

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current u...

2026-07-18
CVE-2026-48364
Analyzed
8.2
Adobe ColdFusion

ColdFusion versions 2025

2026-07-14
CVE-2026-48363
Analyzed
8.2
Adobe ColdFusion

ColdFusion versions 2025

2026-07-14
CVE-2026-48362
Analyzed
10
Adobe ColdFusion 2025

Adobe ColdFusion is susceptible to an OS command injection vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the u...

2026-08-12
CVE-2026-48359
Analyzed
9.6
Adobe Experience Manager

Adobe Experience Manager is vulnerable to XML External Entity injection, which allows authenticated, low-privileged attackers to read sensitive files...

2026-07-15
CVE-2026-48356
Analyzed
9.6
Adobe Adobe Commerce

Adobe Commerce is vulnerable to an unrestricted file upload flaw that can lead to arbitrary code execution if a user interacts with a malicious URL.

2026-07-15
CVE-2026-4834
Analyzed
7.5
WordPress is vulnerable

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1

2026-05-22