23391 Total CVEs
23296 AI Analyzed
328 CISA KEV
5310 Critical
All Vendors
Showing 4501-4550 of 23391 CVEs Page 91 of 468
CVE-2026-5708
Analyzed
8.8
Unknown and Engineering

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026

2026-04-07
CVE-2026-57077
Analyzed
7.7
TODDR YAML::Syck

YAML::Syck versions before 1

2026-07-18
CVE-2026-57076
Analyzed
7.8
TODDR YAML::Syck

YAML::Syck versions before 1

2026-07-18
CVE-2026-57075
Analyzed
9.1
TODDR YAML::Syck

An out-of-bounds read vulnerability in the YAML::Syck Perl module allows attackers to access adjacent memory regions through crafted binary YAML nodes...

2026-07-21
CVE-2026-57074
Analyzed
9.1
GitHub XML::Bare

XML::Bare versions through 0.53 for Perl are susceptible to an out-of-bounds read vulnerability when processing malformed or truncated XML strings.

2026-07-21
CVE-2026-57073
Analyzed
9.1
CODECHILD HTML::Bare

HTML::Bare versions through 0.04 for Perl contain an out-of-bounds read vulnerability in the parserc_parse function due to improper handling of charac...

2026-07-21
CVE-2026-5707
Analyzed
8.8
Unknown and Engineering

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025

2026-04-07
CVE-2026-5706
Analyzed
8.9
GitHub BT Mesh SDK

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote cod...

2026-08-28
CVE-2026-56876
Analyzed
8.1
Unknown extract-zip

extract-zip does not validate symlink targets when extracting zip archives

2026-06-27
CVE-2026-5687
Analyzed
8.8
Tenda CX12L

A weakness has been identified in Tenda CX12L 16

2026-04-07
CVE-2026-5686
Analyzed
8.8
Tenda CX12L

A security flaw has been discovered in Tenda CX12L 16

2026-04-07
CVE-2026-56854
Analyzed
7.5
SAP golang.org/x/crypto/ssh

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedP...

2026-08-30
CVE-2026-56852
Analyzed
7.5
Unknown golang.org/x/text/unicode/norm

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

2026-08-04
CVE-2026-5685
Analyzed
8.8
Tenda CX12L

A vulnerability was identified in Tenda CX12L 16

2026-04-07
CVE-2026-56846
Analyzed
7.5
Node.js Node

A flaw in Node

2026-08-04
CVE-2026-56845
Analyzed
7.5
Rocket.Chat Rocket.Chat

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem

2026-08-04
CVE-2026-56843
Analyzed
9.9
Webpros Plesk

WebPros Plesk contains an authorization flaw in the XML-RPC API that allows authenticated customers to access cross-tenant data and plaintext FTP cred...

2026-07-08
CVE-2026-56841
Analyzed
8.8
Ubiquiti UniFi Protect Application

A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Appl...

2026-07-03
CVE-2026-5684
Analyzed
8
Tenda CX12L

A vulnerability was determined in Tenda CX12L 16

2026-04-07
CVE-2026-56811
Analyzed
8.7
PhoenixFramework Phoenix

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix

2026-07-08
CVE-2026-56810
Analyzed
8.7
Elixir-Mint Mint

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint

2026-07-07
CVE-2026-56808
Analyzed
8.6
AVTECH DGM3103SCT

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with...

2026-06-30
CVE-2026-56793
Analyzed
7.7
Dell OpenManage Server Administrator

Dell OpenManage Server Administrator, versions prior to 11

2026-08-09
CVE-2026-56786
Analyzed
9.8
Unknown RTKLIB

RTKLIB contains an out-of-bounds write vulnerability in the decode_type1033 function, allowing potential arbitrary code execution via crafted RTCM3 st...

2026-06-26
CVE-2026-56785
Analyzed
8.2
FlatPress FlatPress

FlatPress versions prior to commit 10be83c, contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and ema...

2026-06-24
CVE-2026-56784
Analyzed
8.1
OpenRemote OpenRemote

OpenRemote before 1

2026-06-24
CVE-2026-56782
Analyzed
9.8
Unknown gorse

Gorse versions before 0.5.10 contain an authentication bypass in the /api/dump and /api/restore endpoints, allowing unauthenticated attackers to exfil...

2026-06-30
CVE-2026-56780
Analyzed
7.5
Modoboa Modoboa

Modoboa before 2

2026-06-30
CVE-2026-56773
Analyzed
8.8
Teable Teable

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks

2026-06-27
CVE-2026-56771
Analyzed
8.5
NewsBlur NewsBlur

NewsBlur before version 14

2026-06-26
CVE-2026-56769
Analyzed
8.5
Huly Huly Platform

Huly Platform through 0

2026-06-26
CVE-2026-56768
Analyzed
8.8
Seahub Seahub

Seahub before 13

2026-06-26
CVE-2026-56767
Analyzed
8.8
Maxun maxun

Maxun before 0

2026-06-26
CVE-2026-56766
Analyzed
8.8
Hydra thc-hydra

Hydra through 9

2026-06-26
CVE-2026-56765
Analyzed
9.8
Vikunja Vikunja

Vikunja is affected by an authorization bypass vulnerability that allows unauthenticated users to access, download, and delete sensitive project attac...

2026-07-11
CVE-2026-56748
Analyzed
8.8
Cribl Stream

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4

2026-07-28
CVE-2026-56747
Analyzed
8.8
Cribl Cribl Stream

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4

2026-07-28
CVE-2026-56741
Analyzed
7.5
Unknown jline3

JLine is a Java library for handling console input

2026-07-18
CVE-2026-56740
Analyzed
7.5
Unknown jline3

JLine is a Java library for handling console input

2026-07-18
CVE-2026-5674
Analyzed
8.8
Red Hat PipeWire

A flaw was found in PipeWire, a multimedia server

2026-07-17
CVE-2026-56721
Analyzed
8.8
GitHub CamaleonCMS

CamaleonCMS version 2

2026-08-12
CVE-2026-56718
Analyzed
7.5
AJCloud AJY IPC Firmware

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticat...

2026-08-31
CVE-2026-56710
Analyzed
9.8
Unknown grav

The Grav Login plugin before 1.0.16 fails to validate privilege levels in the API, allowing attackers to remove brute-force protection from high-privi...

2026-08-25
CVE-2026-56709
Analyzed
7.5
Grav Grav

Grav before 3

2026-08-25
CVE-2026-56707
Analyzed
7.7
Grav Grav Flex Objects plugin

Grav Flex Objects plugin versions 1

2026-08-25
CVE-2026-56705
Analyzed
9.8
HP Adminer

Adminer before 5.4.3 is vulnerable to DSN injection, allowing unauthenticated attackers to write arbitrary PHP code to the web root and achieve remote...

2026-08-25
CVE-2026-56702
Analyzed
8.8
Vrana Adminer

Adminer versions before 5

2026-08-25
CVE-2026-56700
Analyzed
9.8
HP Grav CMS

Grav CMS is vulnerable to remote code execution via insecure PHP object deserialization, OS command injection, and server-side template injection.

2026-07-01
CVE-2026-56699
Analyzed
10
GitHub wazuh

Wazuh Manager fails to sanitize input in the DataValue.index field, allowing unauthenticated agents to perform NDJSON injection attacks against the ma...

2026-07-16
CVE-2026-56690
Analyzed
8.5
Dell PowerFlex Manager

Dell PowerFlex Manager, Version prior to 5

2026-07-11