20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 4551-4600 of 20297 CVEs Page 92 of 406
CVE-2026-44101
Analyzed
9.8
Phoenix Contact CHARX SEC-3150

The CHARX OCPP Agent service on Phoenix Contact devices lacks authentication, allowing remote attackers to reconfigure backend connections and cause d...

2026-07-30
CVE-2026-44100
Analyzed
9.4
Phoenix Contact CHARX SEC-3150

The CHARX JupiCore service in various Phoenix Contact CHARX SEC controllers contains a missing authentication vulnerability, allowing unauthenticated...

2026-07-30
CVE-2026-44098
Analyzed
8.6
Phoenix Contact CHARX SEC-3000, 3050, 3100, 3150

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection...

2026-07-30
CVE-2026-44094
Analyzed
8.6
Phoenix Contact CHARX SEC-3150, SEC-3100, SEC-3050, SEC-3000

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default creden...

2026-07-30
CVE-2026-44090
Analyzed
9.8
Phoenix Contact CHARX SEC-3150

A missing authentication vulnerability in the Phoenix Contact CHARX SEC series allows unauthenticated remote attackers to access and potentially compr...

2026-07-30
CVE-2026-44089
Analyzed
9.4
TOTOLINK EX1200L

The Totolink EX1200L router contains a buffer overflow in the login functionality, allowing unauthenticated remote attackers to execute arbitrary code...

2026-06-24
CVE-2026-44068
Analyzed
7.6
Unknown Multiple Products

In Netatalk 2

2026-05-21
CVE-2026-44066
Analyzed
7.1
Infor Multiple Products

Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3

2026-05-22
CVE-2026-44064
Analyzed
7.1
Infor Multiple Products

An out-of-bounds read in ASP session ID handling in Netatalk 1

2026-05-22
CVE-2026-44062
Analyzed
7.5
Unknown Multiple Products

A missing output length bounds check in pull_charset_flags() in Netatalk 2

2026-05-22
CVE-2026-44060
Analyzed
7.5
Unknown Multiple Products

An integer underflow in dsi_writeinit() in Netatalk 1

2026-05-22
CVE-2026-44058
Analyzed
7.2
Netatalk Multiple Products

An authentication bypass vulnerability in Netatalk 2

2026-05-22
CVE-2026-44055
Analyzed
7.5
Unknown Multiple Products

A logic error involving bitwise OR operations in Netatalk 3

2026-05-22
CVE-2026-44053
Analyzed
7.4
LG Multiple Products

Netatalk 1

2026-05-22
CVE-2026-44052
Analyzed
7.5
Netatalk Multiple Products

Netatalk 2

2026-05-22
CVE-2026-44051
Analyzed
8.1
Unknown Multiple Products

In Netatalk 3

2026-05-21
CVE-2026-44050
Analyzed
9.9
Netatalk Netatalk

Netatalk contains a heap-based buffer overflow vulnerability within the `cnid` daemon's `comm_rcv()` function.

2026-05-21
CVE-2026-44049
Analyzed
7.5
Unknown Multiple Products

An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2

2026-05-22
CVE-2026-44048
Analyzed
8.8
Unknown Multiple Products

In Netatalk 2

2026-05-21
CVE-2026-44047
Analyzed
8.8
MySQL cnid backend

In Netatalk 3

2026-05-21
CVE-2026-4404
Analyzed
9.4
Harbor Harbor (GoHarbor)

GoHarbor Harbor version 2.15.0 and below uses hard-coded credentials, allowing unauthenticated attackers to gain administrative access to the web user...

2026-03-24
CVE-2026-44028
7.5
Nix Multiple Products

An issue was discovered in Nix before 2

2026-05-05
CVE-2026-44024
Analyzed
9.8
Fluent Fluentd

Fluentd allows path traversal via the ${tag} placeholder in file configurations, enabling attackers to write or overwrite arbitrary files and potentia...

2026-07-09
CVE-2026-44023
Analyzed
8.6
Unknown docling-core

Docling Core defines core data types and transformations for the document processing application Docling

2026-07-17
CVE-2026-44019
Analyzed
8.1
Unknown docling-core

Docling Core defines core data types and transformations for the document processing application Docling

2026-07-17
CVE-2026-44016
Analyzed
8.2
Docling-project Docling

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem

2026-06-25
CVE-2026-44015
Analyzed
8.5
Nginx UI is

Nginx UI is a web user interface for the Nginx web server

2026-05-13
CVE-2026-44009
Analyzed
9.8
Unknown vm2

The vm2 sandbox library for Node.js is vulnerable to sandbox escape, potentially allowing arbitrary command execution on the host system.

2026-05-14
CVE-2026-44008
Analyzed
9.8
Node.js (vm2) vm2

The vm2 sandbox for Node.js is vulnerable to an array species batch neutralization flaw, allowing attackers to escape the sandbox and execute arbitrar...

2026-05-14
CVE-2026-44006
Analyzed
10
Node.js (vm2) vm2

The vm2 sandbox for Node.js is vulnerable to prototype access, allowing attackers to reach arbitrary prototypes and escape the sandbox.

2026-05-14
CVE-2026-44005
Analyzed
10
Node.js (vm2) vm2

The vm2 sandbox for Node.js is vulnerable to prototype pollution, allowing sandboxed code to mutate host-realm objects and escape the environment.

2026-05-14
CVE-2026-44001
Analyzed
8.6
Unknown Multiple Products

vm2 is an open source vm/sandbox for Node

2026-05-14
CVE-2026-43999
Analyzed
9.9
Node.js (vm2) vm2

The vm2 sandbox for Node.js contains a bypass in its builtin allowlist, enabling unauthorized access to restricted modules and arbitrary code executio...

2026-05-14
CVE-2026-43998
Analyzed
8.5
Unknown Multiple Products

vm2 is an open source vm/sandbox for Node

2026-05-14
CVE-2026-43997
Analyzed
10
Node.js (vm2) vm2

The vm2 sandbox for Node.js is vulnerable to a host object escape, allowing attackers to access the host environment by leveraging native symbols.

2026-05-14
CVE-2026-43993
Analyzed
8.2
Unknown Multiple Products

JunoClaw is an agentic AI platform built on Juno Network

2026-05-13
CVE-2026-43992
Analyzed
9.8
Unknown Multiple Products

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_...

2026-05-13
CVE-2026-43991
Analyzed
8.4
Unknown Multiple Products

JunoClaw is an agentic AI platform built on Juno Network

2026-05-13
CVE-2026-43990
Analyzed
8.4
Unknown Multiple Products

JunoClaw is an agentic AI platform built on Juno Network

2026-05-13
CVE-2026-43989
Analyzed
8.5
Unknown Multiple Products

JunoClaw is an agentic AI platform built on Juno Network

2026-05-13
CVE-2026-43986
Analyzed
9.9
Tautulli Tautulli

A server-side request forgery (SSRF) vulnerability in Tautulli allows unauthenticated attackers to force the server to fetch arbitrary URLs.

2026-06-05
CVE-2026-43985
Analyzed
8.8
Tautulli Tautulli

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2026-06-05
CVE-2026-43984
Analyzed
8.9
Tautulli Tautulli

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2026-06-05
CVE-2026-43983
Analyzed
8.1
Pocket Multiple Products

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services

2026-05-14
CVE-2026-43978
Analyzed
8.1
Unknown wger

wger is a free, open-source workout and fitness manager

2026-07-17
CVE-2026-4396
8.3
Reporting Multiple Products

Improper certificate validation in Devolutions Hub Reporting Service 2025

2026-03-19
CVE-2026-43948
Analyzed
9.9
Unknown Multiple Products

wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a g...

2026-05-13
CVE-2026-43947
Analyzed
8.9
Unknown FUXA

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

2026-07-22
CVE-2026-43945
Analyzed
8.9
Unknown FUXA

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

2026-07-22
CVE-2026-43944
Analyzed
9.6
Unknown electerm

The electerm client is vulnerable to local code execution via maliciously crafted deep links or command-line options.

2026-05-09