21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4551-4600 of 21637 CVEs Page 92 of 433
CVE-2026-48160
Analyzed
9.3
Unknown react-tracked

The react-tracked repository contained malicious commits that executed remote code on developer machines during npm install.

2026-08-11
CVE-2026-48159
Analyzed
9.3
Unknown use-reducer-async

The use-reducer-async repository contained malicious commits that executed remote code on developer machines during npm install.

2026-08-11
CVE-2026-48153
Analyzed
8.5
Unknown Multiple Products

Budibase is an open-source low-code platform

2026-05-29
CVE-2026-4815
8.8
HP Multiple Products

A SQL Injection vulnerability has been found in Support Board v3

2026-03-27
CVE-2026-48145
Analyzed
8.2
Apache Apache Thrift

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings

2026-07-28
CVE-2026-48144
Analyzed
9.1
Apache Apache Thrift

An improper certificate validation vulnerability in Apache Thrift c_glib bindings allows attackers to perform man-in-the-middle attacks by failing to...

2026-07-28
CVE-2026-48120
Analyzed
8.6
Unknown kakoune

Kakoune is a code editor

2026-08-08
CVE-2026-48114
Analyzed
9.8
DataONE (Metacat) Metacat

Metacat data repository software contains an unauthenticated SQL injection vulnerability allowing full database read/write/execute access.

2026-06-16
CVE-2026-48113
Analyzed
8.5
Unknown chisel

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH

2026-08-04
CVE-2026-48109
Analyzed
8.2
MessagePack-CSharp MessagePack-CSharp

MessagePack for C# is a MessagePack serializer for C#

2026-06-23
CVE-2026-48098
Analyzed
7.3
Unknown NexTOR_IP_CHANGER

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address

2026-08-09
CVE-2026-48097
Analyzed
7.8
Unknown NexTOR_IP_CHANGER

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address

2026-08-08
CVE-2026-48095
Analyzed
8.8
Unknown 7-Zip

7-Zip is a file archiver with a high compression ratio

2026-06-07
CVE-2026-4809
Analyzed
9.8
HP code while

Plank laravel-mediable through version 6.4.0 allows for arbitrary file upload and remote code execution by trusting client-supplied MIME types during...

2026-03-27
CVE-2026-48087
Analyzed
9.8
Unknown appointment-booking-software

An improper authentication vulnerability in the OpenReception registration handler allows unauthenticated attackers to hijack user passkeys and gain u...

2026-08-07
CVE-2026-48086
Analyzed
9.9
Unknown appointment-booking-software

An improper privilege management vulnerability exists where tenant administrators can escalate their own privileges to platform-wide global administra...

2026-08-07
CVE-2026-48085
Analyzed
9.8
Unknown appointment-booking-software

A missing authorization vulnerability in the OpenReception setup handler allows unauthenticated attackers to create new global administrator accounts...

2026-08-07
CVE-2026-48081
Analyzed
8.1
Unknown appointment-booking-software

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

2026-08-08
CVE-2026-48080
Analyzed
8
Unknown appointment-booking-software

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

2026-08-08
CVE-2026-48063
Analyzed
9.3
SAP Baileys

The Baileys WhatsApp API allows unauthenticated remote attackers to spoof messages and corrupt the application state by sending malicious payloads to...

2026-08-04
CVE-2026-48062
Analyzed
9.8
HP CodeIgniter4

A file upload validation bypass in CodeIgniter4 allows attackers to upload executable PHP files by manipulating MIME-derived extensions.

2026-07-18
CVE-2026-48060
Analyzed
8.1
Litestar Litestar

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework

2026-07-29
CVE-2026-48059
Analyzed
7.5
Netty Netty

Netty is a network application framework for development of protocol servers and clients

2026-06-15
CVE-2026-48056
Analyzed
10
Unknown streambert

Streambert versions prior to 2.5.0 contain an improper input validation flaw in the IPC handler, allowing a compromised renderer process to execute ar...

2026-08-12
CVE-2026-48055
Analyzed
10
Streambert Streambert

A Zip Slip vulnerability in the Streambert desktop application allows attackers to perform path traversal and write arbitrary files to the host filesy...

2026-06-18
CVE-2026-48054
Analyzed
8.8
OpenZeppelin contracts-wizard

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts

2026-08-07
CVE-2026-48048
Analyzed
7.5
XWiki xwiki-platform

XWiki Platform is a generic wiki platform

2026-08-11
CVE-2026-48044
Analyzed
7.5
Envoy Proxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications

2026-06-28
CVE-2026-48042
Analyzed
7.5
Envoy Proxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications

2026-06-28
CVE-2026-48036
Analyzed
8.4
Unknown hulumi

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi

2026-07-25
CVE-2026-48035
Analyzed
7.1
Unknown hulumi

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi

2026-07-26
CVE-2026-48034
Analyzed
8.5
Unknown hulumi

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi

2026-07-25
CVE-2026-48033
Analyzed
8.4
Unknown hulumi

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi

2026-07-25
CVE-2026-48032
Analyzed
8.3
Unknown hulumi

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi

2026-07-25
CVE-2026-48031
Analyzed
9.1
Unknown go-base

The go-base boilerplate template contains a hardcoded JWT signing secret, allowing unauthenticated attackers to forge authentication tokens and bypass...

2026-08-04
CVE-2026-48030
Analyzed
9.9
Unknown pheditor

Pheditor versions 2.0.1 through 2.0.3 are vulnerable to OS command injection via the terminal action handler, allowing authenticated users to achieve...

2026-07-28
CVE-2026-4803
Analyzed
7.2
WordPress is vulnerable

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_...

2026-05-05
CVE-2026-48027
KEV Analyzed
9.8
Nx Multiple Products

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed...

2026-05-28
CVE-2026-48026
Analyzed
8.7
Unknown lakeFS

lakeFS is an open-source tool that transforms object storage into a Git-like repositories

2026-08-08
CVE-2026-48020
Analyzed
7.8
Traefik Labs Traefik

Traefik is an HTTP reverse proxy and load balancer

2026-06-24
CVE-2026-4802
Analyzed
8
Unknown Multiple Products

A flaw was found in Cockpit

2026-05-12
CVE-2026-48017
Analyzed
8.8
DbGate DbGate

DbGate is cross-platform database manager

2026-06-16
CVE-2026-48007
Analyzed
8.6
Unknown element-call

Element Call is a native Matrix video conferencing application

2026-08-08
CVE-2026-48006
Analyzed
7.5
Netty Netty Framework

Netty is a network application framework for development of protocol servers and clients

2026-06-15
CVE-2026-4800
8.1
GitHub Multiple Products

Impact: The fix for CVE-2021-23337 (https://github

2026-04-01
CVE-2026-47994
Analyzed
8.7
Adobe Adobe Commerce

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious...

2026-07-15
CVE-2026-47965
Analyzed
7.8
Adobe Acrobat Reader

Acrobat Reader versions 24

2026-06-14
CVE-2026-47938
Analyzed
10
Adobe Campaign Classic

Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability that allows for unauthenticated privilege escalation.

2026-06-10
CVE-2026-47932
Analyzed
8.8
Adobe ColdFusion

ColdFusion versions 2023

2026-06-10
CVE-2026-47931
Analyzed
8.4
Adobe ColdFusion

ColdFusion versions 2023

2026-06-12