23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 4651-4700 of 23295 CVEs Page 94 of 466
CVE-2026-56032
Analyzed
9.8
HP Buddyboss Platform

A PHP Object Injection vulnerability exists in the Buddyboss Platform plugin that may allow unauthenticated or low-privileged attackers to execute arb...

2026-06-27
CVE-2026-56031
Analyzed
8.1
HP Automator

Unauthenticated PHP Object Injection in Uncanny Automator <= 7

2026-06-27
CVE-2026-56030
Analyzed
9.8
WordPress Paytium

A critical unauthenticated privilege escalation vulnerability in the Paytium plugin allows remote attackers to gain unauthorized administrative privil...

2026-06-27
CVE-2026-56029
Analyzed
7.5
CorvusPay WooCommerce Payment Gateway

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2

2026-06-28
CVE-2026-56028
Analyzed
9.8
WordPress Easy Elements for Elementor

A critical unauthenticated privilege escalation vulnerability exists in the Easy Elements for Elementor plugin, allowing attackers to elevate their ac...

2026-06-27
CVE-2026-56027
Analyzed
9.9
WordPress Booster for WooCommerce

Booster for WooCommerce contains an arbitrary file upload vulnerability allowing unauthenticated remote code execution.

2026-06-27
CVE-2026-56025
Analyzed
7.5
Paymob Paymob for WooCommerce

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4

2026-06-28
CVE-2026-56018
Analyzed
7.5
Unknown JavaScript::Minifier::XS

JavaScript::Minifier::XS versions before 0

2026-06-30
CVE-2026-56017
Analyzed
7.5
Unknown JavaScript::Minifier::XS

JavaScript::Minifier::XS versions before 0

2026-06-30
CVE-2026-56015
Analyzed
9.1
TPODER Net::IP::LPM

The Perl module Net::IP::LPM allows a heap out-of-bounds read due to improper validation of prefix lengths in the add() function.

2026-07-07
CVE-2026-56012
Analyzed
8.5
David Lingren Media Library Assistant

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Bli...

2026-06-20
CVE-2026-56010
Analyzed
8.8
WordPress Abandoned Cart Pro for WooCommerce

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10

2026-06-27
CVE-2026-56008
Analyzed
8.8
WordPress Fusion Builder

Contributor Privilege Escalation in Fusion Builder <= 3

2026-06-27
CVE-2026-56004
Analyzed
10
Unknown buildservice

A shellcode injection vulnerability in the obs tar_scm source service allows attackers to execute arbitrary code via a malicious _service file.

2026-07-03
CVE-2026-56003
Analyzed
8.5
X.Org libXfont2

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfo...

2026-07-09
CVE-2026-56002
Analyzed
8.5
Linux libXfont2

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2

2026-07-09
CVE-2026-56001
Analyzed
8.5
X.Org libXfont2

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2

2026-07-09
CVE-2026-56000
Analyzed
9
X.Org xorg-x11-server

A heap use-after-free vulnerability in X.Org xorg-x11-server and xwayland allows local attackers with a GLX connection to trigger memory corruption vi...

2026-07-08
CVE-2026-55999
Analyzed
8.5
Linux xorg-server

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21

2026-07-08
CVE-2026-55997
Analyzed
8.8
Rancher Rancher

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster

2026-08-05
CVE-2026-55995
Analyzed
8.7
F5 open-iscsi

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS

2026-07-30
CVE-2026-55994
Analyzed
7.5
Apache Apache Camel Iggy

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Came...

2026-07-07
CVE-2026-55978
Analyzed
8.4
HP CatchPulse

An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter com...

2026-08-06
CVE-2026-55971
Analyzed
9.3
Apache Apache Thrift

A heap-based buffer overflow vulnerability in Apache Thrift C++ bindings allows remote attackers to execute arbitrary code or cause a crash via specia...

2026-07-28
CVE-2026-55969
Analyzed
8.7
Apache Apache Thrift

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings

2026-07-28
CVE-2026-55968
Analyzed
8.7
Apache Apache Thrift

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node

2026-07-28
CVE-2026-55961
Analyzed
8.2
Unknown wolfSSL

wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer

2026-06-26
CVE-2026-55960
Analyzed
8.2
Unknown wolfSSL

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X

2026-06-26
CVE-2026-55958
Analyzed
8.3
Renesas TSIP (Trusted Secure IP)

Out-of-bounds write in the Renesas TSIP TLS 1

2026-06-26
CVE-2026-55953
Analyzed
9.1
Erlang OTP

Erlang/OTP TLS 1.2 and earlier clients fail to verify the server-selected cipher suite against the offered list, allowing on-path attackers to perform...

2026-07-28
CVE-2026-55952
Analyzed
8.2
Erlang OTP (Open Telecom Platform)

The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1

2026-07-03
CVE-2026-55950
Analyzed
8.7
Erlang OTP

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker...

2026-07-03
CVE-2026-55944
Analyzed
9.8
Microsoft Dynamics NAV 2018

An insecure deserialization vulnerability in Microsoft Dynamics NAV 2018 allows an unauthenticated attacker to execute arbitrary code remotely.

2026-07-15
CVE-2026-55884
Analyzed
9.2
Unknown tilt

Tilt versions 0.20.8 through 0.37.3 lack authentication on the HUD HTTP server, allowing unauthenticated remote attackers to invoke internal resources...

2026-07-11
CVE-2026-55883
Analyzed
8.3
Kubernetes Tilt

Tilt defines dev environments as code for microservice apps on Kubernetes

2026-07-11
CVE-2026-55882
Analyzed
8.3
Kubernetes Tilt

Tilt defines dev environments as code for microservice apps on Kubernetes

2026-07-11
CVE-2026-55879
Analyzed
9.3
OpenReplay OpenReplay

A stored Cross-Site Scripting (XSS) vulnerability in the OpenReplay tracking SDK allows unauthenticated attackers to execute malicious scripts in the...

2026-07-11
CVE-2026-55878
Analyzed
7.8
Symfony UX

Symfony UX is a JavaScript ecosystem for Symfony

2026-07-09
CVE-2026-55852
Analyzed
8.6
Frappe Frappe

Frappe is a full-stack web application framework

2026-07-11
CVE-2026-55849
Analyzed
8.5
CycloneDX cyclonedx-node-npm

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects

2026-07-09
CVE-2026-55848
Analyzed
8.6
Kubernetes mapfish-print

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Prin...

2026-08-29
CVE-2026-55844
Analyzed
7.5
Home Assistant Core

Home Assistant is open source home automation software that puts local control and privacy first

2026-06-30
CVE-2026-55841
Analyzed
7.5
Fortinet graylog2-server

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the F...

2026-08-30
CVE-2026-5584
Analyzed
7.3
Fosowl Multiple Products

A vulnerability has been found in Fosowl agenticSeek 0

2026-04-06
CVE-2026-55830
Analyzed
8.3
Unknown RestrictedPython

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment

2026-07-09
CVE-2026-55827
Analyzed
7.5
FreeRDP FreeRDP

FreeRDP is a free implementation of the Remote Desktop Protocol

2026-07-12
CVE-2026-55814
Analyzed
7.5
Apache Apache Ranger

Missing Authentication in Apache Ranger Download APIs on versions <= 2

2026-08-11
CVE-2026-55810
Analyzed
8.1
Drupal Plotly.js Graphing

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. Thi...

2026-07-15
CVE-2026-55809
Analyzed
9.8
HP Flag attendance field

An object injection vulnerability in the Drupal Flag attendance field module allows unauthorized modification of object attributes via improperly hand...

2026-07-12
CVE-2026-55794
Analyzed
8.7
Craft CMS Craft CMS

Craft CMS is a content management system (CMS)

2026-07-02