21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4701-4750 of 21637 CVEs Page 95 of 433
CVE-2026-4723
Analyzed
9.8
Mozilla Firefox and Thunderbird

A use-after-free vulnerability in the JavaScript Engine of Mozilla Firefox and Thunderbird allows for critical remote code execution.

2026-03-25
CVE-2026-47220
Analyzed
7.5
Envoy Proxy Envoy

Envoy is an open source edge and service proxy designed for cloud-native applications

2026-06-28
CVE-2026-4722
8.8
Privilege Multiple Products

Privilege escalation in the IPC component

2026-03-25
CVE-2026-47211
Analyzed
8.4
Q00 ouroboros

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior

2026-08-04
CVE-2026-47210
Analyzed
9.8
Unknown vm2

The vm2 sandbox for Node.js is vulnerable to a sandbox escape that allows arbitrary code execution in the host process when using WebAssembly JSPI.

2026-06-13
CVE-2026-47209
Analyzed
8.6
Unknown vm2 (Node.js sandbox)

vm2 is an open source vm/sandbox for Node

2026-06-13
CVE-2026-47208
Analyzed
10
Docker vm2

A sandbox breakout vulnerability in vm2 allows unauthenticated attackers to execute arbitrary commands on the host system via promise manipulation.

2026-06-13
CVE-2026-47201
Analyzed
8.5
Unknown authentik

authentik is an open-source identity provider

2026-06-04
CVE-2026-47198
Analyzed
8.5
Paymenter Paymenter

Paymenter is a free and open-source webshop solution for management of hosting services

2026-07-21
CVE-2026-47194
Analyzed
8.6
Unknown frappe

Frappe is a full-stack web application framework

2026-08-07
CVE-2026-47193
Analyzed
7.5
OpenProject OpenProject

OpenProject is open-source, web-based project management software

2026-06-28
CVE-2026-4719
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Graphics: Text component

2026-03-26
CVE-2026-4718
8.1
Signal Multiple Products

Undefined behavior in the WebRTC: Signaling component

2026-03-26
CVE-2026-4717
Analyzed
9.8
Mozilla Firefox and Thunderbird

A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird. Successful exploitation could allow an att...

2026-03-25
CVE-2026-47162
Analyzed
8.8
Vim Vim

Vim is an open source, command line text editor

2026-06-13
CVE-2026-4716
Analyzed
9.1
Unknown Multiple Products

Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9,...

2026-03-25
CVE-2026-47158
Analyzed
8.3
Unknown vaultwarden

Vaultwarden is a Bitwarden-compatible server written in Rust

2026-07-17
CVE-2026-4715
Analyzed
9.1
Mozilla Firefox and Thunderbird

An uninitialized memory vulnerability in the Graphics: Canvas2D component affects Mozilla Firefox and Thunderbird, leading to potential memory corrupt...

2026-03-25
CVE-2026-47140
Analyzed
10
Linux vm2

An incomplete denylist of Node.js builtins in vm2 allows unauthenticated attackers to escape the sandbox and execute code in the host process.

2026-06-13
CVE-2026-4714
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Audio/Video component

2026-03-26
CVE-2026-47139
Analyzed
8.6
Unknown vm2 (Node.js sandbox)

vm2 is an open source vm/sandbox for Node

2026-06-13
CVE-2026-47137
Analyzed
10
Unknown vm2

An improper security check implementation in vm2 allows unauthenticated attackers to bypass sandbox restrictions and achieve remote code execution.

2026-06-13
CVE-2026-47135
Analyzed
8.7
Unknown vm2 (Node.js sandbox)

vm2 is an open source vm/sandbox for Node

2026-06-13
CVE-2026-47131
Analyzed
10
Unknown vm2

A sandbox escape vulnerability in vm2 allows unauthenticated attackers to execute arbitrary code on the host system via prototype mutation.

2026-06-13
CVE-2026-4713
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Graphics component

2026-03-26
CVE-2026-47129
Analyzed
8.1
Unknown nextcrm-app

NextCRM is open-source customer relationship management (CRM) software

2026-07-21
CVE-2026-47125
Analyzed
8.8
Docker containers

Arcane is an interface for managing Docker containers, images, networks, and volumes

2026-05-30
CVE-2026-4712
7.5
Infor Multiple Products

Information disclosure in the Widget: Cocoa component

2026-03-26
CVE-2026-47117
Analyzed
9.8
OpenMed Multiple Products

OpenMed contains a remote code execution vulnerability in its PII privacy-filter model loading path, allowing unauthenticated attackers to execute arb...

2026-06-03
CVE-2026-47114
Analyzed
8.8
IINA Multiple Products

IINA before 1

2026-05-22
CVE-2026-4711
Analyzed
9.8
Apple Firefox and Thunderbird

A use-after-free vulnerability in the Widget: Cocoa component of Mozilla products on macOS allows for remote code execution via malicious web interact...

2026-03-25
CVE-2026-47107
Analyzed
9.6
Windmill Windmill

Windmill contains a sandbox escape vulnerability due to incorrect default permissions in nsjail configurations, allowing authenticated users to modify...

2026-05-20
CVE-2026-47102
Analyzed
8.8
LiteLLM LiteLLM

LiteLLM prior to 1

2026-05-22
CVE-2026-47101
Analyzed
8.8
Unknown Multiple Products

LiteLLM prior to 1

2026-05-22
CVE-2026-47100
Analyzed
7.5
Unknown Multiple Products

Funnel Builder for WooCommerce Checkout prior to 3

2026-05-20
CVE-2026-47092
Analyzed
7.8
HUD Multiple Products

Claude HUD through 0

2026-05-19
CVE-2026-4709
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Audio/Video: GMP component

2026-03-26
CVE-2026-4708
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Graphics component

2026-03-26
CVE-2026-4707
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Graphics: Canvas2D component

2026-03-26
CVE-2026-47065
Analyzed
9.8
Unknown Multiple Products

Multiple deserialization vulnerabilities exist that allow filter bypass and the triggering of unintended static initializers in Java-based products.

2026-06-04
CVE-2026-4706
7.5
Unknown Multiple Products

Incorrect boundary conditions in the Graphics: Canvas2D component

2026-03-26
CVE-2026-47056
Analyzed
10
Oracle Data Integrator

A critical vulnerability in the Oracle Data Integrator Rest Service component allows an unauthenticated attacker to achieve full system takeover via n...

2026-07-22
CVE-2026-4705
Analyzed
9.8
Mozilla Firefox and Thunderbird

Undefined behavior in the WebRTC: Signaling component of Mozilla products creates a critical security risk for Firefox and Thunderbird users.

2026-03-25
CVE-2026-4704
7.5
Signal Multiple Products

Denial-of-service in the WebRTC: Signaling component

2026-03-26
CVE-2026-47037
Analyzed
8.8
Oracle Oracle Access Manager

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

2026-07-22
CVE-2026-47031
Analyzed
8.8
Oracle Oracle Bills of Material

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues)

2026-07-22
CVE-2026-4702
Analyzed
9.8
Mozilla Firefox and Thunderbird

A JIT miscompilation in the JavaScript Engine of Mozilla products allows unauthenticated attackers to achieve remote code execution via crafted web co...

2026-03-25
CVE-2026-4701
Analyzed
9.8
Mozilla Firefox and Thunderbird

A use-after-free vulnerability in the JavaScript Engine of Mozilla products allows unauthenticated remote code execution through memory corruption.

2026-03-25
CVE-2026-47004
Analyzed
8.8
Oracle Oracle Enterprise Manager Base Platform

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework)

2026-07-22
CVE-2026-4700
Analyzed
9.8
Mozilla Firefox and Thunderbird

A mitigation bypass vulnerability in the Networking: HTTP component affects several Mozilla products, including Firefox and Thunderbird.

2026-03-25