21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 4851-4900 of 21637 CVEs Page 98 of 433
CVE-2026-46716
Analyzed
9.9
Nezha Monitoring

Nezha Monitoring contains a vulnerability where a low-privileged user can trigger arbitrary commands across all monitored servers, resulting in cross-...

2026-06-13
CVE-2026-46713
Analyzed
9.2
Unknown misskey

Misskey fails to properly validate JSON-LD signatures, enabling attackers to spoof activities on the federated social media platform.

2026-08-04
CVE-2026-46710
Analyzed
7.5
Notepad++ Notepad++

Notepad++ is a free and open-source source code editor

2026-06-28
CVE-2026-4670
Analyzed
9.8
Progress Software MOVEit

An authentication bypass vulnerability in Progress Software MOVEit Automation allows unauthorized access to the application.

2026-05-01
CVE-2026-46695
Analyzed
10
Boxlite Boxlite

Boxlite prior to 0.9.0 fails to restrict kernel capabilities, allowing malicious code to remount directories as read-write and perform arbitrary write...

2026-06-11
CVE-2026-46687
Analyzed
7.7
Unknown emlog

Emlog is an open source website building system

2026-07-18
CVE-2026-46686
Analyzed
8.5
Unknown emlog

Emlog is an open source website building system

2026-07-17
CVE-2026-46670
Analyzed
9.8
YesWiki YesWiki

An unauthenticated SQL injection vulnerability in the YesWiki Bazar form-import path allows remote attackers to execute arbitrary SQL commands and ext...

2026-08-12
CVE-2026-46656
Analyzed
8.8
Bludit Bludit CMS

Bludit is a content management system

2026-06-09
CVE-2026-46640
Analyzed
8.7
HP Twig

Twig is a template language for PHP

2026-07-15
CVE-2026-46633
Analyzed
8.7
HP Twig

Twig is a template language for PHP

2026-07-15
CVE-2026-46624
Analyzed
9.9
Twenty Twenty CRM

Twenty CRM is vulnerable to RCE via chained SQL injection and PostgreSQL COPY TO PROGRAM attacks in the REST API.

2026-05-27
CVE-2026-46622
Analyzed
8.1
SolidInvoice SolidInvoice

SolidInvoice is an open-source invoicing platform

2026-06-13
CVE-2026-4662
7.5
WordPress is vulnerable

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3

2026-03-24
CVE-2026-46614
Analyzed
9.8
Kubernetes Fission Router

A route authorization bypass in the Fission router allows unauthorized callers to invoke functions by guessing their metadata, bypassing defined HTTPT...

2026-06-11
CVE-2026-46612
Analyzed
8.8
Kubernetes Fission

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes

2026-06-11
CVE-2026-4661
Analyzed
7.5
WordPress WP CTA – Call Now Button, Sticky Button & Call to Action Builder

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname'...

2026-07-11
CVE-2026-46607
Analyzed
7.8
Nicolargo Glances

Glances is an open-source system cross-platform monitoring tool

2026-06-27
CVE-2026-46606
Analyzed
7.8
Intel Glances

Glances is an open-source system cross-platform monitoring tool

2026-06-27
CVE-2026-46603
Analyzed
7.5
Golang golang.org/x/image/vp8l

VP8L decoding in golang

2026-08-16
CVE-2026-46600
7.5
Unknown golang.org/x/net/dns/dnsmessage

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

2026-08-04
CVE-2026-4660
Analyzed
7.5
HashiCorp Multiple Products

HashiCorp’s go-getter library up to v1

2026-04-10
CVE-2026-46593
Analyzed
8.6
HP PHP Poll Script

A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script

2026-08-01
CVE-2026-46592
Analyzed
7.5
Apache Apache Camel

Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component

2026-07-07
CVE-2026-46591
Analyzed
8.2
Apache Apache Camel

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component

2026-07-07
CVE-2026-46590
Analyzed
8.8
Apache Apache Camel

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component

2026-07-07
CVE-2026-4659
7.5
WordPress is vulnerable

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up...

2026-04-17
CVE-2026-46588
Analyzed
7.3
Apache Camel

Improper Input Validation vulnerability in Apache Camel

2026-07-07
CVE-2026-46587
Analyzed
7.3
Apache Camel

Improper Input Validation vulnerability in Apache Camel

2026-07-07
CVE-2026-46586
Analyzed
7.3
Apache OFBiz

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vuln...

2026-05-20
CVE-2026-46585
Analyzed
7.5
Apache Apache Camel Lucene

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component

2026-07-07
CVE-2026-46562
Analyzed
9.8
Yamcs Yamcs

A code injection vulnerability in the Yamcs mission control framework allows unauthenticated attackers to execute arbitrary OS commands via the Nashor...

2026-07-17
CVE-2026-46558
Analyzed
8.3
Intel Plane

Plane is an open-source project management tool

2026-06-12
CVE-2026-46519
Analyzed
8.8
Kubernetes mcp-server-kubernetes

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management

2026-06-12
CVE-2026-46515
Analyzed
9.3
Unknown frogman

A missing authorization vulnerability in mwtcmi frogman allows authenticated users with low-level permissions to access sensitive system secrets and e...

2026-07-17
CVE-2026-46512
Analyzed
9.9
Unknown Frogman

An input validation flaw in the Frogman PBX control software allows authenticated users with writing privileges to inject arbitrary Asterisk directive...

2026-07-17
CVE-2026-46491
Analyzed
8.6
HP casserver

SimpleSAMLphp-casserver is a CAS 1

2026-06-11
CVE-2026-46490
Analyzed
8.8
Samlify Samlify

samlify is a Node

2026-06-10
CVE-2026-46489
Analyzed
8.1
SolidInvoice SolidInvoice

SolidInvoice is an open-source invoicing platform

2026-06-13
CVE-2026-46485
Analyzed
8.2
Lissy93 Dashy

Dashy is a self-hostable personal dashboard

2026-07-17
CVE-2026-46484
Analyzed
8.1
Headplane Headplane Web UI

Headplane is a feature-complete Web UI for Headscale

2026-06-09
CVE-2026-46481
Analyzed
8.3
Intel OpenMetadata Platform

OpenMetadata is a unified metadata platform

2026-06-09
CVE-2026-46480
Analyzed
8.8
FlowiseAI Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-10
CVE-2026-46479
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46478
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46477
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46476
Analyzed
8.8
Intel Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-16
CVE-2026-46475
Analyzed
8.8
Flowise Flowise

Flowise is a drag & drop user interface to build a customized large language model flow

2026-06-13
CVE-2026-46473
Analyzed
7.5
Unknown Multiple Products

Authen::TOTP versions before 0

2026-05-22
CVE-2026-46457
Analyzed
7.5
Apache Apache Camel

Improper Input Validation vulnerability in Apache Camel NATS component

2026-07-07