Total CVEs

150,152

Critical Severity

4,935

High Severity

17,450

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,161 - 1,180 of 46,557 CVEs
CVE-2026-66339 MEDIUM - 6.5

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, lead...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 24, 2026
Source: NVD
CVE-2026-66338 MEDIUM - 5.4

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend prox...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 24, 2026
Source: NVD
CVE-2026-66337 MEDIUM - 6.5

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client appl...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 24, 2026
Source: NVD
CVE-2026-61892 HIGH - 8.8

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-61886 MEDIUM - 6.5

Weintek cMT3092X HMI stores user account passwords in plaintext.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-60135 MEDIUM - 6.5

An attacker can modify data that should be restricted to read‑only access.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-60134 HIGH - 8.8

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

Vendor: Weintek
Product: cMT3092X firmware, EasyWeb
Published: Jul 24, 2026
Source: NVD
CVE-2026-16280 CRITICAL - 9.8

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memor...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jul 24, 2026
Source: NVD
CVE-2026-61884 CRITICAL - 9.8

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid admi...

Vendor: Tycon Systems
Product: TPDIN-Monitor-WEB2
Published: Jul 24, 2026
Source: NVD
CVE-2026-55985 MEDIUM - 4.3

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to...

Vendor: Tycon Systems
Product: TPDIN-Monitor-WEB2
Published: Jul 24, 2026
Source: NVD
CVE-2025-71408 HIGH - 7.8

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line...

Vendor: ntlk
Product: ntlk
Published: Jul 24, 2026
Source: NVD
CVE-2026-62323 MEDIUM - 6.3

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62379 CRITICAL - 9.8

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62280 MEDIUM - 6.1

OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jul 24, 2026
Source: GitHub

OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass

Vendor: maven
Product: org.openidentityplatform.openam:openam-auth-webauthn
Published: Jul 24, 2026
Source: GitHub
CVE-2026-57497 MEDIUM - 5.3

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

Vendor: go
Product: github.com/quic-go/webtransport-go
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55502 HIGH - 7.1

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55499 MEDIUM - 4.3

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55497 MEDIUM - 6.5

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55496 MEDIUM - 4.3

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub