Total CVEs

136,968

Critical Severity

3,261

High Severity

12,143

Last 7 Days

1,836
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 33,373 CVEs
CVE-2026-42014 MEDIUM - 6.6

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 16, 2026
Source: NVD
CVE-2026-1767 MEDIUM - 5.6

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calcula...

Published: Jun 16, 2026
Source: NVD
CVE-2026-1766 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker co...

Published: Jun 16, 2026
Source: NVD
CVE-2026-1765 MEDIUM - 5.6

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Deni...

Published: Jun 16, 2026
Source: NVD
CVE-2026-1764 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attac...

Published: Jun 16, 2026
Source: NVD

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted altern...

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-9262 MEDIUM - 6.5

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Published: Jun 16, 2026
Source: NVD
CVE-2026-9261 MEDIUM - 6.8

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Published: Jun 16, 2026
Source: NVD
CVE-2026-9260 MEDIUM - 6.2

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Published: Jun 16, 2026
Source: NVD
CVE-2026-9259 MEDIUM - 6.5

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Published: Jun 16, 2026
Source: NVD
CVE-2026-9258 MEDIUM - 6.5

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Published: Jun 16, 2026
Source: NVD

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_bo...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code executi...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD
CVE-2026-48723 HIGH - 7.8

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a sh...

Vendor: browserstack
Product: browserstack-cypress-cli
Published: Jun 15, 2026
Source: NVD

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body. In 'Elixir.GRPC.Server.Transc...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same obj...

Vendor: TIMLEGGE
Product: Crypt::DSA
Published: Jun 15, 2026
Source: NVD

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial of service. HP is releasing software updates to mitigate these potential vulnerabilities.

Published: Jun 15, 2026
Source: NVD
CVE-2026-48714 CRITICAL - 9.1

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did n...

Vendor: i18next
Product: i18next-http-middleware
Published: Jun 15, 2026
Source: NVD