Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,327
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 181 - 200 of 3,181 CVEs
CVE-2026-45447 CRITICAL - 9.8

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed m...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-44815 CRITICAL - 9.8

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-42904 CRITICAL - 9.6

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

Vendor: microsoft
Product: windows_10_21h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-38615 CRITICAL - 9.8

DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

Published: Jun 09, 2026
Source: NVD
CVE-2026-34182 CRITICAL - 9.1

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-eq...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-26142 CRITICAL - 9.8

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

Published: Jun 09, 2026
Source: NVD
CVE-2026-8025 CRITICAL - 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026.  NOTE: The vendor was contacted and it was learned that the produc...

Published: Jun 09, 2026
Source: NVD
CVE-2026-25089 CRITICAL - 9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through ...

Vendor: Fortinet
Product: FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS
Published: Jun 09, 2026
Source: NVD
CVE-2026-10523 CRITICAL - 9.9

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Vendor: ivanti
Product: Sentry
Published: Jun 09, 2026
Source: NVD
CVE-2026-10520 CRITICAL - 10.0

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Vendor: ivanti
Product: Sentry
Published: Jun 09, 2026
Source: NVD
CVE-2026-7486 CRITICAL - 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection. This issue affects E-İmar: from 2.10.1.0 before 3.0.2.

Published: Jun 09, 2026
Source: NVD
CVE-2026-46325 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles memory regions (MRs) with page sizes different from the system PAGE_SIZE. The core issue is that rxe_set_page() is c...

Vendor: Linux
Product: Linux
Published: Jun 09, 2026
Source: NVD
CVE-2026-46316 CRITICAL - 9.3

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each entry with vgic_p...

Vendor: Linux
Product: Linux
Published: Jun 09, 2026
Source: NVD
CVE-2017-20251 CRITICAL - 9.8

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with...

Vendor: Themeisle
Product: Woody Code Snippets
Published: Jun 09, 2026
Source: NVD
CVE-2025-10263 CRITICAL - 9.1

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher except...

Vendor: Arm
Product: C1-Ultra, C1-Premium, Neoverse V3, Neoverse V3AE, Neoverse V1, Neoverse N2, Neoverse N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1, Cortex-X1C, Cortex-A710, Cortex-A78, Cortex-A78AE, Cortex-A78C, Cortex-A77, Cortex-A76, Cortex-A76AE
Published: Jun 09, 2026
Source: NVD
CVE-2009-10007 CRITICAL - 9.1

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

Vendor: ETHER
Product: Catalyst::Plugin::Authentication
Published: Jun 09, 2026
Source: NVD
CVE-2026-9698 CRITICAL - 9.8

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buf...

Vendor: perl
Product: dbi
Published: Jun 09, 2026
Source: NVD
CVE-2026-44083 CRITICAL - 9.8

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later

Vendor: QNAP Systems Inc.
Product: QuMagie
Published: Jun 09, 2026
Source: NVD
CVE-2026-5067 CRITICAL - 9.8

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy that does not guarantee NUL termination when th...

Published: Jun 09, 2026
Source: NVD
CVE-2026-44748 CRITICAL - 9.9

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to se...

Vendor: SAP_SE
Product: SAP NetWeaver AS ABAP and ABAP Platform
Published: Jun 09, 2026
Source: NVD