Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,916
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,981 - 2,000 of 12,363 CVEs
CVE-2026-42677 HIGH - 7.5

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

Vendor: Ben Balter
Product: WP Document Revisions
Published: Jun 01, 2026
Source: NVD
CVE-2026-42675 HIGH - 7.3

Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.

Vendor: Themefic
Product: Hydra Booking
Published: Jun 01, 2026
Source: NVD
CVE-2026-42674 HIGH - 7.5

Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.

Vendor: AAM Plugin
Product: Advanced Access Manager
Published: Jun 01, 2026
Source: NVD
CVE-2026-42673 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logt...

Vendor: Logtivity Activity Logs
Product: Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
Published: Jun 01, 2026
Source: NVD
CVE-2026-38950 HIGH - 7.8

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.

Published: Jun 01, 2026
Source: NVD
CVE-2026-37227 HIGH - 7.5

FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port ...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37225 HIGH - 7.5

FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition field. The E42 layer decoder accepts this as valid, but the E2AP encoder asserts a non-empty constraint when forwarding the request. A remote unauthenticated attacker can crash the i...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37224 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry enforces node ID uniqueness via assert() rather than graceful rejection. A remote unauthenticated attacker can crash the iApp process (port 36421) by sending two E2_SETUP_REQUESTs w...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37223 HIGH - 7.5

FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP messages against a 9-entry whitelist using assert(). A remote unauthenticated attacker can send any decodable E2AP PDU with a message type not in the whitelist to crash the iApp proce...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37222 HIGH - 7.5

FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can send a valid E2AP PDU containing an unexpected number of IEs (e.g., an E2setupRequest with extra optional fields) to crash the near-RT RIC (port 36421)...

Published: Jun 01, 2026
Source: NVD
CVE-2026-10273 HIGH - 7.3

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has ...

Product: php-censor
Published: Jun 01, 2026
Source: NVD
CVE-2026-10270 HIGH - 8.8

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public a...

Vendor: D-Link
Product: DI-7001 MINI
Published: Jun 01, 2026
Source: NVD
CVE-2026-10118 HIGH - 7.8

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subseq...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images
Published: Jun 01, 2026
Source: NVD
CVE-2022-4991 HIGH - 7.4

Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate...

Published: Jun 01, 2026
Source: NVD
CVE-2026-48865 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6.

Vendor: ThimPress
Product: LearnPress
Published: Jun 01, 2026
Source: NVD
CVE-2026-48839 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

Vendor: VeronaLabs
Product: WP Statistics
Published: Jun 01, 2026
Source: NVD
CVE-2026-42683 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-42681 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

Vendor: E2Pdf.com
Product: e2pdf
Published: Jun 01, 2026
Source: NVD
CVE-2026-37221 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pending event. The near-RT RIC uses assert() to enforce the existence of a pending event during response processing. A remote unauthenticated attacker can send a forged RIC_SUBSCRIPTION...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37220 HIGH - 7.5

FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can crash the near-RT RIC (port 364...

Published: Jun 01, 2026
Source: NVD