Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,661
Quick preset (or use dates below)
Clear Filters
Showing 2,021 - 2,040 of 12,893 CVEs
CVE-2026-36603 HIGH - 8.1

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. UPnP is enabled by default through the admin interface, allowing any unauthenticated LAN device to create arbitrar...

Published: Jun 03, 2026
Source: NVD
CVE-2026-20230 HIGH - 8.6

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerab...

Vendor: Cisco
Product: Cisco Unified Communications Manager
Published: Jun 03, 2026
Source: NVD
CVE-2026-37462 HIGH - 7.3

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36574 HIGH - 7.8

A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.

Published: Jun 03, 2026
Source: NVD
CVE-2026-5241 HIGH - 8.0

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, i...

Vendor: huggingface
Product: transformers
Published: Jun 03, 2026
Source: NVD
CVE-2026-37460 HIGH - 7.5

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Published: Jun 03, 2026
Source: NVD
CVE-2022-49042 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Hyper Backup Explorer
Published: Jun 03, 2026
Source: NVD
CVE-2022-49036 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Active Backup for Business Recovery Media Creator
Published: Jun 03, 2026
Source: NVD
CVE-2026-35085 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35084 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35083 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35082 HIGH - 8.8

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35081 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35080 HIGH - 8.1

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35079 HIGH - 8.1

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35078 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35077 HIGH - 8.1

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35076 HIGH - 8.1

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-41032 HIGH - 7.5

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

Vendor: Phoenix Contact
Product: CHARX SEC-3150, CHARX SEC-3100, CHARX SEC-3050, CHARX SEC-3000
Published: Jun 03, 2026
Source: NVD
CVE-2025-15656 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.

Vendor: Mojoomla
Product: School Management
Published: Jun 03, 2026
Source: NVD