Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,971
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,061 - 2,080 of 34,990 CVEs
CVE-2026-12223 MEDIUM - 5.5

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection. The attack needs ...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12222 HIGH - 8.0

A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer overflow. The attack needs t...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12221 HIGH - 8.0

A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The attack needs to be app...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12220 HIGH - 8.0

A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the argument uid leads to stack-based buffer overflow. The attack ca...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12219 MEDIUM - 6.3

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. T...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12218 HIGH - 8.0

A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local netw...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12217 HIGH - 7.8

A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclos...

Vendor: DVDFab
Product: Virtual Drive
Published: Jun 15, 2026
Source: NVD
CVE-2026-12216 MEDIUM - 5.3

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of the argument count_instr can lead to memory corruption. The attack requires local access. The exploit has been made available to th...

Vendor: svaarala
Product: duktape
Published: Jun 15, 2026
Source: NVD
CVE-2026-12214 HIGH - 7.8

A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a...

Vendor: Qihoo
Product: 360 Total Security
Published: Jun 15, 2026
Source: NVD
CVE-2026-12213 MEDIUM - 4.3

A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function getAccountInfo of the file server/account/src/operations.ts of the component User Information Handler. The manipulation results in improper authorization. The attack may be launched r...

Vendor: hcengineering
Product: Huly Platform
Published: Jun 15, 2026
Source: NVD
CVE-2026-12212 MEDIUM - 4.3

A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of the file server/account/src/operations.ts of the component RPC Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has ...

Vendor: hcengineering
Product: Huly Platform
Published: Jun 15, 2026
Source: NVD

A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been publi...

Vendor: Intelbras
Product: iNVU 7016 FT
Published: Jun 15, 2026
Source: NVD
CVE-2026-12210 MEDIUM - 6.3

A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an unknown function of the component utcp-gql/utcp-websocket. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be u...

Vendor: universal-tool-calling-protocol
Product: python-utcp
Published: Jun 15, 2026
Source: NVD
CVE-2026-12209 MEDIUM - 5.3

A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attributes. It is pos...

Vendor: RubyLouvre
Product: avalon
Published: Jun 15, 2026
Source: NVD
CVE-2026-12208 MEDIUM - 5.3

A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to ...

Vendor: jsonata-js
Product: jsonata
Published: Jun 15, 2026
Source: NVD
CVE-2026-12207 MEDIUM - 4.3

A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatientById of the file app\modules\medical\port\rest\controllers\PatientController.php of the component HTTP REST API. The manipulation of the argument ID resul...

Vendor: medkey-org
Product: medkey
Published: Jun 15, 2026
Source: NVD
CVE-2026-12206 MEDIUM - 6.3

A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/backend/app/models/grit/assays/data_table_entity.rb. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The ex...

Vendor: Grit42
Product: Grit
Published: Jun 15, 2026
Source: NVD
CVE-2026-12204 HIGH - 7.3

A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a manipulation can lead to authorization bypass. The...

Product: ShopXO
Published: Jun 15, 2026
Source: NVD
CVE-2026-12203 MEDIUM - 5.3

A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible....

Vendor: HKUDS
Product: AI-Trader
Published: Jun 15, 2026
Source: NVD

A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS class name leads to cross site scripting. The attack may be launched remotely. The exploit has been disc...

Vendor: Intelliants
Product: Subrion CMS
Published: Jun 15, 2026
Source: NVD