Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,979
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,081 - 2,100 of 34,990 CVEs
CVE-2026-12201 MEDIUM - 5.3

A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit has been published and may be used. The vendor was contacted...

Vendor: IObit
Product: Malware Fighter
Published: Jun 15, 2026
Source: NVD
CVE-2026-12200 HIGH - 7.3

A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the library libeay32.dll.html of the component Header Handler. The manipulation of the argument Authorization leads to stack-based buffer overflow. The attack can be initiate...

Vendor: Ritlabs
Product: TinyWeb Server
Published: Jun 15, 2026
Source: NVD
CVE-2026-12198 HIGH - 7.3

A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to launch the attack rem...

Product: Microweber
Published: Jun 15, 2026
Source: NVD
CVE-2026-12197 HIGH - 7.2

A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of the component JSON-RPC Diagnose Endpoint. Performing a manipulation of the argument params.target results in command injection. It is possible to init...

Vendor: Ruijie
Product: EG105G-P
Published: Jun 15, 2026
Source: NVD
CVE-2026-12193 HIGH - 7.8

A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publ...

Vendor: VS Revo
Product: RevoUninstaller
Published: Jun 15, 2026
Source: NVD
CVE-2026-12192 HIGH - 8.8

A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This manipulation causes buffer overflow. The attack is only possible within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early...

Vendor: GALAYOU
Product: Y4
Published: Jun 15, 2026
Source: NVD
CVE-2026-12191 HIGH - 7.8

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted e...

Vendor: Comma AI
Product: Openpilot
Published: Jun 14, 2026
Source: NVD
CVE-2026-12190 MEDIUM - 5.3

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. T...

Vendor: Genspark
Product: AI Workspace App
Published: Jun 14, 2026
Source: NVD
CVE-2026-12189 MEDIUM - 5.3

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper authorization in handler for custom url scheme. The attack can only be executed locally. The exploit has been publi...

Vendor: Moovit
Product: Bus & Public Transit App
Published: Jun 14, 2026
Source: NVD
CVE-2026-12188 MEDIUM - 6.3

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/controllers/concerns/grit/core/grit_entity_controller.rb of the component GritEntityController. Performing a manipulation results in sql injection. The ...

Vendor: Grit42
Product: Grit
Published: Jun 14, 2026
Source: NVD
CVE-2026-12187 HIGH - 8.8

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched re...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 14, 2026
Source: NVD
CVE-2026-12186 HIGH - 8.8

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit ...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 14, 2026
Source: NVD
CVE-2026-54413 HIGH - 8.2

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-by...

Vendor: driftregion
Product: iso14229
Published: Jun 14, 2026
Source: NVD
CVE-2026-54412 HIGH - 8.2

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - ...

Vendor: LiamBindle
Product: MQTT-C
Published: Jun 14, 2026
Source: NVD
CVE-2026-54411 MEDIUM - 5.9

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to reco...

Vendor: Linux-PAM
Product: Linux-PAM
Published: Jun 14, 2026
Source: NVD
CVE-2026-54410 HIGH - 8.6

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length fie...

Vendor: debevv
Product: nanoMODBUS
Published: Jun 14, 2026
Source: NVD
CVE-2026-11527 HIGH - 8.6

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe (&...

Vendor: SHLOMIF
Product: Config::IniFiles
Published: Jun 14, 2026
Source: NVD
CVE-2026-11526 CRITICAL - 9.8

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "c...

Vendor: RURBAN
Product: GD
Published: Jun 14, 2026
Source: NVD

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operatio...

Vendor: Unknown
Product: Iptanus File Upload
Published: Jun 14, 2026
Source: NVD
CVE-2026-54421 MEDIUM - 6.8

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.

Vendor: OpenStack
Product: Ironic
Published: Jun 14, 2026
Source: NVD