Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,725
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 201 - 220 of 35,133 CVEs
CVE-2026-56229 MEDIUM - 6.5

Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access build jobs belonging to different applications by supplying a mismatched app_id and job_id combination. Limited API keys restricted to a single app can ...

Vendor: Capgo
Product: Capgo
Published: Jun 21, 2026
Source: NVD
CVE-2025-71378 HIGH - 8.1

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD
CVE-2025-71357 HIGH - 8.1

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD

picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allowing remote code execution. Attackers can craft pickle files that import dangerous libraries like os and execute arbitrary system commands, which evade picklescan detection and exec...

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD
CVE-2025-71348 HIGH - 8.1

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply...

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD
CVE-2026-12799 MEDIUM - 4.3

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization....

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12798 MEDIUM - 6.3

A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of the argument spec_path ...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12797 MEDIUM - 6.3

A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_hooks/banned_keywords.py of the component Completions Interface. The manipulation of the argument prompt results in incorrect authorization. The attack ...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12796 MEDIUM - 6.3

A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation leads to session expiration. The attack is possible to be ca...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12795 HIGH - 7.3

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12789 MEDIUM - 4.7

A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learning Progress Tracking. Such manipulation of the argument troup_table_nav leads to...

Vendor: ILIAS
Product: Learning Management System
Published: Jun 21, 2026
Source: NVD
CVE-2026-12788 MEDIUM - 6.3

A vulnerability was determined in zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to ini...

Vendor: zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ
Product: ADP Application Developer Platform 应用开发者平台
Published: Jun 21, 2026
Source: NVD
CVE-2026-12787 MEDIUM - 6.3

A vulnerability was found in zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization. The attack may be performed from remote. The exploit has be...

Vendor: zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ
Product: ADP Application Developer Platform 应用开发者平台
Published: Jun 21, 2026
Source: NVD
CVE-2026-12786 HIGH - 7.8

A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library bootpt64.sys of the component Kernel Driver. The manipulation leads to improper access controls. Local access is required to approach this attack. The...

Vendor: Ezbsystems
Product: UltraISO Premium Edition
Published: Jun 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stays set after the call so that the global session lookup in ksmbd_session_lookup_all() can find ...

Vendor: Linux
Product: Linux
Published: Jun 21, 2026
Source: NVD
CVE-2026-12784 HIGH - 7.8

A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the publ...

Vendor: IM-Magic
Product: Partition Resizer
Published: Jun 21, 2026
Source: NVD
CVE-2026-12782 HIGH - 7.8

A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released...

Vendor: EaseUS
Product: Partition Master
Published: Jun 21, 2026
Source: NVD
CVE-2026-12781 HIGH - 7.8

A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly availabl...

Vendor: EaseUS
Product: Partition Master
Published: Jun 21, 2026
Source: NVD
CVE-2026-12780 HIGH - 7.8

A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed a...

Vendor: AOMEI
Product: Backupper
Published: Jun 21, 2026
Source: NVD
CVE-2026-12779 HIGH - 7.8

A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit h...

Vendor: AOMEI
Product: Dynamic Disk Manager
Published: Jun 21, 2026
Source: NVD