Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,751
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 201 - 220 of 35,119 CVEs

In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stays set after the call so that the global session lookup in ksmbd_session_lookup_all() can find ...

Vendor: Linux
Product: Linux
Published: Jun 21, 2026
Source: NVD
CVE-2026-12784 HIGH - 7.8

A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the publ...

Vendor: IM-Magic
Product: Partition Resizer
Published: Jun 21, 2026
Source: NVD
CVE-2026-12782 HIGH - 7.8

A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released...

Vendor: EaseUS
Product: Partition Master
Published: Jun 21, 2026
Source: NVD
CVE-2026-12781 HIGH - 7.8

A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly availabl...

Vendor: EaseUS
Product: Partition Master
Published: Jun 21, 2026
Source: NVD
CVE-2026-12780 HIGH - 7.8

A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed a...

Vendor: AOMEI
Product: Backupper
Published: Jun 21, 2026
Source: NVD
CVE-2026-12779 HIGH - 7.8

A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit h...

Vendor: AOMEI
Product: Dynamic Disk Manager
Published: Jun 21, 2026
Source: NVD
CVE-2026-12778 HIGH - 7.8

A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to ...

Vendor: AOMEI
Product: Partition Assistant
Published: Jun 21, 2026
Source: NVD
CVE-2026-12776 MEDIUM - 6.3

A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has bee...

Vendor: Montodel
Product: House-Rental-Management
Published: Jun 21, 2026
Source: NVD
CVE-2026-12775 HIGH - 7.3

A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The e...

Vendor: Montodel
Product: House-Rental-Management
Published: Jun 21, 2026
Source: NVD
CVE-2026-12774 MEDIUM - 6.3

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-si...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12773 HIGH - 7.3

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launche...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12772 MEDIUM - 6.3

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be initiated...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12771 MEDIUM - 5.0

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high complexity level is as...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12770 MEDIUM - 5.4

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remo...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

Vendor: GNU
Product: Savane
Published: Jun 20, 2026
Source: NVD
CVE-2026-56347 MEDIUM - 6.1

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped menu item fields that execute for all site visitor...

Vendor: WWBN
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56346 MEDIUM - 6.5

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can submit private keys, ciphertext, and passphrases to perform server-side decryption without credentials, ...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56345 HIGH - 8.1

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload ...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56342 MEDIUM - 6.8

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeURL() validation and accepts requests to private IP ranges and cloud metadata end...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56341 HIGH - 7.5

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreem...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD