Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,647
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,241 - 2,260 of 34,996 CVEs
CVE-2026-50108 HIGH - 7.5

The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on t...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-50101 HIGH - 8.1

Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain p...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-50099 MEDIUM - 4.6

During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell that permits arbitrary...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is only enforced as Express...

Vendor: parse-community
Product: parse-server
Published: Jun 12, 2026
Source: NVD
CVE-2026-47236 MEDIUM - 4.3

Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members API. The Jetstream web team page authorizes access with only belongsToTeam() and then loads and serializ...

Vendor: solidtime-io
Product: solidtime
Published: Jun 12, 2026
Source: NVD
CVE-2026-42947 HIGH - 8.8

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account ca...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-42932 MEDIUM - 5.3

Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier high-water mark, the active fleet can be enumerated.

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-28742 CRITICAL - 9.8

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, se...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-12143 HIGH - 7.5

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-qu...

Vendor: form-data
Product: form-data
Published: Jun 12, 2026
Source: NVD
CVE-2026-12043 HIGH - 8.8

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEA...

Vendor: AWS
Product: aws-c-http
Published: Jun 12, 2026
Source: NVD

Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another user's post.

Vendor: Camaleon CMS
Product: Camaleon CMS
Published: Jun 12, 2026
Source: NVD

Tornado has out-of-bounds memory access via C extension

Vendor: pip
Product: tornado
Published: Jun 12, 2026
Source: GitHub
CVE-2026-48154 MEDIUM - 5.9

gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)

Vendor: go
Product: github.com/pilinux/gorest
Published: Jun 12, 2026
Source: GitHub
CVE-2025-58175 MEDIUM - 6.5

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` may allow attacker to perform unauthenticated Server-Side Request Forgery (SSRF). This vulnerability requires that GeoServe...

Vendor: maven
Product: org.geoserver.web:gs-web-app
Published: Jun 12, 2026
Source: GitHub
CVE-2025-52465 HIGH - 7.2

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web ...

Vendor: maven
Product: org.geoserver.web:gs-web-app
Published: Jun 12, 2026
Source: GitHub
CVE-2026-53406 HIGH - 7.8

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

Vendor: Zoom Communications
Product: Remote Control for Zoom Contact Center
Published: Jun 12, 2026
Source: NVD
CVE-2026-48558 CRITICAL - 10.0

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerab...

Vendor: SimpleHelp
Product: SimpleHelp
Published: Jun 12, 2026
Source: NVD
CVE-2026-48165 HIGH - 8.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global syste...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-48163 HIGH - 8.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not a...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-47965 HIGH - 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 12, 2026
Source: NVD