Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,386
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,621 - 2,640 of 33,646 CVEs
CVE-2026-11342 HIGH - 7.3

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and ma...

Vendor: code-projects
Product: Hotel and Tourism Reservation System
Published: Jun 05, 2026
Source: NVD
CVE-2026-11341 MEDIUM - 6.3

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.

Vendor: D-Link
Product: DWR-M920
Published: Jun 05, 2026
Source: NVD
CVE-2025-71318 CRITICAL - 9.8

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including L...

Vendor: Riello UPS
Product: NetMan 204
Published: Jun 05, 2026
Source: NVD
CVE-2025-71317 CRITICAL - 9.8

NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which du...

Vendor: Riello UPS
Product: NetMan 204
Published: Jun 05, 2026
Source: NVD
CVE-2026-47731 CRITICAL - 9.1

NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)

Vendor: pip
Product: ait-core
Published: Jun 05, 2026
Source: GitHub

A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid input.  Crafted inputs can trigger a processing error, causing the RTSP service to enter non-responsive state. Successful exploitation may cause the ...

Published: Jun 05, 2026
Source: NVD
CVE-2026-7473 MEDIUM - 5.8

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a ...

Vendor: arista
Product: eos
Published: Jun 05, 2026
Source: NVD
CVE-2026-48112 MEDIUM - 6.5

7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A 4-byte heap out-of-bounds read exists in the Unix ar archive parser in 7-Zip. When parsing a BSD-style __.SYMDEF symbol table, the ParseLibSy...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-48111 MEDIUM - 4.3

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the ParseDepedencyExpression function of the UEFI firmware image parser(CPP/7zip/Archive/UefiHandler.cpp). The function validates an attacker-controlled opcod...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-48104 MEDIUM - 4.2

7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused by a sparsely populated index array. In the SquashFS handler, _blockToNode is allocated with capacity for every metadata block but populated o...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-48103 MEDIUM - 4.3

7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) archive handler's security descriptor lookup. In CHandler::GetSecurity (CPP/7zip/Archive/Wim/WimHandler.cpp), the per-image SecurOffsets...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-11339 MEDIUM - 6.3

A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be...

Vendor: D-Link
Product: DWR-M920
Published: Jun 05, 2026
Source: NVD

A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. T...

Vendor: SourceCodester
Product: Ship Ferry Ticket Reservation System
Published: Jun 05, 2026
Source: NVD
CVE-2026-11337 MEDIUM - 4.3

A vulnerability was found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected by this vulnerability is an unknown functionality of the file /dashboard_page/forms/fetch.php. The manipulation of the argument department_na...

Vendor: tittuvarghese
Product: CollegeManagementSystem
Published: Jun 05, 2026
Source: NVD
CVE-2025-5090 MEDIUM - 6.5

CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a high privilege access ...

Published: Jun 05, 2026
Source: NVD
CVE-2025-5089 MEDIUM - 6.5

In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash o...

Published: Jun 05, 2026
Source: NVD
CVE-2025-5088 HIGH - 8.3

An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authenticat...

Published: Jun 05, 2026
Source: NVD
CVE-2026-52878 HIGH - 7.5

Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-52880 HIGH - 7.5

klever-go: REST API slow-header connection exhaustion via Gin Engine.Run

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-52879 HIGH - 7.5

klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub