Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,988
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,921 - 2,940 of 34,871 CVEs
CVE-2026-49843 MEDIUM - 5.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's JSON-RPC handler bound the connection to the client-supplied sessid on the ...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49842 HIGH - 7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop intercepts a #-prefixed speed-test protocol (#SPU / #S...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49841 CRITICAL - 9.8

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-w...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49840 CRITICAL - 9.1

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49475 HIGH - 7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49472 MEDIUM - 5.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in libs/xmlrpc-c/lib/expat/x...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49161 HIGH - 7.8

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: pc_manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-49160 HIGH - 7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48583 HIGH - 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48578 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48576 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48575 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48574 HIGH - 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48573 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48570 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48569 HIGH - 7.1

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: visual_studio_code
Published: Jun 09, 2026
Source: NVD
CVE-2026-48568 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48566 MEDIUM - 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_11_24h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-48565 HIGH - 7.8

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_narrator_braille
Published: Jun 09, 2026
Source: NVD
CVE-2026-48563 HIGH - 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_10_1809
Published: Jun 09, 2026
Source: NVD