Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,386
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 281 - 300 of 11,951 CVEs
CVE-2026-12197 HIGH - 7.2

A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of the component JSON-RPC Diagnose Endpoint. Performing a manipulation of the argument params.target results in command injection. It is possible to init...

Vendor: Ruijie
Product: EG105G-P
Published: Jun 15, 2026
Source: NVD
CVE-2026-12193 HIGH - 7.8

A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publ...

Vendor: VS Revo
Product: RevoUninstaller
Published: Jun 15, 2026
Source: NVD
CVE-2026-12192 HIGH - 8.8

A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This manipulation causes buffer overflow. The attack is only possible within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early...

Vendor: GALAYOU
Product: Y4
Published: Jun 15, 2026
Source: NVD
CVE-2026-12191 HIGH - 7.8

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted e...

Vendor: Comma AI
Product: Openpilot
Published: Jun 14, 2026
Source: NVD
CVE-2026-12187 HIGH - 8.8

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched re...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 14, 2026
Source: NVD
CVE-2026-12186 HIGH - 8.8

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit ...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 14, 2026
Source: NVD
CVE-2026-54413 HIGH - 8.2

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-by...

Vendor: driftregion
Product: iso14229
Published: Jun 14, 2026
Source: NVD
CVE-2026-54412 HIGH - 8.2

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - ...

Vendor: LiamBindle
Product: MQTT-C
Published: Jun 14, 2026
Source: NVD
CVE-2026-54410 HIGH - 8.6

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length fie...

Vendor: debevv
Product: nanoMODBUS
Published: Jun 14, 2026
Source: NVD
CVE-2026-11527 HIGH - 8.6

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe (&...

Vendor: SHLOMIF
Product: Config::IniFiles
Published: Jun 14, 2026
Source: NVD
CVE-2026-54420 HIGH - 8.5

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

Vendor: LiteSpeed Technologies
Product: cPanel Plugin
Published: Jun 14, 2026
Source: NVD
CVE-2026-12174 HIGH - 8.8

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been...

Vendor: D-Link
Product: DCS-935L
Published: Jun 13, 2026
Source: NVD
CVE-2026-6428 HIGH - 7.6

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data...

Published: Jun 13, 2026
Source: NVD
CVE-2026-5513 HIGH - 7.2

The Online Scheduling and Appointment Booking System โ€“ Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possib...

Published: Jun 13, 2026
Source: NVD
CVE-2026-9109 HIGH - 7.2

The GPTranslate โ€“ Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all versions up to, and including, 2.31 due to insufficient input sanitization and output escaping. This...

Published: Jun 13, 2026
Source: NVD
CVE-2026-9848 HIGH - 7.5

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks WordPress's `posts_request` filter with `wp_ticket_com_posts_request()`, which calls `emd_author_search_results()` when the c...

Published: Jun 13, 2026
Source: NVD
CVE-2026-54230 HIGH - 7.0

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writ...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-54229 HIGH - 7.0

A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. Th...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-54228 HIGH - 7.8

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing packa...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-6676 HIGH - 7.8

Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.27...

Published: Jun 12, 2026
Source: NVD