Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,445
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,161 - 3,180 of 33,519 CVEs
CVE-2026-44488 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios ...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2026-44487 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub

Rejected reason: After analysis, the originally reported behaviour was determined not to constitute a security vulnerability. The findings were parser-strictness defects without an exploitable framing-disagreement path in any tested deployment configuration.

Published: Jun 04, 2026
Source: NVD
CVE-2026-8037 CRITICAL - 9.6

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Published: Jun 04, 2026
Source: NVD

This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man...

Vendor: GX INDIA
Product: GX Earth 2022, GX Earth 1010
Published: Jun 04, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSBilling's rate limiter, which only applies to `/api/*` ro...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 04, 2026
Source: NVD

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and servic...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-10861 MEDIUM - 6.1

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without sufficiently enforcing that it was a local application path. An unauthenticated remote att...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10856 MEDIUM - 6.1

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation rejected URLs containing an explicit scheme, host, or user component, but did not reject paths beginn...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10855 MEDIUM - 4.3

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization that owned the existin...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10854 MEDIUM - 4.3

A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access restrictions, potentially exp...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10810 MEDIUM - 4.3

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the ...

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10809 MEDIUM - 6.3

A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be use...

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10808 MEDIUM - 6.3

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10807 MEDIUM - 6.3

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image can lead to unrestricted upload. The attack may be launched remotely. Th...

Vendor: mjperpinosa
Product: stumasy
Published: Jun 04, 2026
Source: NVD
CVE-2026-10806 MEDIUM - 6.3

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post results in unrestricted upload. The attack may be initiated remotely. The exploit has been...

Vendor: mjperpinosa
Product: stumasy
Published: Jun 04, 2026
Source: NVD

The HCL BigFix Cloud Lifecycle Management is affected by Lack Of Input Validation. It may leads to an information exposure vulnerability. This low-level flaw allows unauthorized access.

Vendor: HCL
Product: BigFix Cloud Lifecycle Management
Published: Jun 04, 2026
Source: NVD
CVE-2025-59874 HIGH - 8.1

HCL Hive Telco Observability is affected by Β a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.

Vendor: HCL
Product: Hive
Published: Jun 04, 2026
Source: NVD
CVE-2025-46638 HIGH - 7.5

Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).

Vendor: Dell
Product: BSAFE SSL-J
Published: Jun 04, 2026
Source: NVD
CVE-2019-25745 HIGH - 8.2

WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious &#...

Vendor: jgwhite33
Product: Google Review Slider
Published: Jun 04, 2026
Source: NVD