Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
Showing 301 - 320 of 1,466 CVEs

AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interfac...

Published: May 26, 2026
Source: NVD

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation throug...

Published: May 26, 2026
Source: NVD

Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flo...

Published: May 26, 2026
Source: NVD

Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocations. This happens because the database locking mechanism used in the controllers is totally broken a...

Vendor: composer
Product: pterodactyl/panel
Published: May 26, 2026
Source: GitHub
CVE-2026-9572 LOW - 3.3

A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of the argument cat leads to memory leak. The attack can only be performed from a local environment. The ...

Vendor: gpac
Product: gpac
Published: May 26, 2026
Source: NVD
CVE-2026-9567 LOW - 3.3

A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public...

Published: May 26, 2026
Source: NVD
CVE-2026-9564 LOW - 2.4

A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Performing a manipulation of the argument Remarks results in cross site scripting. Remote exploitation of...

Published: May 26, 2026
Source: NVD

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, but applies the requested bulk action to the submitted issue IDs without also requiring those issues to belong to that project. This vulnerability...

Vendor: bugsink
Product: bugsink
Published: May 26, 2026
Source: NVD

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up that event without also requiring it to belong to the issue in the URL. This is a project-boundary authorization issue: a logged-in...

Vendor: bugsink
Product: bugsink
Published: May 26, 2026
Source: NVD

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

Vendor: ZTE
Product: ZXUniPOS NDS-LTE
Published: May 26, 2026
Source: NVD
CVE-2026-9530 LOW - 3.3

A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgbmp Utility. Executing a manipulation can lead to out-of-bounds read. The attack requires local access. The exploit has been made ...

Published: May 26, 2026
Source: NVD
CVE-2026-9529 LOW - 3.3

A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been re...

Published: May 26, 2026
Source: NVD
CVE-2026-9504 LOW - 3.3

A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public ...

Published: May 25, 2026
Source: NVD
CVE-2026-9503 LOW - 3.3

A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been release...

Published: May 25, 2026
Source: NVD
CVE-2026-9501 LOW - 3.3

A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has b...

Published: May 25, 2026
Source: NVD

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD
CVE-2026-9485 LOW - 3.5

A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is ...

Published: May 25, 2026
Source: NVD

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD