Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

947
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 301 - 320 of 35,348 CVEs

Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".

Vendor: presire
Product: qSnapper
Published: Jun 22, 2026
Source: NVD

Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.

Vendor: presire
Product: qSnapper
Published: Jun 22, 2026
Source: NVD
CVE-2026-41046 HIGH - 7.3

A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.

Vendor: presire
Product: qSnapper
Published: Jun 22, 2026
Source: NVD
CVE-2026-41045 HIGH - 8.1

A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.

Vendor: presire
Product: qSnapper
Published: Jun 22, 2026
Source: NVD
CVE-2026-12725 MEDIUM - 5.9

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such ...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4
Published: Jun 22, 2026
Source: NVD
CVE-2026-12628 HIGH - 8.1

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a ...

Vendor: IBM
Product: Storage Protect Client, Storage Protect Snapshot For Windows
Published: Jun 22, 2026
Source: NVD
CVE-2026-12549 MEDIUM - 4.8

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to m...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 22, 2026
Source: NVD
CVE-2026-12479 MEDIUM - 6.1

A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This vulnerability arises from the improper handling of user-provided layer names, which are used to construct directory paths ...

Vendor: keras-team
Product: keras-team/keras
Published: Jun 22, 2026
Source: NVD

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name.

Vendor: Akaunting
Product: Akaunting
Published: Jun 22, 2026
Source: NVD

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation flow. A user with permission to create or modify records, such as Items, can store HTML/JavaScript in the record name.

Vendor: Akaunting
Product: Akaunting
Published: Jun 22, 2026
Source: NVD
CVE-2026-11372 MEDIUM - 5.4

IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session...

Vendor: IBM
Product: TRIRIGA Application Platform
Published: Jun 22, 2026
Source: NVD
CVE-2026-10845 HIGH - 7.3

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.

Vendor: IBM
Product: WebSphere Application Server
Published: Jun 22, 2026
Source: NVD
CVE-2024-51454 MEDIUM - 6.5

IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attac...

Vendor: IBM
Product: Engineering Workflow Management
Published: Jun 22, 2026
Source: NVD
CVE-2023-33854 MEDIUM - 5.3

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.

Vendor: IBM
Product: Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
Published: Jun 22, 2026
Source: NVD
CVE-2026-9162 MEDIUM - 4.3

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which allows a user with an existing WebSocket connection to remain authenticate...

Vendor: mattermost
Product: mattermost_server
Published: Jun 22, 2026
Source: NVD
CVE-2026-9029 HIGH - 7.3

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via e...

Published: Jun 22, 2026
Source: NVD
CVE-2026-8074 LOW - 3.8

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active...

Vendor: mattermost
Product: mattermost_server
Published: Jun 22, 2026
Source: NVD

The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process, allowing unverified or fake email addresses to be accepted. This lack of validation enables the creation of user accounts with fake email addresses, facilitating the mas...

Published: Jun 22, 2026
Source: NVD

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ fields. This vulnerability is also present in the local database, as it contains accessible sensitive information such as data on mi...

Published: Jun 22, 2026
Source: NVD

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ information without requiring prior authorization validation. This could enable an authenticated attacker to alter any use...

Published: Jun 22, 2026
Source: NVD