Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,976
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,201 - 3,220 of 34,447 CVEs
CVE-2026-49234 HIGH - 7.5

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD
CVE-2026-49233 HIGH - 7.5

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD

Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be triggered maliciously by an attacker by opening a large number of connections to the HTTP or RTR server. This only affects...

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD

Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicited 101 Switching Protocols response. In gun_http:handle_inform/8, when a 101 Switching Protocols response is received ove...

Vendor: ninenines
Product: gun
Published: Jun 08, 2026
Source: NVD

Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded HTTP/1.1 response buffering. In gun_http:handle/5, three clauses accumulate incoming TCP data into the connection's buffer field using binary conc...

Vendor: ninenines
Product: gun
Published: Jun 08, 2026
Source: NVD

Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unvalidated HTTP/2 PUSH_PROMISE authority. In gun_http2:push_promise_frame/7, the :authority pseudo-header from an incoming PUSH_PROMISE frame is stored verbatim into the promised stre...

Vendor: ninenines
Product: gun
Published: Jun 08, 2026
Source: NVD
CVE-2026-36789 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 08, 2026
Source: NVD
CVE-2026-25558 MEDIUM - 4.8

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through ...

Vendor: QloApps
Product: QloApps
Published: Jun 08, 2026
Source: NVD
CVE-2026-11521 MEDIUM - 6.3

A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the component Transaction En...

Vendor: Mohammed-eid35
Product: bank-management-system-springboot
Published: Jun 08, 2026
Source: NVD

A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and cou...

Vendor: SourceCodester
Product: Inventory System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11519 MEDIUM - 6.3

A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the component Account Creation Handler. The manipulation of the argument ROLE results in improper authorizati...

Vendor: SourceCodester
Product: Inventory System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11518 MEDIUM - 4.3

A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument fullname/username leads to cross site scripting. The attack is possible to be carried out remotely. Th...

Vendor: SourceCodester
Product: Inventory System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11517 HIGH - 8.8

A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of the argument GroupName can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly dis...

Vendor: UTT
Product: HiPER 2610G
Published: Jun 08, 2026
Source: NVD
CVE-2026-11516 MEDIUM - 5.5

A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBinds results in buffer overflow. The exploit has been made public and could be used.

Vendor: UTT
Product: HiPER 2610G
Published: Jun 08, 2026
Source: NVD
CVE-2026-9549 MEDIUM - 4.8

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom checks to inject malicious HTML or JavaScript into check output that executes in the browser ...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-8833 MEDIUM - 5.4

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validation and inject malicious URLs such as javascript: URIs, resulting in cross-site scripting whe...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-8078 MEDIUM - 4.8

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-7765 MEDIUM - 5.3

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's pers...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-7186 MEDIUM - 5.4

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when ...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-11577 HIGH - 7.2

A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm administrator by importi...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7
Published: Jun 08, 2026
Source: NVD