Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,398
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,221 - 3,240 of 33,519 CVEs
CVE-2026-50214 CRITICAL - 9.8

TheĀ /v1/PlanĀ service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.

Published: Jun 04, 2026
Source: NVD
CVE-2026-49771 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.

Vendor: 10Web
Product: Photo Gallery by 10Web
Published: Jun 04, 2026
Source: NVD
CVE-2026-49510 MEDIUM - 6.1

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie:Ā beforeĀ 21292665023e5074b38254432716866d00f1985f.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47320 MEDIUM - 6.1

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47319 MEDIUM - 6.1

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47318 MEDIUM - 6.1

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47306 MEDIUM - 6.1

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD

A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high c...

Vendor: PaddlePaddle
Product: FastDeploy
Published: Jun 04, 2026
Source: NVD
CVE-2026-10305 MEDIUM - 6.1

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-50213 HIGH - 7.5

The account validation endpointĀ /v1/User/validateĀ returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50212 MEDIUM - 6.5

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50211 CRITICAL - 9.8

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50210 HIGH - 7.5

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50209 HIGH - 7.8

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50208 CRITICAL - 9.4

High-riskĀ TrustAllCertsĀ routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50207 HIGH - 7.8

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-3820 HIGH - 7.2

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.Ā  An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process i...

Published: Jun 04, 2026
Source: NVD
CVE-2026-50206 MEDIUM - 6.8

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50205 HIGH - 8.2

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD