Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,900
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,321 - 3,340 of 34,615 CVEs
CVE-2026-41448 CRITICAL - 9.4

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path cons...

Vendor: AdguardTeam
Product: AdGuardHome
Published: Jun 08, 2026
Source: NVD
CVE-2026-39910 CRITICAL - 9.8

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvalidated PUT servers...

Vendor: STACKIT
Product: IaaS API
Published: Jun 08, 2026
Source: NVD
CVE-2026-39908 MEDIUM - 6.5

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application at...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-25856 HIGH - 8.8

OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying job configurations. Attackers can leverage the plain C# execution mode, which lacks reference filte...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-25855 HIGH - 8.8

OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by uploading script files (.bat.ps1.sh) through the FileProxySource proxy loading feature. Attackers can upload malicious script files as proxy sources, caus...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-25559 HIGH - 8.8

OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete operations by supplying unsanitized absolute paths to the upload handler and wordlist functions. Attackers can chai...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-25555 CRITICAL - 9.8

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied h...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-11611 MEDIUM - 6.5

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connecti...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 08, 2026
Source: NVD

A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting. It is possible to launch ...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11533 MEDIUM - 5.4

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads to i...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11532 MEDIUM - 6.3

A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing a manipulation can lead to improper access controls. The attack may be performe...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11531 HIGH - 7.3

A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator Login Endpoint. Performing a manipulation of the argument a_usr/a_pwd results in...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11530 HIGH - 7.3

A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. T...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-49975 HIGH - 7.5

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, ...

Vendor: wojtekmach
Product: req
Published: Jun 08, 2026
Source: NVD

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client via decompression-bomb response bodies. Req's default response pipeline includes Req.Steps.decode_body/1 and Req.Steps.deco...

Vendor: wojtekmach
Product: req
Published: Jun 08, 2026
Source: NVD
CVE-2026-48913 HIGH - 7.3

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerable to collision attacks since 2017 (SHAttered). Version 4.1.4 fixes the issue.

Vendor: thorsten
Product: phpMyFAQ
Published: Jun 08, 2026
Source: NVD
CVE-2026-46657 HIGH - 7.1

Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a user account, the application fails to invalidate or clear the ...

Vendor: bludit
Product: bludit
Published: Jun 08, 2026
Source: NVD
CVE-2026-46656 HIGH - 8.8

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthor...

Vendor: bludit
Product: bludit
Published: Jun 08, 2026
Source: NVD