Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,288
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 321 - 340 of 3,184 CVEs
CVE-2019-25729 CRITICAL - 9.8

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec...

Vendor: simcy_creative
Product: PDF Signer
Published: Jun 04, 2026
Source: NVD
CVE-2019-25727 CRITICAL - 9.8

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter...

Vendor: ad-manager-wd
Product: Ad Manager WD
Published: Jun 04, 2026
Source: NVD
CVE-2026-4104 CRITICAL - 9.8

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.

Published: Jun 04, 2026
Source: NVD
CVE-2026-10840 CRITICAL - 9.6

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluste...

Vendor: Red Hat
Product: Builds for Red Hat OpenShift, OpenShift Pipelines
Published: Jun 04, 2026
Source: NVD
CVE-2026-50225 CRITICAL - 9.1

The registration pathĀ /v1/account/registerĀ provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50214 CRITICAL - 9.8

TheĀ /v1/PlanĀ service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50211 CRITICAL - 9.8

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50208 CRITICAL - 9.4

High-riskĀ TrustAllCertsĀ routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-49191 CRITICAL - 9.8

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-49188 CRITICAL - 9.8

TheĀ ai_cmdĀ utility executes with full root permissions. It pipes socket inputs directly toĀ popen(), paving the way for unauthenticated users to execute arbitrary root commands.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-49186 CRITICAL - 9.8

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (#Ā orĀ +) to enumerate hidden network devices or publish rogue control commands.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-49185 CRITICAL - 9.8

The FieldX MDM adb messaging topic passes unverified payloads directly intoĀ Runtime.exec(), allowing command/instruction injection.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-41283 CRITICAL - 9.9

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Vendor: OpenStack
Product: Mistral
Published: Jun 04, 2026
Source: NVD

Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub

Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44180 CRITICAL - 9.8

Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-46266 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW, 255); A malicious incoming ICMP packet c...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-46244 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is im...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2026-36748 CRITICAL - 9.0

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36576 CRITICAL - 9.8

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.

Published: Jun 03, 2026
Source: NVD