Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,430
Quick preset (or use dates below)
Clear Filters
Showing 321 - 340 of 12,254 CVEs
CVE-2025-7011 HIGH - 7.8

Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on...

Published: Jun 12, 2026
Source: NVD
CVE-2025-7009 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on ...

Published: Jun 12, 2026
Source: NVD
CVE-2025-7008 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file with .NET metadata may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Bus...

Published: Jun 12, 2026
Source: NVD
CVE-2025-7004 HIGH - 7.8

Heap buffer out-of-bounds write vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on...

Published: Jun 12, 2026
Source: NVD
CVE-2025-7003 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.56.

Published: Jun 12, 2026
Source: NVD
CVE-2025-7002 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.68.

Published: Jun 12, 2026
Source: NVD
CVE-2026-54091 HIGH - 7.5

File Browser has incorrect access control for public directory shares via rule path rebasing

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub
CVE-2026-54092 HIGH - 6.5

File Browser has a DoS Vulnerability via Public Login API

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub
CVE-2026-54057 HIGH - 7.8

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue.

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-54056 HIGH - 7.6

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote `text/uri-list` drops are staged in a temporary directory, but on case-sensiti...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-4870 HIGH - 7.5

IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion in the parser.

Vendor: ibm
Product: qiskit_software_development_kit
Published: Jun 12, 2026
Source: NVD
CVE-2026-44786 HIGH - 7.5

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public category channels are published to MessageBus without permission scoping, so any MessageBus subscriber...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub

File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix

Vendor: go
Product: github.com/filebrowser/filebrowser
Published: Jun 12, 2026
Source: GitHub
CVE-2026-42851 HIGH - 7.8

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal โ€” a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. โ€” can cause kitty to execute attacker-supp...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-42850 HIGH - 8.8

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped and will be correctly echoed back to the terminal with CRLF, as such ...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-53999 HIGH - 7.7

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

Vendor: go
Product: github.com/radius-project/radius
Published: Jun 12, 2026
Source: GitHub
CVE-2026-53408 HIGH - 8.1

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

Vendor: Zoom Communications
Product: Zoom Workplace
Published: Jun 12, 2026
Source: NVD
CVE-2026-53407 HIGH - 8.1

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

Vendor: Zoom Communications
Product: Zoom Workplace
Published: Jun 12, 2026
Source: NVD
CVE-2026-50108 HIGH - 7.5

The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on t...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD