Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,447
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,401 - 3,420 of 33,646 CVEs
CVE-2026-46447 MEDIUM - 5.8

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Vendor: OpenStack
Product: Ironic
Published: Jun 03, 2026
Source: NVD

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Vendor: NETAPP
Product: Active IQ OneCollect
Published: Jun 03, 2026
Source: NVD

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Vendor: NETAPP
Product: Active IQ Config Advisor
Published: Jun 03, 2026
Source: NVD
CVE-2026-10771 HIGH - 7.3

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request forger...

Vendor: crmeb
Product: crmeb_java
Published: Jun 03, 2026
Source: NVD

Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub

Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44180 CRITICAL - 9.8

Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44023 HIGH - 8.6

Docling Core: Unsafe remote filename resolution

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44019 HIGH - 8.1

Docling Core: Insufficient validation of image reference URIs

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-47214 HIGH - 7.1

Docling: Unsafe URI and Path Handling in HTML Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44022 MEDIUM - 5.5

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44020 HIGH - 7.5

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44018 MEDIUM - 5.5

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44016 HIGH - 8.2

Docling: Unsafe Playwright-based HTML Rendering

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-43980 MEDIUM - 6.3

malla: Stored XSS via Meshtastic node names in multiple frontend pages

Vendor: pip
Product: malla
Published: Jun 03, 2026
Source: GitHub
CVE-2026-41234 HIGH - 7.6

Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record l...

Vendor: composer
Product: froxlor/froxlor
Published: Jun 03, 2026
Source: GitHub
CVE-2026-40898 MEDIUM - 5.3

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique fie...

Vendor: go
Product: github.com/quic-go/quic-go
Published: Jun 03, 2026
Source: GitHub
CVE-2026-50033 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44682 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44609 HIGH - 7.3

Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD