Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,531
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,461 - 3,480 of 35,159 CVEs
CVE-2026-42769 MEDIUM - 5.3

Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to ...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD

Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output. Impact summary: The Bleichenbacher-style attack allows an attacker to use the ...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-42767 MEDIUM - 5.9

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service. An attacker controlling a CMP server (or ac...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-42766 MEDIUM - 5.9

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service. The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-42765 HIGH - 7.5

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can tri...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-42764 HIGH - 7.5

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-41108 HIGH - 7.0

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-41098 HIGH - 8.4

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

Published: Jun 09, 2026
Source: NVD
CVE-2026-41092 HIGH - 7.8

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40409 HIGH - 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40404 HIGH - 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-40376 HIGH - 7.5

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: visual_studio_code
Published: Jun 09, 2026
Source: NVD
CVE-2026-40371 HIGH - 8.8

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

Published: Jun 09, 2026
Source: NVD

Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

Published: Jun 09, 2026
Source: NVD
CVE-2026-38615 CRITICAL - 9.8

DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

Published: Jun 09, 2026
Source: NVD
CVE-2026-35188 MEDIUM - 5.0

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path. Impact summary: Successful exploitation allows an attacker to corrupt heap memory via a...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34692 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Explo...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-34335 HIGH - 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-34183 HIGH - 7.5

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUI...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD
CVE-2026-34182 CRITICAL - 9.1

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-eq...

Vendor: OpenSSL
Product: OpenSSL
Published: Jun 09, 2026
Source: NVD