Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,461 - 3,480 of 35,847 CVEs
CVE-2024-21944 MEDIUM - 5.3

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrit...

Vendor: AMD
Product: AMD EPYCโ„ข 7003 Series Processors, AMD EPYCโ„ข 9004 Series Processor
Published: Jun 10, 2026
Source: NVD
CVE-2026-53742 MEDIUM - 5.4

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.

Vendor: quantumcloud
Product: Simple Link Directory
Published: Jun 10, 2026
Source: NVD
CVE-2026-53741 MEDIUM - 5.4

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.

Vendor: quantumcloud
Product: Simple Link Directory
Published: Jun 10, 2026
Source: NVD
CVE-2026-53740 MEDIUM - 5.4

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.

Vendor: Yoast
Product: Yoast Duplicate Post
Published: Jun 10, 2026
Source: NVD
CVE-2026-53739 MEDIUM - 4.3

Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressin...

Vendor: Yoast
Product: Yoast Duplicate Post
Published: Jun 10, 2026
Source: NVD
CVE-2026-53738 HIGH - 8.1

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

Vendor: Inisev
Product: Copy & Delete Posts
Published: Jun 10, 2026
Source: NVD
CVE-2026-53737 MEDIUM - 6.1

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.

Vendor: saas.group
Product: Juicer
Published: Jun 10, 2026
Source: NVD
CVE-2026-53736 MEDIUM - 4.3

Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type.

Vendor: bplugins
Product: Easy Twitter Feeds
Published: Jun 10, 2026
Source: NVD
CVE-2026-53634 MEDIUM - 4.3

Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity c...

Vendor: code16
Product: sharp
Published: Jun 10, 2026
Source: NVD
CVE-2026-50131 HIGH - 8.6

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the IPv4 validation logic present starting in...

Vendor: fedify-dev
Product: fedify, vocab-runtime
Published: Jun 10, 2026
Source: NVD
CVE-2026-48110 HIGH - 7.5

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled SSH strings, name-lists, and byte fields into owned allocations before applying field-specific bounds. A remote SSH peer could s...

Vendor: Eugeny
Product: russh
Published: Jun 10, 2026
Source: NVD
CVE-2026-48108 MEDIUM - 5.3

Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, the server-side identification reader used the same permissive path as the client, allowing pre-b...

Vendor: Eugeny
Product: russh
Published: Jun 10, 2026
Source: NVD
CVE-2026-48107 MEDIUM - 6.5

Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count dir...

Vendor: Eugeny
Product: russh
Published: Jun 10, 2026
Source: NVD

Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query string of a few thousand nested parentheses (โ‰ˆ 4โ€“12 KB) drives the recursive-descent PEG parser past the worker thread's stack guard page. Rust resp...

Vendor: kanidm
Product: kanidm
Published: Jun 10, 2026
Source: NVD
CVE-2026-46669 HIGH - 7.5

OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem 3 of https://eprint.iacr.org/2024/640.pdf but does not check that the scaling factor s is in ...

Vendor: openvm-org
Product: openvm
Published: Jun 10, 2026
Source: NVD
CVE-2026-45384 MEDIUM - 6.1

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in version 4.0.12.

Vendor: rikyoz
Product: bit7z
Published: Jun 10, 2026
Source: NVD

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, a one-byte off-by-one error in SafeOutPathBuilder::restoreSymlink() allows an attacker to craft a .7z archive that, when extracted with bit7z on any non-Windows platform, cr...

Vendor: rikyoz
Product: bit7z
Published: Jun 10, 2026
Source: NVD
CVE-2026-42542 HIGH - 7.5

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3....

Vendor: taosdata
Product: TDengine
Published: Jun 10, 2026
Source: NVD
CVE-2026-2049 HIGH - 7.8

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or o...

Published: Jun 10, 2026
Source: NVD

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).

Vendor: OpenVPN
Product: ovpn-dco-win
Published: Jun 10, 2026
Source: NVD