Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,430
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,521 - 3,540 of 33,646 CVEs
CVE-2025-70101 MEDIUM - 6.5

An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before p...

Vendor: gkostka
Product: lwext4
Published: Jun 03, 2026
Source: NVD
CVE-2025-70100 MEDIUM - 5.5

A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount...

Vendor: gkostka
Product: lwext4
Published: Jun 03, 2026
Source: NVD
CVE-2025-60477 MEDIUM - 5.0

A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

Published: Jun 03, 2026
Source: NVD
CVE-2024-47273 MEDIUM - 4.3

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.

Vendor: Synology
Product: Hyper Backup
Published: Jun 03, 2026
Source: NVD
CVE-2024-47263 MEDIUM - 4.1

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive ...

Vendor: Synology
Product: Hyper Backup
Published: Jun 03, 2026
Source: NVD
CVE-2023-52951 MEDIUM - 5.9

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

Vendor: Synology
Product: Synology Note Station Client
Published: Jun 03, 2026
Source: NVD
CVE-2022-49042 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Hyper Backup Explorer
Published: Jun 03, 2026
Source: NVD
CVE-2022-49036 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Active Backup for Business Recovery Media Creator
Published: Jun 03, 2026
Source: NVD
CVE-2026-35085 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35084 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35083 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35082 HIGH - 8.8

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35081 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35080 HIGH - 8.1

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35079 HIGH - 8.1

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35078 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35077 HIGH - 8.1

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35076 HIGH - 8.1

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35075 CRITICAL - 9.8

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local...

Vendor: cilium
Product: ebpf
Published: Jun 03, 2026
Source: NVD