Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,015
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,541 - 3,560 of 34,907 CVEs

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

Vendor: OpenVPN
Product: OpenVPN
Published: Jun 08, 2026
Source: NVD
CVE-2026-11585 MEDIUM - 6.3

A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publ...

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-49141 HIGH - 7.1

WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership v...

Vendor: ArnasDon
Product: wacrm
Published: Jun 08, 2026
Source: NVD

Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

Vendor: TYPO3
Product: HTML Sanitizer
Published: Jun 08, 2026
Source: NVD

When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of...

Vendor: TYPO3
Product: HTML Sanitizer
Published: Jun 08, 2026
Source: NVD
CVE-2026-46484 HIGH - 8.1

Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.

Vendor: tale
Product: headplane
Published: Jun 08, 2026
Source: NVD
CVE-2026-40519 HIGH - 7.5

Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary co...

Vendor: NginxProxyManager
Product: nginx-proxy-manager
Published: Jun 08, 2026
Source: NVD

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

Vendor: OpenVPN
Product: OpenVPN
Published: Jun 08, 2026
Source: NVD
CVE-2026-11584 MEDIUM - 6.3

A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has...

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11583 MEDIUM - 6.3

A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argument className leads to sql injection. It is possible to initiate the attack remotely. The exploit has...

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11582 HIGH - 7.3

A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been p...

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-52778 CRITICAL - 9.8

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing...

Vendor: YesWiki
Product: yeswiki
Published: Jun 08, 2026
Source: NVD
CVE-2026-11559 MEDIUM - 6.3

A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Vendor: CodeAstro
Product: Payroll System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11558 MEDIUM - 6.3

A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disc...

Vendor: CodeAstro
Product: Payroll System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11557 HIGH - 8.8

A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed re...

Vendor: Tenda
Product: F451
Published: Jun 08, 2026
Source: NVD
CVE-2026-11393 CRITICAL - 9.0

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of anot...

Vendor: AWS
Product: AgentCore CLI
Published: Jun 08, 2026
Source: NVD
CVE-2026-10787 MEDIUM - 4.3

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-10786 MEDIUM - 6.5

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions ...

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-10544 MEDIUM - 6.5

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue affects : * Devoluti...

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-44893 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only ...

Vendor: maven
Product: io.netty:netty-codec-haproxy
Published: Jun 08, 2026
Source: GitHub