Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,561 - 3,580 of 34,822 CVEs
CVE-2026-36786 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 08, 2026
Source: NVD
CVE-2026-34356 HIGH - 7.5

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-34355 HIGH - 7.5

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-34194 HIGH - 7.1

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation. The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled acro...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 08, 2026
Source: NVD
CVE-2026-29170 MEDIUM - 6.1

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this iss...

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-29167 CRITICAL - 9.8

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-22164 HIGH - 7.5

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. By creating resources of certain types and presenting a set of parameters to the affected interface the exploit can be used to corrupt kernel memory.

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 08, 2026
Source: NVD
CVE-2026-11529 MEDIUM - 6.3

A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the ...

Vendor: designcomputer
Product: mysql-mcp-server
Published: Jun 08, 2026
Source: NVD
CVE-2026-11528 HIGH - 8.8

A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow. The attack may be launched remotely. Th...

Vendor: Tenda
Product: AC18
Published: Jun 08, 2026
Source: NVD
CVE-2026-11524 HIGH - 8.8

A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow. The attack may be in...

Vendor: Tenda
Product: W20E
Published: Jun 08, 2026
Source: NVD
CVE-2026-11523 HIGH - 8.8

A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The e...

Vendor: Tenda
Product: W20E
Published: Jun 08, 2026
Source: NVD
CVE-2026-11522 HIGH - 8.8

A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The explo...

Vendor: Tenda
Product: W20E
Published: Jun 08, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vkms' vblank timer with the DRM implementation. The DRM code is identical in concept, but differs in implementation. Vblank timers are covered in vblank helpers and initia...

Vendor: Linux
Product: Linux
Published: Jun 08, 2026
Source: NVD
CVE-2020-37248 MEDIUM - 6.5

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.

Vendor: OfflineIMAP
Product: OfflineIMAP
Published: Jun 08, 2026
Source: NVD
CVE-2026-49235 HIGH - 7.5

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD
CVE-2026-49234 HIGH - 7.5

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD
CVE-2026-49233 HIGH - 7.5

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD

Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be triggered maliciously by an attacker by opening a large number of connections to the HTTP or RTR server. This only affects...

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD

Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicited 101 Switching Protocols response. In gun_http:handle_inform/8, when a 101 Switching Protocols response is received ove...

Vendor: ninenines
Product: gun
Published: Jun 08, 2026
Source: NVD

Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded HTTP/1.1 response buffering. In gun_http:handle/5, three clauses accumulate incoming TCP data into the connection's buffer field using binary conc...

Vendor: ninenines
Product: gun
Published: Jun 08, 2026
Source: NVD