Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
Showing 341 - 360 of 3,310 CVEs
CVE-2026-35075 CRITICAL - 9.8

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-47065 CRITICAL - 9.8

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDKโ€™s ObjectInputStream.readProxyDesc() is dispatched. JDK th...

Vendor: Apache Software Foundation
Product: Apache MINA
Published: Jun 03, 2026
Source: NVD
CVE-2025-14771 CRITICAL - 9.9

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Vendor: ABB
Product: T-MAC Plus
Published: Jun 03, 2026
Source: NVD
CVE-2026-4035 CRITICAL - 9.1

A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in ...

Vendor: lfprojects
Product: mlflow
Published: Jun 03, 2026
Source: NVD
CVE-2026-32625 CRITICAL - 9.6

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any...

Vendor: danny-avila
Product: LibreChat
Published: Jun 02, 2026
Source: NVD
CVE-2026-49448 CRITICAL - 9.8

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.

Vendor: goauthentik
Product: authentik
Published: Jun 02, 2026
Source: NVD
CVE-2026-42849 CRITICAL - 9.3

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue...

Vendor: goauthentik
Product: authentik
Published: Jun 02, 2026
Source: NVD
CVE-2026-5076 CRITICAL - 9.8

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in ...

Published: Jun 02, 2026
Source: NVD
CVE-2026-38967 CRITICAL - 9.8

CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

Published: Jun 02, 2026
Source: NVD
CVE-2026-0611 CRITICAL - 9.8

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying...

Published: Jun 02, 2026
Source: NVD
CVE-2026-47117 CRITICAL - 9.8

OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path th...

Vendor: maziyarpanahi
Product: openmed
Published: Jun 02, 2026
Source: NVD
CVE-2026-10629 CRITICAL - 9.1

SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server headers and ESP traffic), which allows an on-path attacker to compromise confidentiality, integrity, and authenticity of VoLTE signaling via p...

Vendor: Verizon
Product: VoLTE
Published: Jun 02, 2026
Source: NVD
CVE-2026-7312 CRITICAL - 10.0

CWEโ€‘522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obt...

Vendor: progress
Product: sitefinity
Published: Jun 02, 2026
Source: NVD
CVE-2026-7198 CRITICAL - 9.8

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.

Vendor: progress
Product: sitefinity
Published: Jun 02, 2026
Source: NVD
CVE-2026-42684 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

Vendor: Ahmad
Product: WP Job Portal
Published: Jun 02, 2026
Source: NVD
CVE-2025-53209 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.

Vendor: Themeisle
Product: Masteriyo LMS PRO
Published: Jun 02, 2026
Source: NVD
CVE-2026-8206 CRITICAL - 9.8

The Kirki โ€“ Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. Th...

Published: Jun 02, 2026
Source: NVD
CVE-2026-40965 CRITICAL - 10.0

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JW...

Vendor: Cloud Foundry Foundation
Product: uaa_release, CF Deployment
Published: Jun 01, 2026
Source: NVD
CVE-2018-25427 CRITICAL - 9.8

Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception hand...

Vendor: Armcode
Product: Arm Whois
Published: Jun 01, 2026
Source: NVD
CVE-2026-9319 CRITICAL - 9.0

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

Vendor: ibm
Product: websphere_application_server
Published: Jun 01, 2026
Source: NVD