Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,426
Quick preset (or use dates below)
Clear Filters
Showing 341 - 360 of 12,254 CVEs
CVE-2026-50101 HIGH - 8.1

Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain p...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-42947 HIGH - 8.8

A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account ca...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-12143 HIGH - 7.5

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-qu...

Vendor: form-data
Product: form-data
Published: Jun 12, 2026
Source: NVD
CVE-2026-12043 HIGH - 8.8

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEA...

Vendor: AWS
Product: aws-c-http
Published: Jun 12, 2026
Source: NVD
CVE-2025-52465 HIGH - 7.2

GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page

Vendor: maven
Product: org.geoserver.web:gs-web-app
Published: Jun 12, 2026
Source: GitHub
CVE-2026-53406 HIGH - 7.8

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

Vendor: Zoom Communications
Product: Remote Control for Zoom Contact Center
Published: Jun 12, 2026
Source: NVD
CVE-2026-48165 HIGH - 8.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global syste...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-48163 HIGH - 8.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not a...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-47965 HIGH - 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 12, 2026
Source: NVD
CVE-2026-44168 HIGH - 8.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not a...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-7387 HIGH - 8.8

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to esc...

Published: Jun 12, 2026
Source: NVD
CVE-2026-6961 HIGH - 7.6

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary ...

Published: Jun 12, 2026
Source: NVD
CVE-2026-53981 HIGH - 7.6

Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verifica...

Vendor: Cap-go
Product: Cap-go
Published: Jun 12, 2026
Source: NVD
CVE-2026-3840 HIGH - 7.1

A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()` method in `kedro/io/core.py` directly interpolates user-supplied version strings into filesystem paths without sanitization. This enables an attacker...

Published: Jun 12, 2026
Source: NVD
CVE-2026-9638 HIGH - 7.5

Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

Published: Jun 12, 2026
Source: NVD
CVE-2026-50088 HIGH - 8.2

The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3....

Vendor: Aqara
Product: Aqara Developer Portal, Aqara Developer Test Portal
Published: Jun 12, 2026
Source: NVD
CVE-2026-50087 HIGH - 8.2

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High).

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50085 HIGH - 8.6

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/P...

Vendor: Aqara
Product: Board service
Published: Jun 12, 2026
Source: NVD
CVE-2026-50011 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from t...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50010 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X50...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD