Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,415
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,641 - 3,660 of 33,646 CVEs
CVE-2019-25723 MEDIUM - 4.0

Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sending specifically crafted non-Medibus-compliant data through the Medibus interface. Attackers can overload the internal processo...

Vendor: Dräger
Product: Perseus A500
Published: Jun 02, 2026
Source: NVD
CVE-2019-25722 HIGH - 7.6

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A local attacker with di...

Vendor: Dräger
Product: SC 6002XL, SC6802XL, SC 7000, SC8000, SC90000 XL
Published: Jun 02, 2026
Source: NVD
CVE-2019-25721 MEDIUM - 6.5

Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of service vulnerability that allows network-adjacent attackers to repeatedly trigger device reboots by sending malicious requests over the Infinity Network. Attackers can exploit this...

Vendor: Dräger
Product: Infinity M300
Published: Jun 02, 2026
Source: NVD
CVE-2026-49943 MEDIUM - 6.3

CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-size stack array of 2048 + 1 pm_pos entries, while parse_path() expands AS_PATH segments from a receiv...

Vendor: NIC
Product: BIRD
Published: Jun 02, 2026
Source: NVD
CVE-2026-40715 HIGH - 7.8

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

Vendor: Dell
Product: ThinOS 10
Published: Jun 02, 2026
Source: NVD
CVE-2026-40713 MEDIUM - 6.1

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.

Vendor: Dell
Product: ThinOS 10
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add reactions to private ...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows unauthenticated GET requests for reac...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to writ...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the fo...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD
CVE-2026-33244 MEDIUM - 5.4

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an ...

Vendor: remix-run
Product: react-router
Published: Jun 02, 2026
Source: NVD
CVE-2026-24237 HIGH - 7.8

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: NVTabular
Published: Jun 02, 2026
Source: NVD
CVE-2026-24221 HIGH - 7.8

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.

Vendor: NVIDIA
Product: NVTabular
Published: Jun 02, 2026
Source: NVD
CVE-2026-1871 MEDIUM - 6.5

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to cra...

Vendor: tp-link
Product: tapo_c200_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-10606 HIGH - 7.3

A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The exploit has been publicly ...

Product: DedeCMS
Published: Jun 02, 2026
Source: NVD
CVE-2026-0611 CRITICAL - 9.8

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying...

Published: Jun 02, 2026
Source: NVD

HCL iReflection Third party vulnerable and outdated components issue was detected in the web application

Vendor: HCL
Product: iReflection
Published: Jun 02, 2026
Source: NVD
CVE-2026-9590 MEDIUM - 5.3

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.

Vendor: devolutions
Product: devolutions_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-9522 MEDIUM - 5.4

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.

Vendor: devolutions
Product: devolutions_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-7299 MEDIUM - 6.3

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspac...

Vendor: appsmith
Product: appsmith
Published: Jun 02, 2026
Source: NVD