Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,978
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,661 - 3,680 of 34,601 CVEs
CVE-2026-50258 HIGH - 7.8

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 05, 2026
Source: NVD
CVE-2026-50257 HIGH - 7.8

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection d...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 05, 2026
Source: NVD
CVE-2026-50256 HIGH - 7.8

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 05, 2026
Source: NVD
CVE-2026-25659 MEDIUM - 6.5

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation.Β The impact continues as long the attack persists but the system recovers ...

Vendor: Ericsson
Product: Packet Core Gateway (PCG)
Published: Jun 05, 2026
Source: NVD
CVE-2026-25658 MEDIUM - 6.5

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation.Β The impact continues as long the attack persists but the system recovers ...

Vendor: Ericsson
Product: Packet Core Gateway (PCG)
Published: Jun 05, 2026
Source: NVD
CVE-2026-25657 MEDIUM - 6.5

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the...

Vendor: Ericsson
Product: Packet Core Gateway (PCG)
Published: Jun 05, 2026
Source: NVD

A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal network components. By crafting a specific process containing an HTTP Request component, an attacker can force the server to send arbitrary HTTP reque...

Vendor: linqi GmbH
Product: linqi
Published: Jun 05, 2026
Source: NVD

An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorrectly grants access if an 'AnonFile' query parameter containing exactly 256 characters is pr...

Vendor: linqi GmbH
Product: linqi
Published: Jun 05, 2026
Source: NVD

In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.

Published: Jun 05, 2026
Source: NVD
CVE-2026-50265 HIGH - 7.0

A flaw was found in libinput. A local attacker with access to /dev/uinput can inject arbitrary udev properties through the libinput-device-group helper. This injection can lead to root code execution, for example, by exploiting REMOVE_CMD properties that are executed when a device is removed. This v...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 05, 2026
Source: NVD

Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.

Vendor: Samsung Mobile
Product: Samsung Android USB Driver for Windows
Published: Jun 05, 2026
Source: NVD

Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.

Vendor: Samsung Mobile
Product: Samsung Members
Published: Jun 05, 2026
Source: NVD

Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

Vendor: Samsung Mobile
Product: Samsung Internet
Published: Jun 05, 2026
Source: NVD

Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.

Vendor: Samsung Mobile
Product: Samsung Plus TV
Published: Jun 05, 2026
Source: NVD

Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.

Vendor: Samsung Mobile
Product: Samsung Auto
Published: Jun 05, 2026
Source: NVD
CVE-2026-21033 HIGH - 7.1

Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

Vendor: Samsung Mobile
Product: Samsung Assistant
Published: Jun 05, 2026
Source: NVD
CVE-2026-21032 HIGH - 7.1

Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

Vendor: Samsung Mobile
Product: Samsung Assistant
Published: Jun 05, 2026
Source: NVD
CVE-2026-21031 HIGH - 7.8

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21030 HIGH - 7.8

Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21029 HIGH - 7.8

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD