Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,368
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,721 - 3,740 of 33,671 CVEs
CVE-2026-35717 MEDIUM - 6.3

A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controll...

Vendor: vivotek
Product: fd8136_firmware
Published: Jun 02, 2026
Source: NVD

Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient validation or ...

Vendor: Gleam
Product: Gleam
Published: Jun 02, 2026
Source: NVD
CVE-2026-32250 MEDIUM - 4.3

NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queries/user/`. The application reflects user-supplied input from the id parameter into the HTML response ...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD
CVE-2026-28116 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0.

Vendor: Emilia Projects
Product: Progress Planner
Published: Jun 02, 2026
Source: NVD
CVE-2026-27351 MEDIUM - 5.4

Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.

Vendor: Sekander Badsha
Product: Crew HRM
Published: Jun 02, 2026
Source: NVD
CVE-2026-10622 HIGH - 8.2

Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints.

Vendor: Collibra
Product: Collibra Platform (on-prem), Collibra Platform (SaaS)
Published: Jun 02, 2026
Source: NVD
CVE-2026-10621 HIGH - 7.5

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.

Vendor: Collibra
Product: Collibra Platform (SaaS), Collibra Platform (on-prem)
Published: Jun 02, 2026
Source: NVD

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated...

Vendor: misp
Product: misp
Published: Jun 02, 2026
Source: NVD
CVE-2025-69369 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0.

Vendor: Axiomthemes
Product: Racquet
Published: Jun 02, 2026
Source: NVD
CVE-2025-68886 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8.

Vendor: androThemes
Product: Cookiteer
Published: Jun 02, 2026
Source: NVD
CVE-2025-58897 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0.

Vendor: Axiomthemes
Product: Fermentio
Published: Jun 02, 2026
Source: NVD
CVE-2025-58707 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8.

Vendor: Axiomthemes
Product: Spin
Published: Jun 02, 2026
Source: NVD
CVE-2019-25719 HIGH - 8.6

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers ...

Vendor: Dräger
Product: Infinity Acute Care System, Standalone Infinity M540 patient monitor
Published: Jun 02, 2026
Source: NVD
CVE-2019-25717 MEDIUM - 4.3

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration deta...

Vendor: Dräger
Product: Infinity Delta, Infinity Delta XL, Infinity Kappa
Published: Jun 02, 2026
Source: NVD
CVE-2026-8993 MEDIUM - 6.5

D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side R...

Published: Jun 02, 2026
Source: NVD
CVE-2026-42685 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.

Vendor: Ahmad
Product: WP Job Portal
Published: Jun 02, 2026
Source: NVD
CVE-2026-42684 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

Vendor: Ahmad
Product: WP Job Portal
Published: Jun 02, 2026
Source: NVD
CVE-2026-42670 HIGH - 7.5

Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.

Vendor: Etoile Web Design Incorporated
Product: Five Star Restaurant Reservations
Published: Jun 02, 2026
Source: NVD
CVE-2026-42669 HIGH - 7.5

Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0.

Vendor: EventPrime
Product: EventPrime
Published: Jun 02, 2026
Source: NVD
CVE-2026-39551 HIGH - 8.1

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

Vendor: Elated-Themes
Product: Töbel
Published: Jun 02, 2026
Source: NVD