Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,426
Quick preset (or use dates below)
Clear Filters
Showing 361 - 380 of 12,254 CVEs
CVE-2026-48748 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches t...

Vendor: netty
Product: netty
Published: Jun 12, 2026
Source: NVD
CVE-2026-45833 HIGH - 8.8

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in theĀ /api/v2/tenants/default_tenant/databases/default_database/col...

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45832 HIGH - 8.8

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45831 HIGH - 8.8

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45830 HIGH - 8.8

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-7368 HIGH - 8.1

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command top...

Published: Jun 12, 2026
Source: NVD
CVE-2026-6211 HIGH - 8.7

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

Published: Jun 12, 2026
Source: NVD
CVE-2026-53721 HIGH - 8.2

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Vendor: go
Product: github.com/jpillora/chisel
Published: Jun 12, 2026
Source: GitHub
CVE-2026-12066 HIGH - 7.3

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery...

Product: PbootCMS
Published: Jun 12, 2026
Source: NVD
CVE-2026-50645 HIGH - 7.5

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack.Ā Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposi...

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-50633 HIGH - 8.1

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters.Ā Users are recommended to upgrade to versions 4.2.2 or 4.1....

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-50632 HIGH - 8.1

A further incomplete fix forĀ a previous advisory CVE-2026-44417Ā (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions ...

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-50631 HIGH - 7.4

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attac...

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-11846 HIGH - 8.1

TheĀ  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories,Ā  resulting in data destruction or service disruption.

Vendor: IEI Integration Corp
Product: iVEC TANK-XM811
Published: Jun 12, 2026
Source: NVD
CVE-2026-11845 HIGH - 7.2

TheĀ iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute them on the device.

Vendor: IEI Integration Corp
Product: iVEC TANK-XM811
Published: Jun 12, 2026
Source: NVD
CVE-2026-12059 HIGH - 8.8

The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.

Vendor: Cellopoint
Product: CelloOS
Published: Jun 12, 2026
Source: NVD
CVE-2026-48612 HIGH - 8.0

Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.

Vendor: phpBB
Product: phpBB
Published: Jun 12, 2026
Source: NVD