Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,821 - 3,840 of 35,175 CVEs
CVE-2026-11559 MEDIUM - 6.3

A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Vendor: CodeAstro
Product: Payroll System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11558 MEDIUM - 6.3

A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disc...

Vendor: CodeAstro
Product: Payroll System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11557 HIGH - 8.8

A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed re...

Vendor: Tenda
Product: F451
Published: Jun 08, 2026
Source: NVD
CVE-2026-11393 CRITICAL - 9.0

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of anot...

Vendor: AWS
Product: AgentCore CLI
Published: Jun 08, 2026
Source: NVD
CVE-2026-10787 MEDIUM - 4.3

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-10786 MEDIUM - 6.5

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions ...

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-10544 MEDIUM - 6.5

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue affects : * Devoluti...

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-44893 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only ...

Vendor: maven
Product: io.netty:netty-codec-haproxy
Published: Jun 08, 2026
Source: GitHub
CVE-2026-44892 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SET...

Vendor: maven
Product: io.netty:netty-codec-http3
Published: Jun 08, 2026
Source: GitHub
CVE-2026-44890 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's dir...

Vendor: maven
Product: io.netty:netty-codec-redis
Published: Jun 08, 2026
Source: GitHub
CVE-2026-44250 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number...

Vendor: maven
Product: io.netty:netty-codec-redis
Published: Jun 08, 2026
Source: GitHub
CVE-2026-44249 HIGH - 8.1

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can...

Vendor: maven
Product: io.netty:netty-handler
Published: Jun 08, 2026
Source: GitHub

Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary w...

Vendor: npm
Product: actual
Published: Jun 08, 2026
Source: GitHub

A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when apply...

Published: Jun 08, 2026
Source: NVD
CVE-2026-11556 HIGH - 8.8

A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. Remote exploitation of the attack is p...

Vendor: Tenda
Product: F451
Published: Jun 08, 2026
Source: NVD

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complex...

Vendor: D-Link
Product: DGS-1100-08PD
Published: Jun 08, 2026
Source: NVD
CVE-2026-11554 MEDIUM - 4.3

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be uti...

Vendor: TOTOLINK
Product: CP450
Published: Jun 08, 2026
Source: NVD
CVE-2026-11553 HIGH - 8.8

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and ...

Vendor: Tenda
Product: HG7HG9, HG10
Published: Jun 08, 2026
Source: NVD
CVE-2026-11552 MEDIUM - 5.3

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password wi...

Vendor: SourceCodester
Product: Onlne Examination & Learning Management System, Syllabus-aligned Learning Management and Examination System
Published: Jun 08, 2026
Source: NVD
CVE-2026-41479 MEDIUM - 5.4

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri....

Vendor: pip
Product: authlib
Published: Jun 08, 2026
Source: GitHub