Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,286
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,041 - 4,060 of 33,692 CVEs
CVE-2026-10270 HIGH - 8.8

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public a...

Vendor: D-Link
Product: DI-7001 MINI
Published: Jun 01, 2026
Source: NVD
CVE-2026-10269 MEDIUM - 6.3

A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carri...

Vendor: decolua
Product: 9router
Published: Jun 01, 2026
Source: NVD

A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_fiber of the file src/core/marsh.c. Executing a manipulation can lead to integer overflow. It is possible to launch the attack on the local host. The exploit has been made available...

Vendor: janet-lang
Product: janet
Published: Jun 01, 2026
Source: NVD
CVE-2026-10118 HIGH - 7.8

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subseq...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images
Published: Jun 01, 2026
Source: NVD
CVE-2022-4991 HIGH - 7.4

Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate...

Published: Jun 01, 2026
Source: NVD

A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.

Published: Jun 01, 2026
Source: NVD
CVE-2026-48879 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

Vendor: Sergey
Product: AIWU
Published: Jun 01, 2026
Source: NVD
CVE-2026-48866 CRITICAL - 9.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

Vendor: Rocketgenius Inc.
Product: Gravity Forms
Published: Jun 01, 2026
Source: NVD
CVE-2026-48865 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6.

Vendor: ThimPress
Product: LearnPress
Published: Jun 01, 2026
Source: NVD
CVE-2026-48839 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

Vendor: VeronaLabs
Product: WP Statistics
Published: Jun 01, 2026
Source: NVD
CVE-2026-48559 MEDIUM - 5.4

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victi...

Vendor: epoupon
Product: lms
Published: Jun 01, 2026
Source: NVD
CVE-2026-42683 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-42682 CRITICAL - 9.1

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

Vendor: Tomdever
Product: wpForo Forum
Published: Jun 01, 2026
Source: NVD
CVE-2026-42681 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

Vendor: E2Pdf.com
Product: e2pdf
Published: Jun 01, 2026
Source: NVD
CVE-2026-42680 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

Vendor: Wasiliy Strecker / ContestGallery developer
Product: Contest Gallery Pro
Published: Jun 01, 2026
Source: NVD

Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a leg...

Vendor: KAMSOFT
Product: KS-SOMED
Published: Jun 01, 2026
Source: NVD
CVE-2026-37221 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pending event. The near-RT RIC uses assert() to enforce the existence of a pending event during response processing. A remote unauthenticated attacker can send a forged RIC_SUBSCRIPTION...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37220 HIGH - 7.5

FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can crash the near-RT RIC (port 364...

Published: Jun 01, 2026
Source: NVD
CVE-2026-10533 MEDIUM - 5.0

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that acc...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: Jun 01, 2026
Source: NVD

A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/core/debug.c. Performing a manipulation results in out-of-bounds read. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. ...

Vendor: janet-lang
Product: janet
Published: Jun 01, 2026
Source: NVD