Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,270
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,101 - 4,120 of 33,692 CVEs
CVE-2026-25600 MEDIUM - 6.4

The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in the product’s configuration file. Because the secret is constant a...

Vendor: Trac d.o.o.
Product: PDBM
Published: Jun 01, 2026
Source: NVD
CVE-2026-25599 MEDIUM - 6.3

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicati...

Vendor: Orca Energy
Product: Orca heat pump, Orca user portal
Published: Jun 01, 2026
Source: NVD
CVE-2026-10250 HIGH - 7.3

A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely...

Vendor: itsourcecode
Product: Online Blood Bank Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10249 HIGH - 7.3

A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be...

Vendor: itsourcecode
Product: Online Blood Bank Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10248 MEDIUM - 4.7

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Re...

Vendor: SourceCodester
Product: Pharmacy Sales and Inventory System
Published: Jun 01, 2026
Source: NVD

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The attack may be launched r...

Vendor: SourceCodester
Product: Pharmacy Sales and Inventory System
Published: Jun 01, 2026
Source: NVD

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site scripting. The attack m...

Vendor: SourceCodester
Product: Pharmacy Sales and Inventory System
Published: Jun 01, 2026
Source: NVD

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack can be launched remot...

Vendor: SourceCodester
Product: Pharmacy Sales and Inventory System
Published: Jun 01, 2026
Source: NVD

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The at...

Vendor: SourceCodester
Product: Pharmacy Sales and Inventory System
Published: Jun 01, 2026
Source: NVD
CVE-2026-9024 HIGH - 8.7

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.

Published: Jun 01, 2026
Source: NVD
CVE-2026-8474 MEDIUM - 5.3

A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. ...

Published: Jun 01, 2026
Source: NVD
CVE-2026-7858 CRITICAL - 9.8

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.

Published: Jun 01, 2026
Source: NVD
CVE-2026-49361 HIGH - 7.5

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting i...

Vendor: Apache Software Foundation
Product: Apache Fluss (incubating)
Published: Jun 01, 2026
Source: NVD
CVE-2026-49298 HIGH - 8.8

A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g....

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Jun 01, 2026
Source: NVD
CVE-2026-49270 MEDIUM - 5.9

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durabl...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All
Published: Jun 01, 2026
Source: NVD
CVE-2026-49267 MEDIUM - 5.9

Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] smtp_ssl`. An attacker positioned between the worker and the conf...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Jun 01, 2026
Source: NVD
CVE-2026-49157 HIGH - 8.8

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker ma...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ
Published: Jun 01, 2026
Source: NVD
CVE-2026-48827 HIGH - 7.1

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory. Applications are affected if t...

Vendor: Apache Software Foundation
Product: Apache MINA SSHD
Published: Jun 01, 2026
Source: NVD
CVE-2026-48726 MEDIUM - 6.5

A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, so the JWT remained accepted by the...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Jun 01, 2026
Source: NVD
CVE-2026-46764 MEDIUM - 4.3

The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, while the collection endpoint `GET /api/v2/eventLogs` applied per-Dag scoping. An authenticated UI/API user with aud...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Jun 01, 2026
Source: NVD