Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,853
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 401 - 420 of 12,881 CVEs
CVE-2026-37216 MEDIUM - 6.1

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

Published: Jun 15, 2026
Source: NVD
CVE-2026-36933 MEDIUM - 6.8

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

Published: Jun 15, 2026
Source: NVD
CVE-2026-36521 MEDIUM - 6.1

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

Published: Jun 15, 2026
Source: NVD
CVE-2026-11931 MEDIUM - 5.5

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600). To remediate this issue, users should upgra...

Vendor: AWS
Product: Kiro IDE
Published: Jun 15, 2026
Source: NVD
CVE-2025-70102 MEDIUM - 6.3

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a NULL pointer of type 'struct dhcp_opt' when an unexpected/invalid option token or parsi...

Published: Jun 15, 2026
Source: NVD
CVE-2025-55663 MEDIUM - 5.5

A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55661 MEDIUM - 5.5

A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55660 MEDIUM - 5.5

A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55652 MEDIUM - 5.5

A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55650 MEDIUM - 5.5

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55649 MEDIUM - 5.5

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55648 MEDIUM - 5.5

A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55647 MEDIUM - 5.5

An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55645 MEDIUM - 5.5

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55644 MEDIUM - 5.5

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55643 MEDIUM - 5.5

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55642 MEDIUM - 6.5

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55641 MEDIUM - 5.5

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2026-48817 MEDIUM - 5.3

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoin...

Vendor: pip
Product: starlette
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48125 MEDIUM - 5.3

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

Vendor: npm
Product: ua-parser-js
Published: Jun 15, 2026
Source: GitHub