Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,341 - 4,360 of 34,478 CVEs
CVE-2026-8404 LOW - 3.1

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache...

Vendor: djangoproject
Product: django
Published: Jun 03, 2026
Source: NVD
CVE-2026-7666 LOW - 3.1

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read...

Vendor: djangoproject
Product: django
Published: Jun 03, 2026
Source: NVD
CVE-2026-6873 LOW - 3.1

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one w...

Vendor: djangoproject
Product: django
Published: Jun 03, 2026
Source: NVD
CVE-2026-5241 HIGH - 8.0

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, i...

Vendor: huggingface
Product: transformers
Published: Jun 03, 2026
Source: NVD

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs w...

Vendor: djangoproject
Product: Django
Published: Jun 03, 2026
Source: NVD

ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The application does not require or prompt users to change the password upon first login. This b...

Vendor: ProjectsAndPrograms
Product: school-management-system
Published: Jun 03, 2026
Source: NVD

ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or administrator) can inject malicious JavaScript that is subsequently executed in other users’ browsers. C...

Vendor: ProjectsAndPrograms
Product: school-management-system
Published: Jun 03, 2026
Source: NVD

daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or \x85 as header line separators, but autobahn decodes header values to str and calls splitlines()...

Vendor: djangoproject
Product: daphne
Published: Jun 03, 2026
Source: NVD
CVE-2026-44545 MEDIUM - 5.3

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory cons...

Vendor: djangoproject
Product: daphne
Published: Jun 03, 2026
Source: NVD
CVE-2026-37460 HIGH - 7.5

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Published: Jun 03, 2026
Source: NVD

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read priva...

Vendor: djangoproject
Product: Django
Published: Jun 03, 2026
Source: NVD

An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue aff...

Vendor: Thinkst Applied Research
Product: Canarytokens
Published: Jun 03, 2026
Source: NVD
CVE-2025-70101 MEDIUM - 6.5

An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before p...

Vendor: gkostka
Product: lwext4
Published: Jun 03, 2026
Source: NVD
CVE-2025-70100 MEDIUM - 5.5

A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount...

Vendor: gkostka
Product: lwext4
Published: Jun 03, 2026
Source: NVD
CVE-2025-60477 MEDIUM - 5.0

A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

Published: Jun 03, 2026
Source: NVD
CVE-2024-47273 MEDIUM - 4.3

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.

Vendor: Synology
Product: Hyper Backup
Published: Jun 03, 2026
Source: NVD
CVE-2024-47263 MEDIUM - 4.1

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive ...

Vendor: Synology
Product: Hyper Backup
Published: Jun 03, 2026
Source: NVD
CVE-2023-52951 MEDIUM - 5.9

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

Vendor: Synology
Product: Synology Note Station Client
Published: Jun 03, 2026
Source: NVD
CVE-2022-49042 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Hyper Backup Explorer
Published: Jun 03, 2026
Source: NVD
CVE-2022-49036 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Active Backup for Business Recovery Media Creator
Published: Jun 03, 2026
Source: NVD