Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,933
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,481 - 4,500 of 34,481 CVEs
CVE-2026-40713 MEDIUM - 6.1

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.

Vendor: Dell
Product: ThinOS 10
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add reactions to private ...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows unauthenticated GET requests for reac...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to writ...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the fo...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD
CVE-2026-33244 MEDIUM - 5.4

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an ...

Vendor: remix-run
Product: react-router
Published: Jun 02, 2026
Source: NVD
CVE-2026-24237 HIGH - 7.8

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: NVTabular
Published: Jun 02, 2026
Source: NVD
CVE-2026-24221 HIGH - 7.8

NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.

Vendor: NVIDIA
Product: NVTabular
Published: Jun 02, 2026
Source: NVD
CVE-2026-1871 MEDIUM - 6.5

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to cra...

Vendor: tp-link
Product: tapo_c200_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-10606 HIGH - 7.3

A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The exploit has been publicly ...

Product: DedeCMS
Published: Jun 02, 2026
Source: NVD
CVE-2026-0611 CRITICAL - 9.8

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying...

Published: Jun 02, 2026
Source: NVD

HCL iReflection Third party vulnerable and outdated components issue was detected in the web application

Vendor: HCL
Product: iReflection
Published: Jun 02, 2026
Source: NVD
CVE-2026-9590 MEDIUM - 5.3

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.

Vendor: devolutions
Product: devolutions_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-9522 MEDIUM - 5.4

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.

Vendor: devolutions
Product: devolutions_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-7299 MEDIUM - 6.3

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspac...

Vendor: appsmith
Product: appsmith
Published: Jun 02, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood). When Mint's HTTP/2 receive path observes a HEADERS frame without the END_HEADERS flag, the unparsed h...

Vendor: elixir-mint
Product: mint
Published: Jun 02, 2026
Source: NVD

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allows attacker-controlled HTTP/1 servers to desynchronise response framing on shared connections. Mint's HTTP/1 Content-Length parser, Mint.HTTP1.Parse.content_length_h...

Vendor: elixir-mint
Product: mint
Published: Jun 02, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding. In lib/mint/http2.ex, Mint.HTTP2.decode_push_promise_headers_and_add_response/5 inserts a :reserved_remote e...

Vendor: elixir-mint
Product: mint
Published: Jun 02, 2026
Source: NVD

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices the caller-supplied method and target arguments directly into t...

Vendor: elixir-mint
Product: mint
Published: Jun 02, 2026
Source: NVD
CVE-2026-47117 CRITICAL - 9.8

OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path th...

Vendor: maziyarpanahi
Product: openmed
Published: Jun 02, 2026
Source: NVD