Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,015
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,601 - 4,620 of 34,907 CVEs
CVE-2025-52606 MEDIUM - 4.3

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected t...

Vendor: HCL
Product: iControl
Published: Jun 04, 2026
Source: NVD

A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.

Vendor: Forcepoint
Product: VPN Client
Published: Jun 04, 2026
Source: NVD
CVE-2026-49077 MEDIUM - 5.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.

Vendor: Tips and Tricks HQ
Product: WP eMember
Published: Jun 04, 2026
Source: NVD

A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A hig...

Vendor: modelscope
Product: ms-swift
Published: Jun 04, 2026
Source: NVD
CVE-2026-8916 MEDIUM - 6.1

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: beforeĀ dcfde72eae1b0464dc0dd760aec00ada6a148635.

Published: Jun 04, 2026
Source: NVD
CVE-2026-50226 MEDIUM - 5.3

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50225 CRITICAL - 9.1

The registration pathĀ /v1/account/registerĀ provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50224 MEDIUM - 4.9

The web administration panel binds broadly to the public IPv6 address space on portĀ [::]:8080Ā without default firewall limits, making internal API endpoints reachable over the WAN.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50214 CRITICAL - 9.8

TheĀ /v1/PlanĀ service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.

Published: Jun 04, 2026
Source: NVD
CVE-2026-49771 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.

Vendor: 10Web
Product: Photo Gallery by 10Web
Published: Jun 04, 2026
Source: NVD
CVE-2026-49510 MEDIUM - 6.1

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie:Ā beforeĀ 21292665023e5074b38254432716866d00f1985f.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47320 MEDIUM - 6.1

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47319 MEDIUM - 6.1

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47318 MEDIUM - 6.1

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47306 MEDIUM - 6.1

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD

A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high c...

Vendor: PaddlePaddle
Product: FastDeploy
Published: Jun 04, 2026
Source: NVD
CVE-2026-10305 MEDIUM - 6.1

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-50213 HIGH - 7.5

The account validation endpointĀ /v1/User/validateĀ returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50212 MEDIUM - 6.5

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD