Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,601 - 4,620 of 36,556 CVEs
CVE-2026-49957 HIGH - 7.7

Hermes WebUI before version 0.51.269 contains a workspace boundary bypass vulnerability that allows authenticated attackers to circumvent blocked-root path checks by exploiting an early return in the SSH/remote terminal profile workspace resolution logic within _remote_terminal_workspace_candidate()...

Vendor: nesquena
Product: hermes-webui
Published: Jun 09, 2026
Source: NVD
CVE-2026-49956 MEDIUM - 6.5

Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Attackers can send requests to the sessions search handler to re...

Vendor: nesquena
Product: hermes-webui
Published: Jun 09, 2026
Source: NVD
CVE-2026-49955 MEDIUM - 5.3

Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. Attackers can send unlimited POST requests to the authentica...

Vendor: nesquena
Product: hermes-webui
Published: Jun 09, 2026
Source: NVD
CVE-2026-49848 MEDIUM - 4.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's check_auth userauth branch wrote request-supplied userVariables into the co...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49847 HIGH - 7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes th...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49843 MEDIUM - 5.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's JSON-RPC handler bound the connection to the client-supplied sessid on the ...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49842 HIGH - 7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop intercepts a #-prefixed speed-test protocol (#SPU / #S...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49841 CRITICAL - 9.8

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-w...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49840 CRITICAL - 9.1

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49475 HIGH - 7.5

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49472 MEDIUM - 5.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in libs/xmlrpc-c/lib/expat/x...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49161 HIGH - 7.8

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: pc_manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-49160 HIGH - 7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48583 HIGH - 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48578 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48576 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48575 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48574 HIGH - 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48573 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-48570 HIGH - 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD