Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,053
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,741 - 4,760 of 34,990 CVEs

A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local position. The attack is considered to have high co...

Vendor: gradio-app
Product: gradio
Published: Jun 04, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 03, 2026
Source: NVD
CVE-2026-10777 HIGH - 7.3

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component Administrative Backend. Such manipulation leads to improper authentication. The att...

Vendor: ealpha072
Product: Student-Management-System
Published: Jun 03, 2026
Source: NVD

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack. T...

Vendor: sgl-project
Product: SGLang
Published: Jun 03, 2026
Source: NVD
CVE-2026-46447 MEDIUM - 5.8

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Vendor: OpenStack
Product: Ironic
Published: Jun 03, 2026
Source: NVD

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Vendor: NETAPP
Product: Active IQ OneCollect
Published: Jun 03, 2026
Source: NVD

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Vendor: NETAPP
Product: Active IQ Config Advisor
Published: Jun 03, 2026
Source: NVD
CVE-2026-10771 HIGH - 7.3

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request forger...

Vendor: crmeb
Product: crmeb_java
Published: Jun 03, 2026
Source: NVD

Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub

Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44180 CRITICAL - 9.8

Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44023 HIGH - 8.6

Docling Core: Unsafe remote filename resolution

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44019 HIGH - 8.1

Docling Core: Insufficient validation of image reference URIs

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-47214 HIGH - 7.1

Docling: Unsafe URI and Path Handling in HTML Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44022 MEDIUM - 5.5

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44020 HIGH - 7.5

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44018 MEDIUM - 5.5

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44016 HIGH - 8.2

Docling: Unsafe Playwright-based HTML Rendering

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-43980 MEDIUM - 6.3

malla: Stored XSS via Meshtastic node names in multiple frontend pages

Vendor: pip
Product: malla
Published: Jun 03, 2026
Source: GitHub
CVE-2026-41234 HIGH - 7.6

Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record l...

Vendor: composer
Product: froxlor/froxlor
Published: Jun 03, 2026
Source: GitHub