Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,948
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,961 - 4,980 of 34,601 CVEs
CVE-2026-42683 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-42682 CRITICAL - 9.1

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

Vendor: Tomdever
Product: wpForo Forum
Published: Jun 01, 2026
Source: NVD
CVE-2026-42681 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

Vendor: E2Pdf.com
Product: e2pdf
Published: Jun 01, 2026
Source: NVD
CVE-2026-42680 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

Vendor: Wasiliy Strecker / ContestGallery developer
Product: Contest Gallery Pro
Published: Jun 01, 2026
Source: NVD

Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a leg...

Vendor: KAMSOFT
Product: KS-SOMED
Published: Jun 01, 2026
Source: NVD
CVE-2026-37221 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pending event. The near-RT RIC uses assert() to enforce the existence of a pending event during response processing. A remote unauthenticated attacker can send a forged RIC_SUBSCRIPTION...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37220 HIGH - 7.5

FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can crash the near-RT RIC (port 364...

Published: Jun 01, 2026
Source: NVD
CVE-2026-10533 MEDIUM - 5.0

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that acc...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: Jun 01, 2026
Source: NVD

A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/core/debug.c. Performing a manipulation results in out-of-bounds read. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. ...

Vendor: janet-lang
Product: janet
Published: Jun 01, 2026
Source: NVD
CVE-2026-10265 MEDIUM - 6.3

A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly availa...

Vendor: itsourcecode
Product: Content Management System
Published: Jun 01, 2026
Source: NVD

A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly di...

Vendor: lharries
Product: whatsapp-mcp
Published: Jun 01, 2026
Source: NVD
CVE-2026-10263 HIGH - 7.3

A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made p...

Vendor: SourceCodester
Product: Computer Repair Shop Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10262 HIGH - 7.3

A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the p...

Vendor: code-projects
Product: Real State Services
Published: Jun 01, 2026
Source: NVD
CVE-2026-10261 HIGH - 7.3

A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

Vendor: CodeAstro
Product: Online Job Portal
Published: Jun 01, 2026
Source: NVD
CVE-2026-10260 HIGH - 7.3

A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now publi...

Vendor: CodeAstro
Product: Online Job Portal
Published: Jun 01, 2026
Source: NVD
CVE-2026-10259 HIGH - 8.8

A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been ...

Vendor: H3C
Product: Magic B0
Published: Jun 01, 2026
Source: NVD

In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60495 MEDIUM - 5.5

A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60486 MEDIUM - 5.5

A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60485 MEDIUM - 5.5

A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Published: Jun 01, 2026
Source: NVD