Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,008
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,961 - 4,980 of 34,907 CVEs
CVE-2026-27351 MEDIUM - 5.4

Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.

Vendor: Sekander Badsha
Product: Crew HRM
Published: Jun 02, 2026
Source: NVD
CVE-2026-10622 HIGH - 8.2

Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints.

Vendor: Collibra
Product: Collibra Platform (on-prem), Collibra Platform (SaaS)
Published: Jun 02, 2026
Source: NVD
CVE-2026-10621 HIGH - 7.5

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.

Vendor: Collibra
Product: Collibra Platform (SaaS), Collibra Platform (on-prem)
Published: Jun 02, 2026
Source: NVD

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated...

Vendor: misp
Product: misp
Published: Jun 02, 2026
Source: NVD
CVE-2025-69369 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0.

Vendor: Axiomthemes
Product: Racquet
Published: Jun 02, 2026
Source: NVD
CVE-2025-68886 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8.

Vendor: androThemes
Product: Cookiteer
Published: Jun 02, 2026
Source: NVD
CVE-2025-58897 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0.

Vendor: Axiomthemes
Product: Fermentio
Published: Jun 02, 2026
Source: NVD
CVE-2025-58707 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8.

Vendor: Axiomthemes
Product: Spin
Published: Jun 02, 2026
Source: NVD
CVE-2019-25719 HIGH - 8.6

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers ...

Vendor: Dräger
Product: Infinity Acute Care System, Standalone Infinity M540 patient monitor
Published: Jun 02, 2026
Source: NVD
CVE-2019-25717 MEDIUM - 4.3

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration deta...

Vendor: Dräger
Product: Infinity Delta, Infinity Delta XL, Infinity Kappa
Published: Jun 02, 2026
Source: NVD
CVE-2026-8993 MEDIUM - 6.5

D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side R...

Published: Jun 02, 2026
Source: NVD
CVE-2026-42685 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.

Vendor: Ahmad
Product: WP Job Portal
Published: Jun 02, 2026
Source: NVD
CVE-2026-42684 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

Vendor: Ahmad
Product: WP Job Portal
Published: Jun 02, 2026
Source: NVD
CVE-2026-42670 HIGH - 7.5

Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.

Vendor: Etoile Web Design Incorporated
Product: Five Star Restaurant Reservations
Published: Jun 02, 2026
Source: NVD
CVE-2026-42669 HIGH - 7.5

Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0.

Vendor: EventPrime
Product: EventPrime
Published: Jun 02, 2026
Source: NVD
CVE-2026-39551 HIGH - 8.1

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

Vendor: Elated-Themes
Product: Töbel
Published: Jun 02, 2026
Source: NVD
CVE-2026-39550 HIGH - 8.1

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

Vendor: Elated-Themes
Product: Aperitif
Published: Jun 02, 2026
Source: NVD
CVE-2025-58705 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue affects Crafti: from n/a through 1.12.

Vendor: Axiomthemes
Product: Crafti
Published: Jun 02, 2026
Source: NVD
CVE-2025-58024 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion. This issue affects Accordion FAQ: from n/a through 2.2.1.

Vendor: UnboundStudio
Product: Accordion FAQ
Published: Jun 02, 2026
Source: NVD
CVE-2025-53440 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. This issue affects Confidant: from n/a through 1.4.

Vendor: Axiomthemes
Product: Confidant
Published: Jun 02, 2026
Source: NVD