Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,750
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,041 - 5,060 of 35,133 CVEs
CVE-2026-50031 HIGH - 7.5

ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management...

Vendor: FreeIPMI
Product: FreeIPMI
Published: Jun 03, 2026
Source: NVD

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is need...

Product: dask
Published: Jun 03, 2026
Source: NVD
CVE-2026-10704 HIGH - 7.3

A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can...

Vendor: SourceCodester
Product: Pizzafy E-Commerce System
Published: Jun 03, 2026
Source: NVD
CVE-2026-10703 MEDIUM - 6.3

A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData Handler. The manipulation leads to use after free. Remote exploitation of the attack is possible. Th...

Vendor: EIPStackGroup
Product: OpENer
Published: Jun 03, 2026
Source: NVD
CVE-2026-9516 HIGH - 7.5

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the norma...

Vendor: rurban
Product: cpanel\
Published: Jun 03, 2026
Source: NVD
CVE-2026-9334 HIGH - 7.3

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_R...

Vendor: rurban
Product: cpanel\
Published: Jun 03, 2026
Source: NVD
CVE-2026-10694 HIGH - 7.3

A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.

Vendor: SourceCodester
Product: Online Food Ordering System
Published: Jun 03, 2026
Source: NVD
CVE-2026-10693 MEDIUM - 6.3

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit ha...

Vendor: SourceCodester
Product: Online Boat Reservation System
Published: Jun 03, 2026
Source: NVD
CVE-2026-9732 MEDIUM - 4.3

The EmergencyWP โ€“ Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scop...

Published: Jun 03, 2026
Source: NVD
CVE-2026-7421 MEDIUM - 4.4

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient ...

Published: Jun 03, 2026
Source: NVD
CVE-2026-10692 MEDIUM - 4.3

A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument regex can lead to inefficient regular expression complexity. It is possible to launch the attack ...

Vendor: johnhuang316
Product: code-index-mcp
Published: Jun 03, 2026
Source: NVD
CVE-2026-10691 MEDIUM - 4.3

A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a manipulation of the argument SearchResult[] results in inefficient regular expression complexity. It is...

Vendor: wonderwhy-er
Product: DesktopCommanderMCP
Published: Jun 03, 2026
Source: NVD
CVE-2026-10690 MEDIUM - 6.3

A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. Th...

Vendor: wonderwhy-er
Product: DesktopCommanderMCP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44654 HIGH - 8.1

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the owner has reused across multiple agents. The deletion removes the file globally โ€” not just from the sh...

Vendor: danny-avila
Product: LibreChat
Published: Jun 02, 2026
Source: NVD
CVE-2026-44653 MEDIUM - 6.5

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted admin-managed secrets through `GET /api/mcp/servers` and `GET /api/mcp/servers/:serverName`. The ...

Vendor: danny-avila
Product: LibreChat
Published: Jun 02, 2026
Source: NVD
CVE-2026-42507 MEDIUM - 5.3

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

Vendor: Go standard library
Product: net/textproto
Published: Jun 02, 2026
Source: NVD
CVE-2026-42504 HIGH - 7.5

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

Vendor: Go standard library
Product: mime
Published: Jun 02, 2026
Source: NVD
CVE-2026-41412 MEDIUM - 4.9

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP client (`simpleHttpClient`) into every extension script's scope. The `postFileAndSaveResponse()` me...

Vendor: alfio-event
Product: alf.io
Published: Jun 02, 2026
Source: NVD

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.

Vendor: glpi-project
Product: glpi
Published: Jun 02, 2026
Source: NVD
CVE-2026-35482 HIGH - 8.0

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrator to execute arbitrary operating system commands on the serv...

Vendor: alfio-event
Product: alf.io
Published: Jun 02, 2026
Source: NVD