Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,141 - 5,160 of 34,768 CVEs
CVE-2026-10261 HIGH - 7.3

A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

Vendor: CodeAstro
Product: Online Job Portal
Published: Jun 01, 2026
Source: NVD
CVE-2026-10260 HIGH - 7.3

A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now publi...

Vendor: CodeAstro
Product: Online Job Portal
Published: Jun 01, 2026
Source: NVD
CVE-2026-10259 HIGH - 8.8

A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been ...

Vendor: H3C
Product: Magic B0
Published: Jun 01, 2026
Source: NVD

In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60495 MEDIUM - 5.5

A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60486 MEDIUM - 5.5

A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60485 MEDIUM - 5.5

A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60483 MEDIUM - 5.5

A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60481 MEDIUM - 5.5

A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-55664 MEDIUM - 5.5

A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Published: Jun 01, 2026
Source: NVD
CVE-2024-40646 HIGH - 8.6

Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to commit fbde301b97986d5913fc4bc95f5445750d282e11 are vulnerable to path traversal. Users should upgrade to a version containing commit fbde301b97986d5913fc4bc95f5445750d282e11 to rece...

Vendor: vertex-app
Product: vertex
Published: Jun 01, 2026
Source: NVD

kas checks out SHA-like git branches as valid commits

Vendor: pip
Product: kas
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47412 HIGH - 8.1

praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47415 HIGH - 8.3

praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47413 CRITICAL - 9.6

praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47411 MEDIUM - 6.5

praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47417 HIGH - 8.1

praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47418 HIGH - 8.1

praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub

rattler has an entry-point path traversal in noarch:python install (arbitrary file write)

Vendor: rust
Product: rattler
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47428 CRITICAL - 9.6

Vitest browser mode serves unsanitized otelCarrier query parameter as inline script

Vendor: npm
Product: @vitest/browser
Published: Jun 01, 2026
Source: GitHub