Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,729
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 521 - 540 of 36,814 CVEs
CVE-2026-40083 HIGH - 7.2

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php, the application assigns $selected_items by calling cacti_unserialize(stripslashes(gnrv('selecte...

Vendor: Cacti
Product: cacti
Published: Jun 25, 2026
Source: NVD
CVE-2026-40082 MEDIUM - 5.4

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207 directly sets $_SESSION[...

Vendor: Cacti
Product: cacti
Published: Jun 25, 2026
Source: NVD
CVE-2026-40080 MEDIUM - 6.1

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer after logi...

Vendor: Cacti
Product: cacti
Published: Jun 25, 2026
Source: NVD
CVE-2026-8720 HIGH - 7.5

wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the supplied key is longer than the BLAKE2 block size the key-hashing branch reinitialized the running hash state, discarding the accumul...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-7532 HIGH - 7.5

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-7511 HIGH - 7.5

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6331 HIGH - 7.5

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signature length was only checked as not exceeding the MAC length, so a zero-length or otherwise truncated ta...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6330 MEDIUM - 6.5

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively ignored part of the re-encrypted ciphertext, so a decapsulating p...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6329 MEDIUM - 6.5

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the MAC parsed from the PKCS#12 structure using a length taken directly fr...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6325 HIGH - 7.5

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6092 MEDIUM - 5.3

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-55962 MEDIUM - 6.5

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an empty/absent peer certificate was only intended for the initial handshak...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD
CVE-2026-54479 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other ...

Vendor: EVoke
Product: EVoke CSMS
Published: Jun 25, 2026
Source: NVD
CVE-2026-50176 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

Vendor: EVoke
Product: EVoke CSMS
Published: Jun 25, 2026
Source: NVD
CVE-2026-44622 MEDIUM - 6.5

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Vendor: EVoke
Product: EVoke CSMS
Published: Jun 25, 2026
Source: NVD
CVE-2026-40702 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to p...

Vendor: EVoke
Product: EVoke CSMS
Published: Jun 25, 2026
Source: NVD
CVE-2026-22879 HIGH - 8.1

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

Vendor: vtk
Product: vtk
Published: Jun 25, 2026
Source: NVD
CVE-2026-13283 HIGH - 7.5

Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 25, 2026
Source: NVD
CVE-2026-13282 MEDIUM - 6.8

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 25, 2026
Source: NVD
CVE-2026-13281 HIGH - 8.3

Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 25, 2026
Source: NVD