Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,257
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,461 - 5,480 of 35,861 CVEs
CVE-2026-49941 HIGH - 7.5

Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit net...

Vendor: RRWO
Product: Net::CIDR::Set
Published: Jun 04, 2026
Source: NVD
CVE-2026-49940 MEDIUM - 6.5

Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This could allow network masks to accept larger networks.

Vendor: RRWO
Product: Net::CIDR::Set
Published: Jun 04, 2026
Source: NVD
CVE-2026-46741 HIGH - 7.5

Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that the git repository contains an unreleased version with the ...

Vendor: SANBEG
Product: Etsy::StatsD
Published: Jun 04, 2026
Source: NVD
CVE-2026-46739 MEDIUM - 5.3

Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. The update_stats (used for updating counters) and gauge methods do not check that valu...

Vendor: COSIMO
Product: Net::Statsd
Published: Jun 04, 2026
Source: NVD
CVE-2025-67446 CRITICAL - 9.8

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and ...

Published: Jun 04, 2026
Source: NVD

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destinat...

Published: Jun 04, 2026
Source: NVD
CVE-2026-5228 HIGH - 8.8

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.

Published: Jun 04, 2026
Source: NVD
CVE-2026-44393 HIGH - 7.4

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expecte...

Published: Jun 04, 2026
Source: NVD
CVE-2026-43986 CRITICAL - 9.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-43985 HIGH - 8.8

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In the default form and JWT-based authentication mode,...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-43984 HIGH - 8.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint writes attacker-controlled strings directly into the main application log. The ad...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-40930 MEDIUM - 5.4

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controll...

Vendor: pnggroup
Product: libpng, libpng-apng
Published: Jun 04, 2026
Source: NVD
CVE-2026-38570 HIGH - 7.5

bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36182 CRITICAL - 9.8

GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.

Published: Jun 04, 2026
Source: NVD

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craf...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10815 MEDIUM - 6.3

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. Th...

Vendor: LakshayD02
Product: Hostel-Management-System-PHP
Published: Jun 04, 2026
Source: NVD
CVE-2026-10814 MEDIUM - 4.5

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. The attack needs to be performed locally. The attac...

Vendor: milvus-io
Product: milvus
Published: Jun 04, 2026
Source: NVD

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level ...

Product: LMCache
Published: Jun 04, 2026
Source: NVD

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On a fresh install before the setup wizard is completed, all management endpoints are completely unaut...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-36180 MEDIUM - 4.6

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack.

Published: Jun 04, 2026
Source: NVD