Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,398
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 581 - 600 of 33,519 CVEs

The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 me...

Vendor: Wertheim GmbH
Product: Wertheim SafeController 5400 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)
Published: Jun 15, 2026
Source: NVD
CVE-2026-12057 HIGH - 8.6

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.

Vendor: Foxit Software Inc.
Product: Foxit AI
Published: Jun 15, 2026
Source: NVD
CVE-2026-50100 HIGH - 7.8

Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted ...

Vendor: Ricoh Company, Ltd., KONICA MINOLTA JAPAN, INC.
Product: Multiple printer drivers
Published: Jun 15, 2026
Source: NVD
CVE-2026-44188 MEDIUM - 5.3

A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they c...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2
Published: Jun 15, 2026
Source: NVD

Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions,...

Vendor: OpenSolution
Product: Quick.CMS
Published: Jun 15, 2026
Source: NVD
CVE-2026-9278 MEDIUM - 5.4

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against an...

Published: Jun 15, 2026
Source: NVD
CVE-2026-8935 CRITICAL - 9.8

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

Published: Jun 15, 2026
Source: NVD
CVE-2026-8386 MEDIUM - 5.3

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address an...

Published: Jun 15, 2026
Source: NVD
CVE-2026-8385 MEDIUM - 5.3

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, categ...

Published: Jun 15, 2026
Source: NVD
CVE-2026-12223 MEDIUM - 5.5

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection. The attack needs ...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12222 HIGH - 8.0

A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer overflow. The attack needs t...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12221 HIGH - 8.0

A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The attack needs to be app...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12220 HIGH - 8.0

A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the argument uid leads to stack-based buffer overflow. The attack ca...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12219 MEDIUM - 6.3

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. T...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12218 HIGH - 8.0

A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local netw...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12217 HIGH - 7.8

A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclos...

Vendor: DVDFab
Product: Virtual Drive
Published: Jun 15, 2026
Source: NVD
CVE-2026-12216 MEDIUM - 5.3

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of the argument count_instr can lead to memory corruption. The attack requires local access. The exploit has been made available to th...

Vendor: svaarala
Product: duktape
Published: Jun 15, 2026
Source: NVD
CVE-2026-12214 HIGH - 7.8

A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a...

Vendor: Qihoo
Product: 360 Total Security
Published: Jun 15, 2026
Source: NVD
CVE-2026-12213 MEDIUM - 4.3

A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function getAccountInfo of the file server/account/src/operations.ts of the component User Information Handler. The manipulation results in improper authorization. The attack may be launched r...

Vendor: hcengineering
Product: Huly Platform
Published: Jun 15, 2026
Source: NVD
CVE-2026-12212 MEDIUM - 4.3

A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of the file server/account/src/operations.ts of the component RPC Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has ...

Vendor: hcengineering
Product: Huly Platform
Published: Jun 15, 2026
Source: NVD