Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,381 - 6,400 of 36,778 CVEs
CVE-2026-46739 MEDIUM - 5.3

Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. The update_stats (used for updating counters) and gauge methods do not check that valu...

Vendor: COSIMO
Product: Net::Statsd
Published: Jun 04, 2026
Source: NVD
CVE-2025-67446 CRITICAL - 9.8

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and ...

Published: Jun 04, 2026
Source: NVD

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destinat...

Published: Jun 04, 2026
Source: NVD
CVE-2026-5228 HIGH - 8.8

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.

Published: Jun 04, 2026
Source: NVD
CVE-2026-44393 HIGH - 7.4

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expecte...

Published: Jun 04, 2026
Source: NVD
CVE-2026-43986 CRITICAL - 9.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-43985 HIGH - 8.8

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In the default form and JWT-based authentication mode,...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-43984 HIGH - 8.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint writes attacker-controlled strings directly into the main application log. The ad...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-40930 MEDIUM - 5.4

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controll...

Vendor: pnggroup
Product: libpng, libpng-apng
Published: Jun 04, 2026
Source: NVD
CVE-2026-38570 HIGH - 7.5

bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36182 CRITICAL - 9.8

GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.

Published: Jun 04, 2026
Source: NVD

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craf...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10815 MEDIUM - 6.3

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. Th...

Vendor: LakshayD02
Product: Hostel-Management-System-PHP
Published: Jun 04, 2026
Source: NVD
CVE-2026-10814 MEDIUM - 4.5

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. The attack needs to be performed locally. The attac...

Vendor: milvus-io
Product: milvus
Published: Jun 04, 2026
Source: NVD

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level ...

Product: LMCache
Published: Jun 04, 2026
Source: NVD

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On a fresh install before the setup wizard is completed, all management endpoints are completely unaut...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-36180 MEDIUM - 4.6

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36178 MEDIUM - 4.6

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive user data.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36176 HIGH - 7.1

GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36175 MEDIUM - 6.8

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments.

Published: Jun 04, 2026
Source: NVD