Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,649
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,421 - 6,440 of 36,815 CVEs
CVE-2026-5228 HIGH - 8.8

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.

Published: Jun 04, 2026
Source: NVD
CVE-2026-44393 HIGH - 7.4

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expecte...

Published: Jun 04, 2026
Source: NVD
CVE-2026-43986 CRITICAL - 9.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-43985 HIGH - 8.8

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In the default form and JWT-based authentication mode,...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-43984 HIGH - 8.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint writes attacker-controlled strings directly into the main application log. The ad...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-40930 MEDIUM - 5.4

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controll...

Vendor: pnggroup
Product: libpng, libpng-apng
Published: Jun 04, 2026
Source: NVD
CVE-2026-38570 HIGH - 7.5

bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36182 CRITICAL - 9.8

GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.

Published: Jun 04, 2026
Source: NVD

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craf...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10815 MEDIUM - 6.3

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. Th...

Vendor: LakshayD02
Product: Hostel-Management-System-PHP
Published: Jun 04, 2026
Source: NVD
CVE-2026-10814 MEDIUM - 4.5

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. The attack needs to be performed locally. The attac...

Vendor: milvus-io
Product: milvus
Published: Jun 04, 2026
Source: NVD

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level ...

Product: LMCache
Published: Jun 04, 2026
Source: NVD

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On a fresh install before the setup wizard is completed, all management endpoints are completely unaut...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-36180 MEDIUM - 4.6

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36178 MEDIUM - 4.6

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive user data.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36176 HIGH - 7.1

GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36175 MEDIUM - 6.8

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36174 MEDIUM - 4.6

GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers to obtain sensitive information, including network credentials, via monitoring the serial UART interface.

Published: Jun 04, 2026
Source: NVD
CVE-2026-35906 CRITICAL - 9.6

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HTTP query string.

Published: Jun 04, 2026
Source: NVD
CVE-2026-35905 CRITICAL - 9.8

T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.

Published: Jun 04, 2026
Source: NVD