Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,778
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,501 - 6,520 of 36,744 CVEs

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Vendor: NETAPP
Product: Active IQ Config Advisor
Published: Jun 03, 2026
Source: NVD
CVE-2026-10771 HIGH - 7.3

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request forger...

Vendor: crmeb
Product: crmeb_java
Published: Jun 03, 2026
Source: NVD

Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub

Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44180 CRITICAL - 9.8

Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44023 HIGH - 8.6

Docling Core: Unsafe remote filename resolution

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44019 HIGH - 8.1

Docling Core: Insufficient validation of image reference URIs

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-47214 HIGH - 7.1

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44022 MEDIUM - 5.5

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers could craft malic...

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44020 HIGH - 7.5

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard xml.sax.parseString() without protection against XML External Entity (XXE) attacks. An attacker could...

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44018 MEDIUM - 5.5

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GB...

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44016 HIGH - 8.2

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for rendering (rendering option by default deactivated), then the Playwright-based rend...

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-43980 MEDIUM - 6.3

malla: Stored XSS via Meshtastic node names in multiple frontend pages

Vendor: pip
Product: malla
Published: Jun 03, 2026
Source: GitHub
CVE-2026-41234 HIGH - 7.6

Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record l...

Vendor: composer
Product: froxlor/froxlor
Published: Jun 03, 2026
Source: GitHub
CVE-2026-40898 MEDIUM - 5.3

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique fie...

Vendor: go
Product: github.com/quic-go/quic-go
Published: Jun 03, 2026
Source: GitHub
CVE-2026-50033 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44682 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44609 HIGH - 7.3

Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This allows arbitrary external URLs to be configured as redirect tar...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 03, 2026
Source: NVD
CVE-2026-42061 HIGH - 7.3

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD