Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 641 - 660 of 35,345 CVEs
CVE-2017-20254 HIGH - 8.2

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid parameter. Attackers can send GET requests to index.php with the option=com_userbench&view=detail&use...

Vendor: Gegabyte
Product: User Bench
Published: Jun 19, 2026
Source: NVD
CVE-2017-20253 HIGH - 8.2

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract s...

Vendor: Gegabyte
Product: My Projects
Published: Jun 19, 2026
Source: NVD
CVE-2017-20252 HIGH - 8.2

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname param...

Vendor: nextgeneditor
Product: NextGen Editor
Published: Jun 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog and replaces it with a new one while another thread is sending a...

Vendor: Linux
Product: Linux
Published: Jun 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus reported that vti6_init_net() does not set the netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0). Other similar tunnel drivers (...

Vendor: Linux
Product: Linux
Published: Jun 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be re-evaluated to ensure it is properly pinned as RW. Since the umem is hidden inside each driver'...

Vendor: Linux
Product: Linux
Published: Jun 19, 2026
Source: NVD

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` โ€” invoked from `__destruct()` and from a registered shutdown function โ€” calls `unlink()` on every entry with...

Vendor: pontedilana
Product: php-weasyprint
Published: Jun 19, 2026
Source: NVD
CVE-2026-21768 MEDIUM - 6.3

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.

Vendor: HCLSoftware
Product: Verse for Android
Published: Jun 19, 2026
Source: NVD
CVE-2025-71326 HIGH - 7.8

AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that exe...

Vendor: Avast
Product: AVAST Antivirus
Published: Jun 19, 2026
Source: NVD
CVE-2023-54353 HIGH - 7.8

Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Person...

Vendor: Personifyinc
Product: Chromacam
Published: Jun 19, 2026
Source: NVD
CVE-2022-50971 HIGH - 7.8

Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem pri...

Vendor: Malwarebytes
Product: Malwarebytes
Published: Jun 19, 2026
Source: NVD
CVE-2021-47985 HIGH - 7.8

Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts...

Vendor: Brother
Product: SAPSprint
Published: Jun 19, 2026
Source: NVD
CVE-2020-37254 HIGH - 7.8

Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.

Vendor: Wondershare
Product: PDFelement
Published: Jun 19, 2026
Source: NVD
CVE-2020-37253 HIGH - 7.8

Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.

Vendor: Winstep
Product: Winstep
Published: Jun 19, 2026
Source: NVD
CVE-2020-37252 HIGH - 7.8

Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSyst...

Vendor: Realtek
Product: Realtek Audio Service
Published: Jun 19, 2026
Source: NVD
CVE-2020-37251 HIGH - 7.8

RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service st...

Vendor: Real
Product: RealTimes Desktop Service
Published: Jun 19, 2026
Source: NVD
CVE-2020-37250 HIGH - 7.8

TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be executed during service ...

Vendor: Weird-Solutions
Product: TFTP Broadband
Published: Jun 19, 2026
Source: NVD
CVE-2019-25747 HIGH - 7.8

Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary c...

Vendor: Network-Inventory-Advisor
Product: Network Inventory Advisor
Published: Jun 19, 2026
Source: NVD
CVE-2016-20095 HIGH - 7.8

Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory...

Vendor: Matrix42
Product: Matrix42 Remote Control Host
Published: Jun 19, 2026
Source: NVD
CVE-2016-20094 HIGH - 7.8

AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application s...

Vendor: Anydesk
Product: AnyDesk
Published: Jun 19, 2026
Source: NVD