Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,621 - 6,640 of 36,724 CVEs
CVE-2026-41032 HIGH - 7.5

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

Vendor: Phoenix Contact
Product: CHARX SEC-3150, CHARX SEC-3100, CHARX SEC-3050, CHARX SEC-3000
Published: Jun 03, 2026
Source: NVD
CVE-2025-15656 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.

Vendor: Mojoomla
Product: School Management
Published: Jun 03, 2026
Source: NVD
CVE-2025-15655 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0.

Vendor: Mojoomla
Product: School Management
Published: Jun 03, 2026
Source: NVD
CVE-2025-14774 HIGH - 7.4

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Vendor: ABB
Product: T-MAC Plus
Published: Jun 03, 2026
Source: NVD
CVE-2025-14773 HIGH - 8.0

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Vendor: ABB
Product: T-MAC Plus
Published: Jun 03, 2026
Source: NVD
CVE-2025-14772 HIGH - 8.8

Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Vendor: ABB
Product: T-MAC Plus
Published: Jun 03, 2026
Source: NVD
CVE-2025-14771 CRITICAL - 9.9

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Vendor: ABB
Product: T-MAC Plus
Published: Jun 03, 2026
Source: NVD
CVE-2026-4035 CRITICAL - 9.1

A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in ...

Vendor: lfprojects
Product: mlflow
Published: Jun 03, 2026
Source: NVD
CVE-2025-15654 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8.

Vendor: Fox-themes
Product: Prague
Published: Jun 03, 2026
Source: NVD
CVE-2026-5078 MEDIUM - 5.3

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or L...

Vendor: morgan_project
Product: morgan
Published: Jun 03, 2026
Source: NVD

In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipul...

Vendor: The Vinyl Cache Project, Varnish Software
Product: Vinyl Cache, Varnish Cache (pre split), Varnish Cache by Varnish Software
Published: Jun 03, 2026
Source: NVD
CVE-2026-50031 HIGH - 7.5

ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management...

Vendor: FreeIPMI
Product: FreeIPMI
Published: Jun 03, 2026
Source: NVD

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is need...

Product: dask
Published: Jun 03, 2026
Source: NVD
CVE-2026-10704 HIGH - 7.3

A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can...

Vendor: SourceCodester
Product: Pizzafy E-Commerce System
Published: Jun 03, 2026
Source: NVD
CVE-2026-10703 MEDIUM - 6.3

A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData Handler. The manipulation leads to use after free. Remote exploitation of the attack is possible. Th...

Vendor: EIPStackGroup
Product: OpENer
Published: Jun 03, 2026
Source: NVD
CVE-2026-9516 HIGH - 7.5

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the norma...

Vendor: rurban
Product: cpanel\
Published: Jun 03, 2026
Source: NVD
CVE-2026-9334 HIGH - 7.3

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_R...

Vendor: rurban
Product: cpanel\
Published: Jun 03, 2026
Source: NVD
CVE-2026-10694 HIGH - 7.3

A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.

Vendor: SourceCodester
Product: Online Food Ordering System
Published: Jun 03, 2026
Source: NVD
CVE-2026-10693 MEDIUM - 6.3

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit ha...

Vendor: SourceCodester
Product: Online Boat Reservation System
Published: Jun 03, 2026
Source: NVD
CVE-2026-9732 MEDIUM - 4.3

The EmergencyWP โ€“ Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scop...

Published: Jun 03, 2026
Source: NVD