Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,804
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 661 - 680 of 36,708 CVEs
CVE-2026-46732 MEDIUM - 6.7

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to E...

Vendor: Dell
Product: Display and Peripheral Manager
Published: Jun 25, 2026
Source: NVD
CVE-2026-42390 MEDIUM - 5.3

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-42389 MEDIUM - 5.3

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-42388 MEDIUM - 5.9

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-42387 MEDIUM - 5.9

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-41120 CRITICAL - 9.8

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

Vendor: Dell
Product: Wyse Management Suite
Published: Jun 25, 2026
Source: NVD
CVE-2026-40012 MEDIUM - 5.3

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD

Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

Published: Jun 25, 2026
Source: NVD
CVE-2026-27366 HIGH - 7.5

Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

Vendor: MainWP
Product: MainWP Child
Published: Jun 25, 2026
Source: NVD

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 chall...

Vendor: Devolutions
Product: Server
Published: Jun 25, 2026
Source: NVD

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD
CVE-2026-40211 MEDIUM - 5.3

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory ...

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD
CVE-2026-40210 MEDIUM - 4.8

An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD
CVE-2026-40209 MEDIUM - 5.3

An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if...

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD
CVE-2026-33612 HIGH - 7.5

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-42005 MEDIUM - 4.3

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Vendor: PowerDNS
Product: Authoritative
Published: Jun 25, 2026
Source: NVD

"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed. This issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, o...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: Jun 25, 2026
Source: NVD

When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass. This vulnerability is similar to https://www.cve.org/CVERecord?id=CVE-2020-1957 https://www.cve.org/CVERecord , except that it affects the `shiro-guice`...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: Jun 25, 2026
Source: NVD