Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,764
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,961 - 6,980 of 36,728 CVEs
CVE-2025-22426 MEDIUM - 5.9

In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: Google
Product: Android
Published: Jun 01, 2026
Source: NVD
CVE-2025-22424 HIGH - 7.8

In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: Google
Product: Android
Published: Jun 01, 2026
Source: NVD
CVE-2019-25716 MEDIUM - 6.5

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the dev...

Vendor: Dräger
Product: Infinity Delta, Infinity Delta XL, Infinity Kappa
Published: Jun 01, 2026
Source: NVD
CVE-2018-25435 MEDIUM - 5.3

ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages tha...

Vendor: zeuscart
Product: ZeusCart
Published: Jun 01, 2026
Source: NVD
CVE-2018-25434 HIGH - 8.2

WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas_keys values to extract sensitive databa...

Vendor: eliekhoury
Product: WP AutoSuggest
Published: Jun 01, 2026
Source: NVD
CVE-2018-25433 HIGH - 8.2

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com...

Vendor: Joomlaextensions
Product: JE Photo Gallery
Published: Jun 01, 2026
Source: NVD
CVE-2018-25432 HIGH - 8.4

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exc...

Vendor: Armcode
Product: Arm Whois
Published: Jun 01, 2026
Source: NVD
CVE-2018-25431 HIGH - 7.1

No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious SQL code in the orde...

Vendor: goFrendiAsgard
Product: No-CMS
Published: Jun 01, 2026
Source: NVD
CVE-2018-25430 HIGH - 7.1

Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the eGeqIdEquipe parameter. Attackers can send GET requests to the egeq.php endpoint with crafted SQL payloads to extract sensitive databas...

Vendor: Paroiciel
Product: Paroiciel
Published: Jun 01, 2026
Source: NVD
CVE-2018-25429 HIGH - 7.1

Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the zProIdPro parameter. Attackers can send GET requests to zpro.php with crafted SQL payloads in the zProIdPro parameter to extract sensit...

Vendor: Paroiciel
Product: Paroiciel
Published: Jun 01, 2026
Source: NVD
CVE-2018-25428 HIGH - 8.2

Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter. Attackers can send GET requests to the trec.php endpoint with crafted SQL payloads to extract database informa...

Vendor: Paroiciel
Product: Paroiciel
Published: Jun 01, 2026
Source: NVD
CVE-2018-25427 CRITICAL - 9.8

Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception hand...

Vendor: Armcode
Product: Arm Whois
Published: Jun 01, 2026
Source: NVD
CVE-2026-5419 LOW - 3.7

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of in...

Published: Jun 01, 2026
Source: NVD
CVE-2026-49433 MEDIUM - 5.0

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20...

Vendor: DeepAI
Product: api.deepai.org
Published: Jun 01, 2026
Source: NVD
CVE-2026-49140 MEDIUM - 4.3

Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent ...

Vendor: HKUDS
Product: nanobot
Published: Jun 01, 2026
Source: NVD

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stor...

Vendor: HKUDS
Product: nanobot
Published: Jun 01, 2026
Source: NVD
CVE-2026-49138 MEDIUM - 5.0

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the au...

Vendor: HKUDS
Product: nanobot
Published: Jun 01, 2026
Source: NVD
CVE-2026-49136 HIGH - 7.5

Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to read arbitrary image-format files outside the intended uploads directory by exploiting an incomplete...

Vendor: Anionex
Product: banana-slides
Published: Jun 01, 2026
Source: NVD
CVE-2026-49135 HIGH - 7.1

CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the same host can read th...

Vendor: steipete
Product: CodexBar
Published: Jun 01, 2026
Source: NVD
CVE-2026-49134 HIGH - 7.1

CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a privileged shell paylo...

Vendor: steipete
Product: CodexBar
Published: Jun 01, 2026
Source: NVD