Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,796
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,061 - 7,080 of 36,724 CVEs
CVE-2026-42671 MEDIUM - 6.5

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

Vendor: Paolo
Product: GeoDirectory
Published: Jun 01, 2026
Source: NVD
CVE-2026-38950 HIGH - 7.8

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.

Published: Jun 01, 2026
Source: NVD
CVE-2026-37227 HIGH - 7.5

FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port ...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37225 HIGH - 7.5

FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition field. The E42 layer decoder accepts this as valid, but the E2AP encoder asserts a non-empty constraint when forwarding the request. A remote unauthenticated attacker can crash the i...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37224 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry enforces node ID uniqueness via assert() rather than graceful rejection. A remote unauthenticated attacker can crash the iApp process (port 36421) by sending two E2_SETUP_REQUESTs w...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37223 HIGH - 7.5

FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP messages against a 9-entry whitelist using assert(). A remote unauthenticated attacker can send any decodable E2AP PDU with a message type not in the whitelist to crash the iApp proce...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37222 HIGH - 7.5

FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can send a valid E2AP PDU containing an unexpected number of IEs (e.g., an E2setupRequest with extra optional fields) to crash the near-RT RIC (port 36421)...

Published: Jun 01, 2026
Source: NVD
CVE-2026-10275 MEDIUM - 5.0

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attac...

Product: OpenSC
Published: Jun 01, 2026
Source: NVD
CVE-2026-10274 MEDIUM - 6.3

A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAssetMetadata of the file src/mcp-server.ts of the component Axios Request Flow. Executing a manipulation of the argument assetPath can lead to server-side ...

Vendor: indrasishbanerjee
Product: aem-mcp-server
Published: Jun 01, 2026
Source: NVD
CVE-2026-10273 HIGH - 7.3

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has ...

Product: php-censor
Published: Jun 01, 2026
Source: NVD
CVE-2026-10272 MEDIUM - 6.5

A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of the argument sid leads to improper authorization. It is possible to launch the attack re...

Vendor: a4m4
Product: Student-Management-System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10271 MEDIUM - 6.3

A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the component Admin Endpoint. This manipulation of the argument uid causes execution after redirect. It is possible to initiate th...

Vendor: a4m4
Product: Student-Management-System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10270 HIGH - 8.8

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public a...

Vendor: D-Link
Product: DI-7001 MINI
Published: Jun 01, 2026
Source: NVD
CVE-2026-10269 MEDIUM - 6.3

A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carri...

Vendor: decolua
Product: 9router
Published: Jun 01, 2026
Source: NVD

A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_fiber of the file src/core/marsh.c. Executing a manipulation can lead to integer overflow. It is possible to launch the attack on the local host. The exploit has been made available...

Vendor: janet-lang
Product: janet
Published: Jun 01, 2026
Source: NVD
CVE-2026-10118 HIGH - 7.8

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subseq...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images
Published: Jun 01, 2026
Source: NVD
CVE-2022-4991 HIGH - 7.4

Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate...

Published: Jun 01, 2026
Source: NVD

A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.

Published: Jun 01, 2026
Source: NVD
CVE-2026-48879 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

Vendor: Sergey
Product: AIWU
Published: Jun 01, 2026
Source: NVD
CVE-2026-48866 CRITICAL - 9.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

Vendor: Rocketgenius Inc.
Product: Gravity Forms
Published: Jun 01, 2026
Source: NVD