Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

980
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,681 - 7,700 of 35,345 CVEs
CVE-2026-48136 MEDIUM - 4.1

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions...

Vendor: checkpoint
Product: Quantum Security Management
Published: May 26, 2026
Source: NVD
CVE-2026-48135 MEDIUM - 5.3

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48134 HIGH - 7.6

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to...

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48133 HIGH - 7.5

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48132 HIGH - 7.4

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negot...

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48131 HIGH - 8.1

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2025-11482 HIGH - 7.5

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service.

Vendor: B&R Industrial Automation GmbH
Product: PPT30 Operating System
Published: May 26, 2026
Source: NVD

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

Vendor: ZTE
Product: ZXUniPOS NDS-LTE
Published: May 26, 2026
Source: NVD
CVE-2026-39661 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18.

Vendor: Magentech
Product: SW Core
Published: May 26, 2026
Source: NVD
CVE-2026-39642 MEDIUM - 5.3

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.

Vendor: SpabRice
Product: Nyla
Published: May 26, 2026
Source: NVD
CVE-2026-27427 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.

Vendor: Dylan Kuhn
Product: Geo Mashup
Published: May 26, 2026
Source: NVD
CVE-2026-25713 HIGH - 7.8

MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 26, 2026
Source: NVD
CVE-2026-25104 HIGH - 7.8

MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 26, 2026
Source: NVD
CVE-2026-24638 MEDIUM - 4.3

Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

Vendor: Webful Creations
Product: RepairBuddy
Published: May 26, 2026
Source: NVD
CVE-2026-24590 MEDIUM - 5.3

Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.

Vendor: VideoWhisper.com
Product: Paid Videochat Turnkey Site
Published: May 26, 2026
Source: NVD
CVE-2026-8047 HIGH - 7.5

The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.

Published: May 26, 2026
Source: NVD
CVE-2026-8046 HIGH - 8.1

The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.

Published: May 26, 2026
Source: NVD
CVE-2026-44469 HIGH - 7.8

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before insta...

Vendor: CODESYS
Product: CODESYS Development System
Published: May 26, 2026
Source: NVD
CVE-2026-44468 HIGH - 7.8

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary co...

Vendor: CODESYS
Product: CODESYS Development System
Published: May 26, 2026
Source: NVD
CVE-2026-39655 MEDIUM - 5.3

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

Vendor: TeconceTheme
Product: Mayosis Core
Published: May 26, 2026
Source: NVD