Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 821 - 840 of 12,942 CVEs
CVE-2026-46433 MEDIUM - 6.5

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be...

Vendor: lldpd
Product: lldpd
Published: Jun 09, 2026
Source: NVD
CVE-2026-47905 MEDIUM - 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue ...

Vendor: Adobe
Product: CAI Content Credentials
Published: Jun 09, 2026
Source: NVD
CVE-2026-47904 MEDIUM - 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue ...

Vendor: Adobe
Product: CAI Content Credentials
Published: Jun 09, 2026
Source: NVD
CVE-2026-47903 MEDIUM - 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user inte...

Vendor: Adobe
Product: CAI Content Credentials
Published: Jun 09, 2026
Source: NVD
CVE-2026-47902 MEDIUM - 6.2

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue ...

Vendor: Adobe
Product: CAI Content Credentials
Published: Jun 09, 2026
Source: NVD
CVE-2026-34657 MEDIUM - 5.5

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to wr...

Vendor: Adobe
Product: CAI Content Credentials
Published: Jun 09, 2026
Source: NVD
CVE-2026-34417 MEDIUM - 6.1

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious content through the project request parameter in oscal-forms.php. The parameter value is URL-decoded and assigned ...

Vendor: brian-ruf
Product: OSCAL-GUI
Published: Jun 09, 2026
Source: NVD
CVE-2026-25860 MEDIUM - 6.1

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaS...

Vendor: frankverbeke
Product: OpenClinic GA
Published: Jun 09, 2026
Source: NVD

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

Vendor: composer
Product: symfony/runtime
Published: Jun 09, 2026
Source: GitHub
CVE-2026-47961 MEDIUM - 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction ...

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 09, 2026
Source: NVD
CVE-2026-47933 MEDIUM - 4.8

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they brows...

Vendor: Adobe
Product: ColdFusion
Published: Jun 09, 2026
Source: NVD
CVE-2026-47926 MEDIUM - 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction ...

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 09, 2026
Source: NVD
CVE-2026-47925 MEDIUM - 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Explo...

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 09, 2026
Source: NVD
CVE-2026-47924 MEDIUM - 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in th...

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 09, 2026
Source: NVD
CVE-2026-47923 MEDIUM - 5.5

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction ...

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 09, 2026
Source: NVD
CVE-2026-34416 MEDIUM - 6.1

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious input through the project request parameter. Attackers can craft a malicious URL containing unsanitized input that...

Vendor: brian-ruf
Product: OSCAL-GUI
Published: Jun 09, 2026
Source: NVD
CVE-2026-25557 MEDIUM - 5.4

Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject...

Vendor: Evoluted
Product: PHP Directory Listing Script
Published: Jun 09, 2026
Source: NVD

Net::IMAP: Command Injection via ID command argument

Vendor: rubygems
Product: net-imap
Published: Jun 09, 2026
Source: GitHub
CVE-2026-47910 MEDIUM - 6.3

Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue r...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47909 MEDIUM - 6.3

Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD