Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 861 - 880 of 12,942 CVEs
CVE-2026-41116 MEDIUM - 6.3

Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.

Vendor: Dell
Product: Inventory Collector Client
Published: Jun 09, 2026
Source: NVD
CVE-2026-34705 MEDIUM - 5.5

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a vi...

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-34704 MEDIUM - 5.5

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this iss...

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-34703 MEDIUM - 5.5

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this iss...

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-34694 MEDIUM - 5.9

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim...

Vendor: Adobe
Product: Adobe Experience Manager Forms JEE
Published: Jun 09, 2026
Source: NVD
CVE-2026-28237 MEDIUM - 5.5

Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.

Vendor: AMD
Product: AMD Β΅Prof
Published: Jun 09, 2026
Source: NVD
CVE-2026-0466 MEDIUM - 5.5

Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.

Vendor: amd
Product: uprof
Published: Jun 09, 2026
Source: NVD
CVE-2026-50508 MEDIUM - 6.5

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Published: Jun 09, 2026
Source: NVD
CVE-2026-50507 MEDIUM - 6.8

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-49958 MEDIUM - 5.0

Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete files outside the configured workspace boundary by replacing a validated path component with a symli...

Vendor: nesquena
Product: hermes-webui
Published: Jun 09, 2026
Source: NVD
CVE-2026-49956 MEDIUM - 6.5

Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Attackers can send requests to the sessions search handler to re...

Vendor: nesquena
Product: hermes-webui
Published: Jun 09, 2026
Source: NVD
CVE-2026-49955 MEDIUM - 5.3

Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. Attackers can send unlimited POST requests to the authentica...

Vendor: nesquena
Product: hermes-webui
Published: Jun 09, 2026
Source: NVD
CVE-2026-49848 MEDIUM - 4.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's check_auth userauth branch wrote request-supplied userVariables into the co...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49843 MEDIUM - 5.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's JSON-RPC handler bound the connection to the client-supplied sessid on the ...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49472 MEDIUM - 5.3

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in libs/xmlrpc-c/lib/expat/x...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-48566 MEDIUM - 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_11_24h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-48562 MEDIUM - 4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Jun 09, 2026
Source: NVD
CVE-2026-48560 MEDIUM - 5.4

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: sharepoint_server
Published: Jun 09, 2026
Source: NVD
CVE-2026-48304 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's ...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-48301 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's ...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Jun 09, 2026
Source: NVD