Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,009
Quick preset (or use dates below)
Clear Filters
Showing 861 - 880 of 13,341 CVEs
CVE-2026-32856 MEDIUM - 6.1

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in ...

Vendor: Ellucian
Product: Banner Self-Service
Published: Jun 09, 2026
Source: NVD
CVE-2026-40639 MEDIUM - 5.7

Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.

Published: Jun 09, 2026
Source: NVD
CVE-2026-39170 MEDIUM - 6.3

SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36798 MEDIUM - 6.5

Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSetDebugCfgr function via the enable, level, and module parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36778 MEDIUM - 4.9

Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameter of the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36777 MEDIUM - 6.5

Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the param_1 parameter of the formSetCfm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36773 MEDIUM - 6.5

Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the Go parameter of the ask_to_reboot function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36772 MEDIUM - 6.5

Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36728 MEDIUM - 5.4

A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a chat message.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36726 MEDIUM - 5.3

An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete arbitrary files via supplying directory traversal sequences.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36725 MEDIUM - 6.1

A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the notice_content parameter.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36724 MEDIUM - 6.5

An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:update permission to cause a Denial of Service (DoS) via manipulating the func field of scheduled tasks.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36722 MEDIUM - 5.4

An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.

Published: Jun 09, 2026
Source: NVD
CVE-2025-55659 MEDIUM - 6.5

A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 09, 2026
Source: NVD
CVE-2025-55658 MEDIUM - 6.5

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 09, 2026
Source: NVD
CVE-2025-55651 MEDIUM - 5.5

A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 09, 2026
Source: NVD
CVE-2023-43686 MEDIUM - 6.2

An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.

Published: Jun 09, 2026
Source: NVD

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

Vendor: rubygems
Product: net-imap
Published: Jun 09, 2026
Source: GitHub
CVE-2026-44275 MEDIUM - 6.3

Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write

Vendor: Dell
Product: Dell/Alienware Purchased Apps
Published: Jun 09, 2026
Source: NVD
CVE-2026-41116 MEDIUM - 6.3

Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.

Vendor: Dell
Product: Inventory Collector Client
Published: Jun 09, 2026
Source: NVD