Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 81 - 100 of 34,996 CVEs
CVE-2026-12781 HIGH - 7.8

A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly availabl...

Vendor: EaseUS
Product: Partition Master
Published: Jun 21, 2026
Source: NVD
CVE-2026-12780 HIGH - 7.8

A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed a...

Vendor: AOMEI
Product: Backupper
Published: Jun 21, 2026
Source: NVD
CVE-2026-12779 HIGH - 7.8

A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit h...

Vendor: AOMEI
Product: Dynamic Disk Manager
Published: Jun 21, 2026
Source: NVD
CVE-2026-12778 HIGH - 7.8

A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to ...

Vendor: AOMEI
Product: Partition Assistant
Published: Jun 21, 2026
Source: NVD
CVE-2026-12776 MEDIUM - 6.3

A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has bee...

Vendor: Montodel
Product: House-Rental-Management
Published: Jun 21, 2026
Source: NVD
CVE-2026-12775 HIGH - 7.3

A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The e...

Vendor: Montodel
Product: House-Rental-Management
Published: Jun 21, 2026
Source: NVD
CVE-2026-12774 MEDIUM - 6.3

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-si...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12773 HIGH - 7.3

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launche...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12772 MEDIUM - 6.3

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be initiated...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12771 MEDIUM - 5.0

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high complexity level is as...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12770 MEDIUM - 5.4

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remo...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

Vendor: GNU
Product: Savane
Published: Jun 20, 2026
Source: NVD
CVE-2026-56347 MEDIUM - 6.1

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped menu item fields that execute for all site visitor...

Vendor: WWBN
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56346 MEDIUM - 6.5

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can submit private keys, ciphertext, and passphrases to perform server-side decryption without credentials, ...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56345 HIGH - 8.1

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload ...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56342 MEDIUM - 6.8

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeURL() validation and accepts requests to private IP ranges and cloud metadata end...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56341 HIGH - 7.5

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreem...

Vendor: AVideo
Product: AVideo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56340 HIGH - 8.8

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor indices, when t...

Vendor: vLLM
Product: vLLM
Published: Jun 20, 2026
Source: NVD
CVE-2025-71379 MEDIUM - 4.3

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns โ€” in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible serving chat endpoint โ€” are susceptible to catastrophic backtracking. An attacke...

Vendor: vllm
Product: vllm
Published: Jun 20, 2026
Source: NVD
CVE-2026-5366 CRITICAL - 9.9

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git...

Published: Jun 20, 2026
Source: NVD