Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,434
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 981 - 1,000 of 11,951 CVEs
CVE-2026-34355 HIGH - 7.5

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-34194 HIGH - 7.1

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation. The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled acro...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 08, 2026
Source: NVD
CVE-2026-22164 HIGH - 7.5

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. By creating resources of certain types and presenting a set of parameters to the affected interface the exploit can be used to corrupt kernel memory.

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 08, 2026
Source: NVD
CVE-2026-11528 HIGH - 8.8

A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow. The attack may be launched remotely. Th...

Vendor: Tenda
Product: AC18
Published: Jun 08, 2026
Source: NVD
CVE-2026-11524 HIGH - 8.8

A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow. The attack may be in...

Vendor: Tenda
Product: W20E
Published: Jun 08, 2026
Source: NVD
CVE-2026-11523 HIGH - 8.8

A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The e...

Vendor: Tenda
Product: W20E
Published: Jun 08, 2026
Source: NVD
CVE-2026-11522 HIGH - 8.8

A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The explo...

Vendor: Tenda
Product: W20E
Published: Jun 08, 2026
Source: NVD
CVE-2026-49235 HIGH - 7.5

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD
CVE-2026-49234 HIGH - 7.5

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD
CVE-2026-49233 HIGH - 7.5

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

Vendor: NLnet Labs
Product: Routinator
Published: Jun 08, 2026
Source: NVD
CVE-2026-36789 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 08, 2026
Source: NVD
CVE-2026-11517 HIGH - 8.8

A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of the argument GroupName can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly dis...

Vendor: UTT
Product: HiPER 2610G
Published: Jun 08, 2026
Source: NVD
CVE-2026-11577 HIGH - 7.2

A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm administrator by importi...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7
Published: Jun 08, 2026
Source: NVD
CVE-2026-50752 HIGH - 7.4

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow ...

Vendor: checkpoint
Product: Quantum Security Gateway, Spark Firewalls
Published: Jun 08, 2026
Source: NVD
CVE-2026-11504 HIGH - 8.8

A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer ove...

Vendor: Tenda
Product: CX12L
Published: Jun 08, 2026
Source: NVD
CVE-2026-11503 HIGH - 8.8

A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set of the component Wi-Fi Configuration Endpoint. Such manipulation of the argument ssid leads to stack-based buffer overflow....

Vendor: Tenda
Product: CX12L
Published: Jun 08, 2026
Source: NVD
CVE-2026-11501 HIGH - 7.3

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=save_patient. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-41724 HIGH - 8.0

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

Vendor: VMware
Product: VCF operations, VMware Aria Operations, VMware Telco Cloud Platform
Published: Jun 08, 2026
Source: NVD
CVE-2026-41723 HIGH - 8.0

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

Vendor: VMware
Product: VCF operations, VMware Aria Operations, VMware Telco Cloud Platform
Published: Jun 08, 2026
Source: NVD
CVE-2026-41722 HIGH - 8.0

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

Vendor: VMware
Product: VCF operations, VMware Aria Operations, VMware Telco Cloud Platform
Published: Jun 08, 2026
Source: NVD