Total CVEs

149,335

Critical Severity

4,787

High Severity

17,139

Last 7 Days

2,819
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 10,521 - 10,540 of 45,740 CVEs
CVE-2026-52673 MEDIUM - 6.5

SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component

Published: Jun 23, 2026
Source: NVD

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.

Vendor: Pegasystems
Product: Pega Infinity
Published: Jun 23, 2026
Source: NVD
CVE-2025-55639 MEDIUM - 6.5

GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

Published: Jun 23, 2026
Source: NVD

HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

Vendor: HCLSoftware
Product: Connections
Published: Jun 23, 2026
Source: NVD
CVE-2026-56815 HIGH - 7.4

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

Vendor: rasta-mouse
Product: pwnlift
Published: Jun 23, 2026
Source: NVD
CVE-2026-35019 HIGH - 8.1

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge ...

Vendor: NetComm Wireless Pty Ltd
Product: NF20MESH
Published: Jun 23, 2026
Source: NVD
CVE-2026-35018 HIGH - 8.8

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands as root by injecting shell metacharacters into the username JSON parameter processed by the dalStorage_addUserAc...

Vendor: NetComm Wireless Pty Ltd
Product: NF20MESH
Published: Jun 23, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custo...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 23, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the cron admin identity,...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 23, 2026
Source: NVD
CVE-2026-12969 MEDIUM - 5.3

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS z...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4
Published: Jun 23, 2026
Source: NVD

DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is in End Of Life phase and will not receive any updates. However, deleting info.php...

Vendor: DRIMO
Product: DRIMO CMS
Published: Jun 23, 2026
Source: NVD
CVE-2026-10609 MEDIUM - 6.8

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate S...

Vendor: Red Hat
Product: Logging Subsystem for Red Hat OpenShift
Published: Jun 23, 2026
Source: NVD
CVE-2026-56784 HIGH - 8.1

OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary alarm IDs. The removeAlarms() method in AlarmResourceImpl.java...

Vendor: openremote
Product: openremote
Published: Jun 23, 2026
Source: NVD
CVE-2026-56762 MEDIUM - 5.3

Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing invalid characters such as control characters (e.g. \r or \n) when an application passes a user-controlled cookie name. This can produce malformed Set-Cooki...

Vendor: Hono
Product: Hono
Published: Jun 23, 2026
Source: NVD
CVE-2026-56701 MEDIUM - 6.5

Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files. The application uses simplexml_load_string without disabling external entity loading, enabling attackers to inject XXE payloads ...

Vendor: Grav
Product: Grav
Published: Jun 23, 2026
Source: NVD

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 23, 2026
Source: NVD

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 23, 2026
Source: NVD

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 23, 2026
Source: NVD
CVE-2026-56322 HIGH - 7.5

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allowing attackers to enumerate private channels and leak version/config state. Unauthenticated attackers ...

Vendor: Capgo
Product: Capgo
Published: Jun 23, 2026
Source: NVD
CVE-2026-56315 CRITICAL - 9.8

picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files importing these unblocke...

Vendor: picklescan
Product: picklescan
Published: Jun 23, 2026
Source: NVD