Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,430
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,041 - 1,060 of 11,951 CVEs
CVE-2026-46493 HIGH - 7.5

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes the issue.

Vendor: haxtheweb
Product: haxcms-php
Published: Jun 05, 2026
Source: NVD
CVE-2026-11401 HIGH - 8.0

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the acto...

Vendor: AWS
Product: AWS Advanced Go Wrapper
Published: Jun 05, 2026
Source: NVD
CVE-2026-11400 HIGH - 8.0

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the ac...

Vendor: AWS
Product: AWS Advanced JDBC Wrapper
Published: Jun 05, 2026
Source: NVD
CVE-2026-5415 HIGH - 8.8

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX handler relying solely on a nonce check (check_aja...

Published: Jun 05, 2026
Source: NVD
CVE-2026-5411 HIGH - 8.8

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability check in the save_ajax() function of the licensing module, com...

Published: Jun 05, 2026
Source: NVD
CVE-2026-46392 HIGH - 8.7

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...

Vendor: haxtheweb
Product: haxcms-php
Published: Jun 05, 2026
Source: NVD
CVE-2026-50733 HIGH - 8.8

Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll(...

Vendor: shd101wyy
Product: Markdown Preview Enhanced
Published: Jun 05, 2026
Source: NVD
CVE-2026-49493 HIGH - 8.8

Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled co...

Vendor: shd101wyy
Product: Markdown Preview Enhanced
Published: Jun 05, 2026
Source: NVD
CVE-2026-49492 HIGH - 8.8

Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - the diagram filename attribute, imported file paths, and the latex_engine code-chunk attribute. On Windows, a crafted mark...

Vendor: shd101wyy
Product: Markdown Preview Enhanced
Published: Jun 05, 2026
Source: NVD
CVE-2026-45749 HIGH - 8.1

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior to version 2.3.2 accept the account password as a sole authentication factor for MFA-critical ope...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45745 HIGH - 8.0

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacker to intercept and modify HTTPS traffic to the configured Te...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45743 HIGH - 8.1

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do not verify that the requesting user owns the SSH session identified by `sessionId`. An authenticated attacker who knows or guess...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45291 HIGH - 7.5

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a bug in Network to close the paren...

Vendor: CloudburstMC
Product: Network
Published: Jun 05, 2026
Source: NVD
CVE-2026-45290 HIGH - 7.5

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a vulnerability in Network to stall...

Vendor: CloudburstMC
Product: Network
Published: Jun 05, 2026
Source: NVD
CVE-2026-36501 HIGH - 7.5

An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published: Jun 05, 2026
Source: NVD
CVE-2026-11344 HIGH - 7.3

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. Th...

Vendor: code-projects
Product: Vehicle Management System
Published: Jun 05, 2026
Source: NVD
CVE-2026-11342 HIGH - 7.3

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and ma...

Vendor: code-projects
Product: Hotel and Tourism Reservation System
Published: Jun 05, 2026
Source: NVD
CVE-2025-5088 HIGH - 8.3

An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authenticat...

Published: Jun 05, 2026
Source: NVD
CVE-2026-52878 HIGH - 7.5

Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-52880 HIGH - 7.5

klever-go: REST API slow-header connection exhaustion via Gin Engine.Run

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub