Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,368
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 101 - 120 of 3,181 CVEs
CVE-2026-53519 CRITICAL - 9.1

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admin-frontend asset request. The check uses strings.Ha...

Vendor: nezhahq
Product: nezha
Published: Jun 12, 2026
Source: NVD
CVE-2026-41157 CRITICAL - 9.8

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash. The software computes a required memory size from untrusted input, but i...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 12, 2026
Source: NVD
CVE-2026-28742 CRITICAL - 9.8

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, se...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-48558 CRITICAL - 10.0

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerab...

Vendor: SimpleHelp
Product: SimpleHelp
Published: Jun 12, 2026
Source: NVD
CVE-2026-44172 CRITICAL - 9.8

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections,...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-44170 CRITICAL - 9.8

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-50091 CRITICAL - 9.1

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H...

Vendor: Aqara
Product: com.lumiunited.aqarahome
Published: Jun 12, 2026
Source: NVD
CVE-2026-50090 CRITICAL - 9.3

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L...

Vendor: Aqara
Product: Cloud OAuth Authorization Endpoint
Published: Jun 12, 2026
Source: NVD
CVE-2026-50086 CRITICAL - 10.0

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Al...

Vendor: Aqara
Product: Aqara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-50084 CRITICAL - 9.6

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined...

Vendor: Aqara
Product: Cloud Production API
Published: Jun 12, 2026
Source: NVD
CVE-2026-50083 CRITICAL - 9.1

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, C...

Vendor: Aqara
Product: Aquara IAM/SSO Gateway
Published: Jun 12, 2026
Source: NVD
CVE-2026-6853 CRITICAL - 9.8

Improper restriction of excessive authentication attempts vulnerability in BaĹźbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile App: from v1.0.6 before v1.5.

Published: Jun 12, 2026
Source: NVD
CVE-2026-54133 CRITICAL - 9.8

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an a...

Vendor: jmespath
Product: jmespath.php
Published: Jun 12, 2026
Source: NVD
CVE-2026-53787 CRITICAL - 9.8

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint without authent...

Vendor: Amasty
Product: Order Attributes for Magento 2
Published: Jun 12, 2026
Source: NVD
CVE-2026-10557 CRITICAL - 9.8

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carryin...

Vendor: Yarbo
Product: Yarbo Android/IOS mobile application, Yarbo Cloud MQTT infrastructure
Published: Jun 12, 2026
Source: NVD
CVE-2026-11849 CRITICAL - 9.8

The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.

Vendor: IEI Integration Corp
Product: iRM-TSi410X
Published: Jun 12, 2026
Source: NVD
CVE-2026-50628 CRITICAL - 9.8

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1...

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-50627 CRITICAL - 9.1

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attac...

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-49875 CRITICAL - 9.8

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-48611 CRITICAL - 9.8

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

Vendor: phpBB
Product: phpBB
Published: Jun 12, 2026
Source: NVD