Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
Showing 1,181 - 1,200 of 12,840 CVEs
CVE-2026-47911 HIGH - 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 09, 2026
Source: NVD
CVE-2026-11799 HIGH - 7.5

UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.

Vendor: Mozilla
Product: Focus for iOS, Klar for iOS
Published: Jun 09, 2026
Source: NVD
CVE-2025-71319 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF...

Vendor: image-size
Product: image-size
Published: Jun 09, 2026
Source: NVD
CVE-2026-48306 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-48305 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-47908 HIGH - 7.8

Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47907 HIGH - 8.2

Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue r...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47906 HIGH - 8.6

Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious f...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-34710 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-34709 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-11824 HIGH - 7.8

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attacke...

Vendor: SQLite
Product: SQLite
Published: Jun 09, 2026
Source: NVD
CVE-2026-11822 HIGH - 7.8

SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds r...

Vendor: SQLite
Product: SQLite
Published: Jun 09, 2026
Source: NVD
CVE-2026-8863 HIGH - 7.8

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating...

Published: Jun 09, 2026
Source: NVD
CVE-2026-39169 HIGH - 7.5

SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36823 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36822 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36821 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36820 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36819 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36818 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 09, 2026
Source: NVD