Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,325
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,301 - 1,320 of 11,958 CVEs
CVE-2026-5228 HIGH - 8.8

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.

Published: Jun 04, 2026
Source: NVD
CVE-2026-44393 HIGH - 7.4

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expecte...

Published: Jun 04, 2026
Source: NVD
CVE-2026-43985 HIGH - 8.8

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In the default form and JWT-based authentication mode,...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-43984 HIGH - 8.9

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint writes attacker-controlled strings directly into the main application log. The ad...

Vendor: Tautulli
Product: Tautulli
Published: Jun 04, 2026
Source: NVD
CVE-2026-38570 HIGH - 7.5

bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.

Published: Jun 04, 2026
Source: NVD
CVE-2026-36176 HIGH - 7.1

GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.

Published: Jun 04, 2026
Source: NVD
CVE-2026-28318 HIGH - 7.5

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

Vendor: SolarWinds
Product: Serv-U
Published: Jun 04, 2026
Source: NVD
CVE-2026-10863 HIGH - 8.1

A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. Depending on how the value was p...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-45730 HIGH - 8.3

Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project

Vendor: go
Product: github.com/nuclio/nuclio
Published: Jun 04, 2026
Source: GitHub
CVE-2026-45337 HIGH - 7.6

Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending

Vendor: npm
Product: better-auth
Published: Jun 04, 2026
Source: GitHub
CVE-2026-44496 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who ca...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2026-44488 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios ...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2026-44487 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2025-59874 HIGH - 8.1

HCL Hive Telco Observability is affected by Β a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.

Vendor: HCL
Product: Hive
Published: Jun 04, 2026
Source: NVD
CVE-2025-46638 HIGH - 7.5

Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).

Vendor: Dell
Product: BSAFE SSL-J
Published: Jun 04, 2026
Source: NVD
CVE-2019-25745 HIGH - 8.2

WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious &#...

Vendor: jgwhite33
Product: Google Review Slider
Published: Jun 04, 2026
Source: NVD
CVE-2019-25737 HIGH - 7.2

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft...

Vendor: Screets
Product: Live Chat Unlimited
Published: Jun 04, 2026
Source: NVD
CVE-2019-25736 HIGH - 8.4

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe o...

Vendor: Labf
Product: LabF nfsAxe
Published: Jun 04, 2026
Source: NVD
CVE-2019-25735 HIGH - 8.4

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execu...

Vendor: Allplayer
Product: AllPlayer
Published: Jun 04, 2026
Source: NVD
CVE-2019-25733 HIGH - 8.4

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigg...

Vendor: nsauditor
Product: NetShareWatcher
Published: Jun 04, 2026
Source: NVD