Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,339
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,321 - 1,340 of 11,967 CVEs
CVE-2026-44488 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios ...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2026-44487 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2025-59874 HIGH - 8.1

HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.

Vendor: HCL
Product: Hive
Published: Jun 04, 2026
Source: NVD
CVE-2025-46638 HIGH - 7.5

Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).

Vendor: Dell
Product: BSAFE SSL-J
Published: Jun 04, 2026
Source: NVD
CVE-2019-25745 HIGH - 8.2

WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious &#...

Vendor: jgwhite33
Product: Google Review Slider
Published: Jun 04, 2026
Source: NVD
CVE-2019-25737 HIGH - 7.2

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft...

Vendor: Screets
Product: Live Chat Unlimited
Published: Jun 04, 2026
Source: NVD
CVE-2019-25736 HIGH - 8.4

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe o...

Vendor: Labf
Product: LabF nfsAxe
Published: Jun 04, 2026
Source: NVD
CVE-2019-25735 HIGH - 8.4

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execu...

Vendor: Allplayer
Product: AllPlayer
Published: Jun 04, 2026
Source: NVD
CVE-2019-25733 HIGH - 8.4

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigg...

Vendor: nsauditor
Product: NetShareWatcher
Published: Jun 04, 2026
Source: NVD
CVE-2019-25732 HIGH - 8.2

PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the query parameter to ext...

Vendor: eitube
Product: EI-Tube
Published: Jun 04, 2026
Source: NVD
CVE-2019-25731 HIGH - 7.2

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST requests to /gmusic/zuzconso...

Vendor: Zuz
Product: Zuz Music
Published: Jun 04, 2026
Source: NVD
CVE-2019-25730 HIGH - 8.2

Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to ex...

Vendor: Themerig
Product: Listing Hub CMS
Published: Jun 04, 2026
Source: NVD
CVE-2019-25728 HIGH - 8.2

Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including login.php, indexframe.php,...

Vendor: care2x
Product: Care2x
Published: Jun 04, 2026
Source: NVD
CVE-2019-25726 HIGH - 8.2

All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id pa...

Vendor: Nicheoffice
Product: All in One Video Downloader
Published: Jun 04, 2026
Source: NVD
CVE-2026-44486 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios ...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2026-10843 HIGH - 7.2

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: Jun 04, 2026
Source: NVD
CVE-2025-52612 HIGH - 7.1

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .

Vendor: HCL
Product: iControl
Published: Jun 04, 2026
Source: NVD
CVE-2026-49771 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.

Vendor: 10Web
Product: Photo Gallery by 10Web
Published: Jun 04, 2026
Source: NVD
CVE-2026-50213 HIGH - 7.5

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50210 HIGH - 7.5

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD