Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,053
Quick preset (or use dates below)
Clear Filters
Showing 1,321 - 1,340 of 13,384 CVEs
CVE-2026-25657 MEDIUM - 6.5

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the...

Vendor: Ericsson
Product: Packet Core Gateway (PCG)
Published: Jun 05, 2026
Source: NVD
CVE-2026-21028 MEDIUM - 5.5

Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21026 MEDIUM - 5.5

Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21025 MEDIUM - 5.5

Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21017 MEDIUM - 5.5

Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21826 MEDIUM - 6.1

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

Vendor: HCLSoftware
Product: Digital Experience & DX Compose
Published: Jun 05, 2026
Source: NVD
CVE-2026-21825 MEDIUM - 6.1

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

Vendor: HCLSoftware
Product: DX Compose
Published: Jun 05, 2026
Source: NVD
CVE-2026-10732 MEDIUM - 6.4

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written...

Product: decompress
Published: Jun 05, 2026
Source: NVD
CVE-2026-50592 MEDIUM - 6.4

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).

Vendor: Znuny
Product: Znuny
Published: Jun 05, 2026
Source: NVD
CVE-2026-50591 MEDIUM - 5.4

IN Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.

Vendor: Znuny
Product: Znuny
Published: Jun 05, 2026
Source: NVD
CVE-2026-50590 MEDIUM - 4.5

In Mimecast Incydr before 2.6.0, arbitrary file access can occur.

Vendor: Mimecast
Product: Incydr
Published: Jun 05, 2026
Source: NVD
CVE-2026-50589 MEDIUM - 5.3

In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

Vendor: OpenStack
Product: Ironic
Published: Jun 05, 2026
Source: NVD
CVE-2026-11309 MEDIUM - 4.3

Insufficient policy enforcement in History in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11308 MEDIUM - 6.3

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11302 MEDIUM - 4.3

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11300 MEDIUM - 4.3

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11299 MEDIUM - 6.5

Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11298 MEDIUM - 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11294 MEDIUM - 4.3

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11292 MEDIUM - 4.3

Insufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD