Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,215
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 121 - 140 of 230 CVEs
CVE-2026-28727 HIGH - 7.8

Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124.

Vendor: Acronis
Product: Acronis Cyber Protect 17, Acronis Cyber Protect Cloud Agent
Published: Mar 06, 2026
Source: NVD
CVE-2025-30413 MEDIUM - 4.4

Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

Vendor: Acronis
Product: Acronis Cyber Protect Cloud Agent, Acronis Cyber Protect 17
Published: Mar 06, 2026
Source: NVD
CVE-2025-11791 MEDIUM - 5.5

Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.

Vendor: Acronis
Product: Acronis Cyber Protect 17, Acronis Cyber Protect Cloud Agent
Published: Mar 06, 2026
Source: NVD
CVE-2025-11790 MEDIUM - 4.4

Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.

Vendor: Acronis
Product: Acronis Cyber Protect Cloud Agent
Published: Mar 06, 2026
Source: NVD
CVE-2026-30798 HIGH - 7.5

Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is a...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files flu...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source โ€” API endpoint handling hea...

Vendor: rustdesk-server-pro
Product: RustDesk Server Pro
Published: Mar 05, 2026
Source: NVD

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routine...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs and...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/flu...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files ...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

Improper Restriction of Excessive Authentication Attempts, Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Peer authentication, API login modules), rustdesk-server RustDesk Server (OSS)...

Vendor: rustdesk-server-pro, rustdesk-server
Product: RustDesk Server Pro, RustDesk Server (OSS)
Published: Mar 05, 2026
Source: NVD

Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Reusing Session IDs (aka Session Replay). Th...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_mediator.Rs, src/hbbs_http/sync...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program routine...

Published: Mar 05, 2026
Source: NVD

Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD
CVE-2026-28412 MEDIUM - 6.5

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server w...

Vendor: f
Product: textream
Published: Mar 02, 2026
Source: NVD
CVE-2026-28403 HIGH - 7.6

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same brow...

Vendor: f
Product: textream
Published: Mar 02, 2026
Source: NVD
CVE-2026-3102 MEDIUM - 6.3

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried...

Vendor: exiftool_project
Product: exiftool
Published: Feb 24, 2026
Source: NVD