Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,978
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 121 - 140 of 34,601 CVEs
CVE-2026-44942 MEDIUM - 6.5

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

Vendor: SUSE
Product: libzypp
Published: Jun 18, 2026
Source: NVD
CVE-2026-42490 MEDIUM - 6.5

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these o...

Vendor: Xen
Product: Xen
Published: Jun 18, 2026
Source: NVD
CVE-2026-42489 MEDIUM - 5.3

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these o...

Vendor: Xen
Product: Xen
Published: Jun 18, 2026
Source: NVD
CVE-2026-42488 HIGH - 8.1

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between the loaded page-tables and the mapcache metadata which can lead to corruption of the mapcache.

Vendor: Xen
Product: Xen
Published: Jun 18, 2026
Source: NVD
CVE-2026-42487 HIGH - 7.9

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore nee...

Vendor: Xen
Product: Xen
Published: Jun 18, 2026
Source: NVD

A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netremap.php" modules where unsanitized GET parameters are directly embedded into HTML output. This allows an attacker to inject arbitrary ...

Vendor: LMS
Product: LMS
Published: Jun 18, 2026
Source: NVD

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the "exec()" function without proper validation, allowing attackers to execute arbitrary operating system commands.

Vendor: LMS
Product: LMS
Published: Jun 18, 2026
Source: NVD

An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" module due to insufficient sanitization of the POST "tg[]" parameter. The application directly concatenates user-supplied array values into an SQL query using &q...

Vendor: LMS
Product: LMS
Published: Jun 18, 2026
Source: NVD

Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat m...

Vendor: Docker
Product: Docker Sandboxes
Published: Jun 18, 2026
Source: NVD

A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time ...

Vendor: Shenzhen Liandian Communication Technology LTD
Product: V380 IP Camera / AppFHE1_V1.0.6.0
Published: Jun 18, 2026
Source: NVD

Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host resolver whenever the network is internet-connected, without consulting the policy. A workload inside a sandbox, which th...

Vendor: Docker
Product: Docker Sandboxes
Published: Jun 18, 2026
Source: NVD

Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access to the system, can place a malicious DLL in C:\Windows\Temp and wait for the application to be executed. Because DFIR-ORC is extracted and execut...

Vendor: ANSSI
Product: DFIR-ORC
Published: Jun 18, 2026
Source: NVD

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol version...

Vendor: Google
Product: MCP Toolbox for Databases (googleapis/mcp-toolbox)
Published: Jun 18, 2026
Source: NVD

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, t...

Vendor: Google
Product: MCP Toolbox for Databases (googleapis/mcp-toolbox)
Published: Jun 18, 2026
Source: NVD

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where...

Vendor: Google
Product: MCP Toolbox for Databases (googleapis/mcp-toolbox)
Published: Jun 18, 2026
Source: NVD
CVE-2026-55669 MEDIUM - 4.2

ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider

Vendor: go
Product: github.com/zitadel/zitadel
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55672 HIGH - 7.4

ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)

Vendor: go
Product: github.com/zitadel/zitadel
Published: Jun 18, 2026
Source: GitHub

SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.

Published: Jun 18, 2026
Source: NVD
CVE-2026-8039 MEDIUM - 6.4

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possibl...

Published: Jun 18, 2026
Source: NVD

8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compiler accepts attacker-controlled filename and line number metadata and later uses it without validation when accessing source line arrays. By supplying invalid or oversized line numbe...

Vendor: rui314
Product: 8cc
Published: Jun 18, 2026
Source: NVD