Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,642
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 121 - 140 of 36,344 CVEs

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certific...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permitted/excluded DNS name constraints could be accepted.

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may not be fully reduced modulo the field prime 2^255 - 19. This can leave the field element in a non-canonical form, producing an incorrect result from the sc...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

Published: Jun 25, 2026
Source: NVD

A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 TS file.

Published: Jun 25, 2026
Source: NVD
CVE-2026-57700 CRITICAL - 10.0

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

Vendor: Daan.dev
Product: OMGF Pro
Published: Jun 25, 2026
Source: NVD
CVE-2026-56790 HIGH - 7.3

CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. Attackers can deliver a crafted NMEA-2000 message with an out-of-range PGN value over CAN bus or N2K-ov...

Vendor: canboat
Product: canboat
Published: Jun 25, 2026
Source: NVD
CVE-2026-56789 MEDIUM - 6.5

RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger memory corruption by failing to clamp satellite count values from RINEX epoch headers. Attackers can craft malicious RINEX files declaring more than 64 satel...

Vendor: tomojitakasu
Product: RTKLIB
Published: Jun 25, 2026
Source: NVD
CVE-2026-56788 MEDIUM - 4.4

RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowing attackers to trigger denial of service. Crafted RINEX files with unknown observation types cause negative array indexing into the codepris table, re...

Vendor: tomojitakasu
Product: RTKLIB
Published: Jun 25, 2026
Source: NVD
CVE-2026-56787 MEDIUM - 6.5

RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:1446 that allows remote attackers to trigger a global buffer overflow via crafted RTCM3 SSR messages with attacker-controlled signal mode fields. Remote attackers can exploit this ...

Vendor: tomojitakasu
Product: RTKLIB
Published: Jun 25, 2026
Source: NVD
CVE-2026-56786 CRITICAL - 9.8

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can...

Vendor: tomojitakasu
Product: RTKLIB
Published: Jun 25, 2026
Source: NVD
CVE-2026-56779 MEDIUM - 6.4

MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by supplying unvalidated downloadCallbackUrl and download_url parameters. Attackers with default workspace USER role can ex...

Vendor: 1Panel-dev
Product: MaxKB
Published: Jun 25, 2026
Source: NVD
CVE-2026-56774 MEDIUM - 5.4

Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessions. Attackers can enumerate sequential sessio...

Vendor: kanboard
Product: kanboard
Published: Jun 25, 2026
Source: NVD
CVE-2026-56772 MEDIUM - 4.3

NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id values to access ano...

Vendor: samuelclay
Product: NewsBlur
Published: Jun 25, 2026
Source: NVD
CVE-2026-56771 HIGH - 8.5

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cl...

Vendor: samuelclay
Product: NewsBlur
Published: Jun 25, 2026
Source: NVD
CVE-2026-56770 HIGH - 7.5

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causi...

Vendor: schwehr
Product: libais
Published: Jun 25, 2026
Source: NVD
CVE-2026-56769 HIGH - 8.5

Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal serv...

Vendor: hcengineering
Product: platform
Published: Jun 25, 2026
Source: NVD
CVE-2026-56768 HIGH - 8.8

Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory tr...

Vendor: haiwen
Product: seahub
Published: Jun 25, 2026
Source: NVD
CVE-2026-56767 HIGH - 8.8

Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execu...

Vendor: getmaxun
Product: maxun
Published: Jun 25, 2026
Source: NVD