Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,288
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,401 - 1,420 of 11,967 CVEs
CVE-2026-36574 HIGH - 7.8

A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.

Published: Jun 03, 2026
Source: NVD
CVE-2026-5241 HIGH - 8.0

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, i...

Vendor: huggingface
Product: transformers
Published: Jun 03, 2026
Source: NVD
CVE-2026-37460 HIGH - 7.5

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Published: Jun 03, 2026
Source: NVD
CVE-2022-49042 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Hyper Backup Explorer
Published: Jun 03, 2026
Source: NVD
CVE-2022-49036 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Active Backup for Business Recovery Media Creator
Published: Jun 03, 2026
Source: NVD
CVE-2026-35085 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35084 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35083 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35082 HIGH - 8.8

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35081 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35080 HIGH - 8.1

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35079 HIGH - 8.1

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35078 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35077 HIGH - 8.1

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35076 HIGH - 8.1

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-41032 HIGH - 7.5

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

Vendor: Phoenix Contact
Product: CHARX SEC-3150, CHARX SEC-3100, CHARX SEC-3050, CHARX SEC-3000
Published: Jun 03, 2026
Source: NVD
CVE-2025-15656 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.

Vendor: Mojoomla
Product: School Management
Published: Jun 03, 2026
Source: NVD
CVE-2025-15655 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0.

Vendor: Mojoomla
Product: School Management
Published: Jun 03, 2026
Source: NVD
CVE-2025-14774 HIGH - 7.4

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Vendor: ABB
Product: T-MAC Plus
Published: Jun 03, 2026
Source: NVD
CVE-2025-14773 HIGH - 8.0

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Vendor: ABB
Product: T-MAC Plus
Published: Jun 03, 2026
Source: NVD