Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,501 - 1,520 of 34,868 CVEs
CVE-2026-12162 MEDIUM - 5.5

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-12161 HIGH - 8.8

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted altern...

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-9262 MEDIUM - 6.5

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9261 MEDIUM - 6.8

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9260 MEDIUM - 6.2

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9259 MEDIUM - 6.5

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9258 MEDIUM - 6.5

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_bo...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code executi...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD
CVE-2026-48723 HIGH - 7.8

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a sh...

Vendor: browserstack
Product: browserstack-cypress-cli
Published: Jun 15, 2026
Source: NVD

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body. In 'Elixir.GRPC.Server.Transc...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD
CVE-2026-12205 CRITICAL - 9.1

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same obj...

Vendor: TIMLEGGE
Product: Crypt::DSA
Published: Jun 15, 2026
Source: NVD

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial of service. HP is releasing software updates to mitigate these potential vulnerabilities.

Published: Jun 15, 2026
Source: NVD
CVE-2026-48714 CRITICAL - 9.1

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did n...

Vendor: i18next
Product: i18next-http-middleware
Published: Jun 15, 2026
Source: NVD
CVE-2026-48713 CRITICAL - 9.1

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configu...

Vendor: i18next
Product: i18next-fs-backend
Published: Jun 15, 2026
Source: NVD
CVE-2026-48157 MEDIUM - 6.1

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses HttpException::setTitle() and/or setDescription() to include untrusted/request-derived data in the error title or description (e.g. "No products fou...

Vendor: slimphp
Product: Slim
Published: Jun 15, 2026
Source: NVD
CVE-2026-12087 CRITICAL - 9.1

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-b...

Vendor: PEVANS
Product: Socket
Published: Jun 15, 2026
Source: NVD
CVE-2026-11832 CRITICAL - 9.1

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

Vendor: BIAFRA
Product: Dancer2::Plugin::Auth::OAuth
Published: Jun 15, 2026
Source: NVD
CVE-2026-9691 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

Published: Jun 15, 2026
Source: NVD