Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,266
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,501 - 1,520 of 33,692 CVEs
CVE-2026-22899 MEDIUM - 6.5

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6....

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2026-22893 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66281 HIGH - 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66280 HIGH - 7.2

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the f...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66279 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66273 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-62851 MEDIUM - 4.4

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License C...

Vendor: QNAP Systems Inc.
Product: License Center
Published: Jun 10, 2026
Source: NVD
CVE-2025-62850 HIGH - 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follow...

Vendor: QNAP Systems Inc.
Product: QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66276 CRITICAL - 9.8

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero, QuTScloud
Published: Jun 10, 2026
Source: NVD

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 ...

Vendor: QNAP Systems Inc.
Product: Notification Center
Published: Jun 10, 2026
Source: NVD
CVE-2026-46532 MEDIUM - 4.6

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd() in components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c). This issue has been ...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45542 HIGH - 7.1

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/pro...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45541 HIGH - 7.5

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the esp_http_server component. While parsing the client-supplied Sec-WebSocket-Protocol request...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45329 HIGH - 7.1

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only some of the caller-supplied pointer arguments, leaving input pointer arguments unchecked....

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45328 CRITICAL - 9.3

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware perip...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45160 MEDIUM - 6.5

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_options() in components/lwip/apps/dhcpserver/dhcpserver.c) shipped with ESP-IDF's lwIP component....

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigat...

Vendor: frappe
Product: lms
Published: Jun 10, 2026
Source: NVD

SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities in SimpleBLE. There is a stack overflow vulnerability in the dongl backend’s Protocol::simpleble_write function (local, caller-co...

Vendor: simpleble
Product: simpleble
Published: Jun 10, 2026
Source: NVD
CVE-2026-53675 MEDIUM - 4.3

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_chec...

Vendor: BuddyPress
Product: BuddyPress
Published: Jun 10, 2026
Source: NVD