Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,381
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,521 - 1,540 of 33,519 CVEs
CVE-2025-52292 HIGH - 7.5

A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 09, 2026
Source: NVD
CVE-2023-43688 HIGH - 7.5

An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities.

Published: Jun 09, 2026
Source: NVD
CVE-2023-43686 MEDIUM - 6.2

An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.

Published: Jun 09, 2026
Source: NVD
CVE-2023-29146 HIGH - 8.2

The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a collidin...

Published: Jun 09, 2026
Source: NVD

Net::IMAP: Denial of Service via incomplete raw argument validation

Vendor: rubygems
Product: net-imap
Published: Jun 09, 2026
Source: GitHub

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

Vendor: rubygems
Product: net-imap
Published: Jun 09, 2026
Source: GitHub
CVE-2026-50636 HIGH - 8.8

The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values directly into a tid IN ('...') SQL clause without parameterization or input validation. A remote, authenticated ...

Vendor: LimeSurvey
Product: LimeSurvey
Published: Jun 09, 2026
Source: NVD
CVE-2026-50635 HIGH - 8.8

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation...

Vendor: LimeSurvey
Product: LimeSurvey
Published: Jun 09, 2026
Source: NVD
CVE-2026-50512 HIGH - 7.8

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: pc_manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-50511 HIGH - 7.8

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: pc_manager
Published: Jun 09, 2026
Source: NVD
CVE-2026-48293 HIGH - 7.8

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-44275 MEDIUM - 6.3

Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write

Vendor: Dell
Product: Dell/Alienware Purchased Apps
Published: Jun 09, 2026
Source: NVD
CVE-2026-41116 MEDIUM - 6.3

Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.

Vendor: Dell
Product: Inventory Collector Client
Published: Jun 09, 2026
Source: NVD
CVE-2026-34708 HIGH - 7.8

InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InCopy
Published: Jun 09, 2026
Source: NVD
CVE-2026-34707 HIGH - 7.8

InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InCopy
Published: Jun 09, 2026
Source: NVD
CVE-2026-34706 HIGH - 7.8

InCopy versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InCopy
Published: Jun 09, 2026
Source: NVD
CVE-2026-34705 MEDIUM - 5.5

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a vi...

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-34704 MEDIUM - 5.5

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this iss...

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-34703 MEDIUM - 5.5

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this iss...

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-34702 HIGH - 7.8

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InDesign Desktop
Published: Jun 09, 2026
Source: NVD