Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,285
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,581 - 1,600 of 11,967 CVEs
CVE-2026-8501 HIGH - 7.8

Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit thi...

Published: Jun 01, 2026
Source: NVD
CVE-2026-46243 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, users...

Vendor: Linux
Product: Linux
Published: Jun 01, 2026
Source: NVD
CVE-2026-45156 HIGH - 8.1

Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0,...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-42678 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.

Vendor: Liquid Web / StellarWP
Product: GiveWP
Published: Jun 01, 2026
Source: NVD
CVE-2026-42677 HIGH - 7.5

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

Vendor: Ben Balter
Product: WP Document Revisions
Published: Jun 01, 2026
Source: NVD
CVE-2026-42675 HIGH - 7.3

Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.

Vendor: Themefic
Product: Hydra Booking
Published: Jun 01, 2026
Source: NVD
CVE-2026-42674 HIGH - 7.5

Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.

Vendor: AAM Plugin
Product: Advanced Access Manager
Published: Jun 01, 2026
Source: NVD
CVE-2026-42673 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logt...

Vendor: Logtivity Activity Logs
Product: Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
Published: Jun 01, 2026
Source: NVD
CVE-2026-38950 HIGH - 7.8

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.

Published: Jun 01, 2026
Source: NVD
CVE-2026-37227 HIGH - 7.5

FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port ...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37225 HIGH - 7.5

FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition field. The E42 layer decoder accepts this as valid, but the E2AP encoder asserts a non-empty constraint when forwarding the request. A remote unauthenticated attacker can crash the i...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37224 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry enforces node ID uniqueness via assert() rather than graceful rejection. A remote unauthenticated attacker can crash the iApp process (port 36421) by sending two E2_SETUP_REQUESTs w...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37223 HIGH - 7.5

FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP messages against a 9-entry whitelist using assert(). A remote unauthenticated attacker can send any decodable E2AP PDU with a message type not in the whitelist to crash the iApp proce...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37222 HIGH - 7.5

FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can send a valid E2AP PDU containing an unexpected number of IEs (e.g., an E2setupRequest with extra optional fields) to crash the near-RT RIC (port 36421)...

Published: Jun 01, 2026
Source: NVD
CVE-2026-10273 HIGH - 7.3

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has ...

Product: php-censor
Published: Jun 01, 2026
Source: NVD
CVE-2026-10270 HIGH - 8.8

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public a...

Vendor: D-Link
Product: DI-7001 MINI
Published: Jun 01, 2026
Source: NVD
CVE-2026-10118 HIGH - 7.8

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subseq...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images
Published: Jun 01, 2026
Source: NVD
CVE-2022-4991 HIGH - 7.4

Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate...

Published: Jun 01, 2026
Source: NVD
CVE-2026-48865 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6.

Vendor: ThimPress
Product: LearnPress
Published: Jun 01, 2026
Source: NVD
CVE-2026-48839 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

Vendor: VeronaLabs
Product: WP Statistics
Published: Jun 01, 2026
Source: NVD