Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
Showing 1,601 - 1,620 of 13,384 CVEs
CVE-2026-49510 MEDIUM - 6.1

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47320 MEDIUM - 6.1

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47319 MEDIUM - 6.1

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47318 MEDIUM - 6.1

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-47306 MEDIUM - 6.1

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-10305 MEDIUM - 6.1

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Vendor: Samsung Open Source
Product: rlottie
Published: Jun 04, 2026
Source: NVD
CVE-2026-50212 MEDIUM - 6.5

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50206 MEDIUM - 6.8

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-49204 MEDIUM - 6.5

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-49192 MEDIUM - 5.4

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

Vendor: Acer
Product: Connect M6E 5G Portable WiFi Router
Published: Jun 04, 2026
Source: NVD
CVE-2026-50219 MEDIUM - 4.9

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,

Vendor: libexpat project
Product: libexpat
Published: Jun 04, 2026
Source: NVD
CVE-2026-10805 MEDIUM - 6.7

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD U...

Published: Jun 04, 2026
Source: NVD
CVE-2026-48681 MEDIUM - 5.9

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

Vendor: OpenStack
Product: Ironic
Published: Jun 04, 2026
Source: NVD
CVE-2026-44917 MEDIUM - 4.9

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

Vendor: OpenStack
Product: Ironic
Published: Jun 04, 2026
Source: NVD
CVE-2026-10597 MEDIUM - 5.3

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.

Vendor: ITPison
Product: OMICARD EDM
Published: Jun 04, 2026
Source: NVD
CVE-2026-8653 MEDIUM - 6.5

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m...

Published: Jun 04, 2026
Source: NVD
CVE-2026-7764 MEDIUM - 6.8

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a cr...

Published: Jun 04, 2026
Source: NVD
CVE-2026-8722 MEDIUM - 6.5

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

Vendor: team
Product: net\
Published: Jun 04, 2026
Source: NVD
CVE-2026-46447 MEDIUM - 5.8

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Vendor: OpenStack
Product: Ironic
Published: Jun 03, 2026
Source: NVD
CVE-2026-44022 MEDIUM - 5.5

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub