Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,661 - 1,680 of 13,053 CVEs
CVE-2026-10805 MEDIUM - 6.7

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD U...

Published: Jun 04, 2026
Source: NVD
CVE-2026-48681 MEDIUM - 5.9

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

Vendor: OpenStack
Product: Ironic
Published: Jun 04, 2026
Source: NVD
CVE-2026-44917 MEDIUM - 4.9

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

Vendor: OpenStack
Product: Ironic
Published: Jun 04, 2026
Source: NVD
CVE-2026-10597 MEDIUM - 5.3

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.

Vendor: ITPison
Product: OMICARD EDM
Published: Jun 04, 2026
Source: NVD
CVE-2026-8653 MEDIUM - 6.5

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m...

Published: Jun 04, 2026
Source: NVD
CVE-2026-7764 MEDIUM - 6.8

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a cr...

Published: Jun 04, 2026
Source: NVD
CVE-2026-8722 MEDIUM - 6.5

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

Vendor: team
Product: net\
Published: Jun 04, 2026
Source: NVD
CVE-2026-46447 MEDIUM - 5.8

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Vendor: OpenStack
Product: Ironic
Published: Jun 03, 2026
Source: NVD
CVE-2026-44022 MEDIUM - 5.5

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44018 MEDIUM - 5.5

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-43980 MEDIUM - 6.3

malla: Stored XSS via Meshtastic node names in multiple frontend pages

Vendor: pip
Product: malla
Published: Jun 03, 2026
Source: GitHub
CVE-2026-40898 MEDIUM - 5.3

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique fie...

Vendor: go
Product: github.com/quic-go/quic-go
Published: Jun 03, 2026
Source: GitHub
CVE-2026-37700 MEDIUM - 4.1

Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page

Published: Jun 03, 2026
Source: NVD
CVE-2026-26825 MEDIUM - 5.3

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lea...

Vendor: libxls_project
Product: libxls
Published: Jun 03, 2026
Source: NVD
CVE-2026-26824 MEDIUM - 6.5

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed by ole2_validate_sector_chain(), which may result in application...

Vendor: libxls_project
Product: libxls
Published: Jun 03, 2026
Source: NVD
CVE-2026-45702 MEDIUM - 4.4

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior to version 4.11.0, a type confusion vulnerability exists in OP-TEE OS when processing an FFA_MEM_SHARE...

Vendor: OP-TEE
Product: optee_os
Published: Jun 03, 2026
Source: NVD
CVE-2026-45614 MEDIUM - 4.7

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of the ECDH shared secret paths, the public key isn't verified to be a point on the correct curve. B...

Vendor: OP-TEE
Product: optee_os
Published: Jun 03, 2026
Source: NVD
CVE-2026-26379 MEDIUM - 6.5

Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.

Vendor: koha
Product: koha
Published: Jun 03, 2026
Source: NVD
CVE-2026-26378 MEDIUM - 5.4

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features

Vendor: koha
Product: koha
Published: Jun 03, 2026
Source: NVD
CVE-2026-46272 MEDIUM - 4.7

In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysfs and perf mode When trying to run perf and sysfs mode simultaneously, the WARN_ON() in tmc_etr_enable_hw() is triggered sometimes: WARNING: CPU: 42 PID: 3911571 at drivers/hwtr...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD