Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,647
Quick preset (or use dates below)
Clear Filters
Showing 1,661 - 1,680 of 13,389 CVEs
CVE-2026-20233 MEDIUM - 6.1

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability...

Vendor: Cisco
Product: Cisco Webex Meetings
Published: Jun 03, 2026
Source: NVD
CVE-2026-20175 MEDIUM - 6.1

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input ...

Vendor: Cisco
Product: Cisco Finesse
Published: Jun 03, 2026
Source: NVD
CVE-2025-71314 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Recover from panthor_gpu_flush_caches() failures We have seen a few cases where the whole memory subsystem is blocked and flush operations never complete. When that happens, we want to: - schedule a reset, so we can ...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2025-71313 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL check for alloc_workqueue() alloc_workqueue() can return NULL on memory allocation failure. Without proper error checking, this may lead to a NULL pointer dereference when queue_work() is later call...

Vendor: Linux
Product: Linux
Published: Jun 03, 2026
Source: NVD
CVE-2019-25720 MEDIUM - 6.5

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed network packet. Attackers can repeatedly send such malformed packets...

Vendor: Dräger
Product: SC 6002XL, SC6802XL, SC 7000, SC8000, SC90000 XL
Published: Jun 03, 2026
Source: NVD
CVE-2026-6657 MEDIUM - 6.1

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the start of the string. Thi...

Published: Jun 03, 2026
Source: NVD

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-site scripting. An attacker could conduct a targeted phish...

Vendor: Laravel-Backpack
Product: CRUD
Published: Jun 03, 2026
Source: NVD
CVE-2026-44545 MEDIUM - 5.3

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory cons...

Vendor: djangoproject
Product: daphne
Published: Jun 03, 2026
Source: NVD
CVE-2025-70101 MEDIUM - 6.5

An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before p...

Vendor: gkostka
Product: lwext4
Published: Jun 03, 2026
Source: NVD
CVE-2025-70100 MEDIUM - 5.5

A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount...

Vendor: gkostka
Product: lwext4
Published: Jun 03, 2026
Source: NVD
CVE-2025-60477 MEDIUM - 5.0

A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

Published: Jun 03, 2026
Source: NVD
CVE-2024-47273 MEDIUM - 4.3

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.

Vendor: Synology
Product: Hyper Backup
Published: Jun 03, 2026
Source: NVD
CVE-2024-47263 MEDIUM - 4.1

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive ...

Vendor: Synology
Product: Hyper Backup
Published: Jun 03, 2026
Source: NVD
CVE-2023-52951 MEDIUM - 5.9

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

Vendor: Synology
Product: Synology Note Station Client
Published: Jun 03, 2026
Source: NVD
CVE-2026-5078 MEDIUM - 5.3

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or L...

Vendor: morgan_project
Product: morgan
Published: Jun 03, 2026
Source: NVD
CVE-2026-10703 MEDIUM - 6.3

A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData Handler. The manipulation leads to use after free. Remote exploitation of the attack is possible. Th...

Vendor: EIPStackGroup
Product: OpENer
Published: Jun 03, 2026
Source: NVD
CVE-2026-10693 MEDIUM - 6.3

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit ha...

Vendor: SourceCodester
Product: Online Boat Reservation System
Published: Jun 03, 2026
Source: NVD
CVE-2026-9732 MEDIUM - 4.3

The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scop...

Published: Jun 03, 2026
Source: NVD
CVE-2026-7421 MEDIUM - 4.4

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient ...

Published: Jun 03, 2026
Source: NVD
CVE-2026-10692 MEDIUM - 4.3

A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument regex can lead to inefficient regular expression complexity. It is possible to launch the attack ...

Vendor: johnhuang316
Product: code-index-mcp
Published: Jun 03, 2026
Source: NVD