Total CVEs

138,170

Critical Severity

3,538

High Severity

12,685

Last 7 Days

1,967
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,661 - 1,680 of 34,575 CVEs
CVE-2026-12207 MEDIUM - 4.3

A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatientById of the file app\modules\medical\port\rest\controllers\PatientController.php of the component HTTP REST API. The manipulation of the argument ID resul...

Vendor: medkey-org
Product: medkey
Published: Jun 15, 2026
Source: NVD
CVE-2026-12206 MEDIUM - 6.3

A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/backend/app/models/grit/assays/data_table_entity.rb. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The ex...

Vendor: Grit42
Product: Grit
Published: Jun 15, 2026
Source: NVD
CVE-2026-12204 HIGH - 7.3

A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a manipulation can lead to authorization bypass. The...

Product: ShopXO
Published: Jun 15, 2026
Source: NVD
CVE-2026-12203 MEDIUM - 5.3

A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible....

Vendor: HKUDS
Product: AI-Trader
Published: Jun 15, 2026
Source: NVD

A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS class name leads to cross site scripting. The attack may be launched remotely. The exploit has been disc...

Vendor: Intelliants
Product: Subrion CMS
Published: Jun 15, 2026
Source: NVD
CVE-2026-12201 MEDIUM - 5.3

A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit has been published and may be used. The vendor was contacted...

Vendor: IObit
Product: Malware Fighter
Published: Jun 15, 2026
Source: NVD
CVE-2026-12200 HIGH - 7.3

A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the library libeay32.dll.html of the component Header Handler. The manipulation of the argument Authorization leads to stack-based buffer overflow. The attack can be initiate...

Vendor: Ritlabs
Product: TinyWeb Server
Published: Jun 15, 2026
Source: NVD
CVE-2026-12198 HIGH - 7.3

A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to launch the attack rem...

Product: Microweber
Published: Jun 15, 2026
Source: NVD
CVE-2026-12197 HIGH - 7.2

A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of the component JSON-RPC Diagnose Endpoint. Performing a manipulation of the argument params.target results in command injection. It is possible to init...

Vendor: Ruijie
Product: EG105G-P
Published: Jun 15, 2026
Source: NVD
CVE-2026-12193 HIGH - 7.8

A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publ...

Vendor: VS Revo
Product: RevoUninstaller
Published: Jun 15, 2026
Source: NVD
CVE-2026-12192 HIGH - 8.8

A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This manipulation causes buffer overflow. The attack is only possible within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early...

Vendor: GALAYOU
Product: Y4
Published: Jun 15, 2026
Source: NVD
CVE-2026-12191 HIGH - 7.8

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted e...

Vendor: Comma AI
Product: Openpilot
Published: Jun 14, 2026
Source: NVD
CVE-2026-12190 MEDIUM - 5.3

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. T...

Vendor: Genspark
Product: AI Workspace App
Published: Jun 14, 2026
Source: NVD
CVE-2026-12189 MEDIUM - 5.3

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper authorization in handler for custom url scheme. The attack can only be executed locally. The exploit has been publi...

Vendor: Moovit
Product: Bus & Public Transit App
Published: Jun 14, 2026
Source: NVD
CVE-2026-12188 MEDIUM - 6.3

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/controllers/concerns/grit/core/grit_entity_controller.rb of the component GritEntityController. Performing a manipulation results in sql injection. The ...

Vendor: Grit42
Product: Grit
Published: Jun 14, 2026
Source: NVD
CVE-2026-12187 HIGH - 8.8

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched re...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 14, 2026
Source: NVD
CVE-2026-12186 HIGH - 8.8

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit ...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 14, 2026
Source: NVD
CVE-2026-54413 HIGH - 8.2

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-by...

Vendor: driftregion
Product: iso14229
Published: Jun 14, 2026
Source: NVD
CVE-2026-54412 HIGH - 8.2

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - ...

Vendor: LiamBindle
Product: MQTT-C
Published: Jun 14, 2026
Source: NVD
CVE-2026-54411 MEDIUM - 5.9

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to reco...

Vendor: Linux-PAM
Product: Linux-PAM
Published: Jun 14, 2026
Source: NVD