Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
Showing 1,681 - 1,700 of 12,883 CVEs
CVE-2026-45743 HIGH - 8.1

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do not verify that the requesting user owns the SSH session identified by `sessionId`. An authenticated attacker who knows or guess...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45291 HIGH - 7.5

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a bug in Network to close the paren...

Vendor: CloudburstMC
Product: Network
Published: Jun 05, 2026
Source: NVD
CVE-2026-45290 HIGH - 7.5

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a vulnerability in Network to stall...

Vendor: CloudburstMC
Product: Network
Published: Jun 05, 2026
Source: NVD
CVE-2026-36501 HIGH - 7.5

An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published: Jun 05, 2026
Source: NVD
CVE-2026-11344 HIGH - 7.3

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. Th...

Vendor: code-projects
Product: Vehicle Management System
Published: Jun 05, 2026
Source: NVD
CVE-2026-11342 HIGH - 7.3

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and ma...

Vendor: code-projects
Product: Hotel and Tourism Reservation System
Published: Jun 05, 2026
Source: NVD
CVE-2025-5088 HIGH - 8.3

An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authenticat...

Published: Jun 05, 2026
Source: NVD
CVE-2026-52878 HIGH - 7.5

Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-52880 HIGH - 7.5

klever-go: REST API slow-header connection exhaustion via Gin Engine.Run

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-52879 HIGH - 7.5

klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-48017 HIGH - 8.8

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no...

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47684 HIGH - 7.7

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed o...

Vendor: npm
Product: @sync-in/server
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47419 HIGH - 8.3

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Form View Redirect URL

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Row Comments

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47261 HIGH - 7.5

Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access control mechanism can be bypassed via the wasip2 descriptor.open-at or wasip1 path_open interfaces by ...

Vendor: rust
Product: wasmtime-wasi
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47249 HIGH - 7.5

Klever-Go KVM: Hash-array amplification in P2P resolver request handling

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-45726 HIGH - 7.6

Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService

Vendor: go
Product: github.com/siderolabs/omni
Published: Jun 05, 2026
Source: GitHub
CVE-2026-45720 HIGH - 7.0

Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token

Vendor: go
Product: github.com/siderolabs/omni
Published: Jun 05, 2026
Source: GitHub
CVE-2026-48095 HIGH - 8.8

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crash...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD