Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
Showing 1,721 - 1,740 of 13,389 CVEs
CVE-2026-35718 MEDIUM - 6.5

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request.

Vendor: vivotek
Product: fd8136_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-35716 MEDIUM - 6.3

A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/a...

Vendor: vivotek
Product: fd8136_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-34460 MEDIUM - 5.4

NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging the authorization code. This allows an attacker to capture a valid OAuth callback URL for their own account and cause a v...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD
CVE-2026-49782 MEDIUM - 5.4

Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0.

Vendor: Elementor
Product: Elementor Website Builder
Published: Jun 02, 2026
Source: NVD
CVE-2026-41918 MEDIUM - 5.7

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive da...

Vendor: Siemens
Product: RUGGEDCOM RST2428P
Published: Jun 02, 2026
Source: NVD
CVE-2026-35717 MEDIUM - 6.3

A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controll...

Vendor: vivotek
Product: fd8136_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-32250 MEDIUM - 4.3

NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queries/user/`. The application reflects user-supplied input from the id parameter into the HTML response ...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD
CVE-2026-28116 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0.

Vendor: Emilia Projects
Product: Progress Planner
Published: Jun 02, 2026
Source: NVD
CVE-2026-27351 MEDIUM - 5.4

Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.

Vendor: Sekander Badsha
Product: Crew HRM
Published: Jun 02, 2026
Source: NVD
CVE-2019-25717 MEDIUM - 4.3

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration deta...

Vendor: Dräger
Product: Infinity Delta, Infinity Delta XL, Infinity Kappa
Published: Jun 02, 2026
Source: NVD
CVE-2026-8993 MEDIUM - 6.5

D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side R...

Published: Jun 02, 2026
Source: NVD
CVE-2026-5422 MEDIUM - 6.8

A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling dir...

Vendor: jupyter
Product: jupyter_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-5191 MEDIUM - 5.4

The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

Published: Jun 02, 2026
Source: NVD
CVE-2026-46718 MEDIUM - 6.5

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Calcite
Published: Jun 02, 2026
Source: NVD
CVE-2026-41115 MEDIUM - 4.3

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This disc...

Vendor: Apache Software Foundation
Product: Apache Kafka
Published: Jun 02, 2026
Source: NVD
CVE-2025-53346 MEDIUM - 4.3

Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Core: from n/a through 2.3.3.

Vendor: ThimPress
Product: Thim Core
Published: Jun 02, 2026
Source: NVD
CVE-2025-53345 MEDIUM - 6.5

Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3.

Vendor: ThimPress
Product: Thim Core
Published: Jun 02, 2026
Source: NVD
CVE-2025-53302 MEDIUM - 5.3

Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Constructor: from n/a through 1.6.5.

Vendor: Anton Shevchuk
Product: Constructor
Published: Jun 02, 2026
Source: NVD
CVE-2025-52766 MEDIUM - 6.5

Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from n/a through 1.17.0.

Vendor: Printeers
Product: Printeers Print & Ship
Published: Jun 02, 2026
Source: NVD
CVE-2026-9730 MEDIUM - 4.3

The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify...

Published: Jun 02, 2026
Source: NVD