Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,994
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,741 - 1,760 of 12,353 CVEs
CVE-2026-41859 HIGH - 7.8

A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_ap...

Vendor: Cloud Foundry Foundation
Product: BOSH
Published: Jun 04, 2026
Source: NVD
CVE-2026-41858 HIGH - 7.5

Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely t...

Vendor: Cloud Foundry Foundation
Product: windows-utilities-release
Published: Jun 04, 2026
Source: NVD
CVE-2026-41011 HIGH - 8.2

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Ex...

Vendor: Cloud Foundry Foundation
Product: BOSH
Published: Jun 04, 2026
Source: NVD
CVE-2026-10737 HIGH - 7.5

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated attackers to read file metadata and obtain download links...

Vendor: smartypants
Product: SP Project & Document Manager
Published: Jun 04, 2026
Source: NVD
CVE-2026-10777 HIGH - 7.3

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component Administrative Backend. Such manipulation leads to improper authentication. The att...

Vendor: ealpha072
Product: Student-Management-System
Published: Jun 03, 2026
Source: NVD
CVE-2026-10771 HIGH - 7.3

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request forger...

Vendor: crmeb
Product: crmeb_java
Published: Jun 03, 2026
Source: NVD
CVE-2026-44023 HIGH - 8.6

Docling Core: Unsafe remote filename resolution

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44019 HIGH - 8.1

Docling Core: Insufficient validation of image reference URIs

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-47214 HIGH - 7.1

Docling: Unsafe URI and Path Handling in HTML Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44020 HIGH - 7.5

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44016 HIGH - 8.2

Docling: Unsafe Playwright-based HTML Rendering

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-41234 HIGH - 7.6

Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record l...

Vendor: composer
Product: froxlor/froxlor
Published: Jun 03, 2026
Source: GitHub
CVE-2026-50033 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44682 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44609 HIGH - 7.3

Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-42061 HIGH - 7.3

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44017 HIGH - 7.5

Docling: Unsafe Zip Extraction in EasyOCR Model Download

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-8889 HIGH - 7.5

Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).

Vendor: securly
Product: securly
Published: Jun 03, 2026
Source: NVD
CVE-2026-8888 HIGH - 7.5

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in deni...

Vendor: securly
Product: securly
Published: Jun 03, 2026
Source: NVD
CVE-2026-8881 HIGH - 7.5

Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been broken since 2004 and a single iteration provides no key stretching.

Vendor: securly
Product: securly
Published: Jun 03, 2026
Source: NVD