Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,741 - 1,760 of 35,119 CVEs
CVE-2026-50255 MEDIUM - 6.7

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges.

Vendor: Sony Corporation
Product: Optical Disc Archive Software for Windows
Published: Jun 16, 2026
Source: NVD
CVE-2026-10780 MEDIUM - 4.3

The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_...

Vendor: mohammadtanzilurrahman
Product: Static Block
Published: Jun 16, 2026
Source: NVD
CVE-2026-10635 MEDIUM - 6.3

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded inside the caller-owned struct k_mem_domain. When a domain is destroyed via k_mem_domain_de...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2025-10262 MEDIUM - 6.3

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privileges.

Vendor: Nokia
Product: SR Linux
Published: Jun 16, 2026
Source: NVD
CVE-2026-6964 MEDIUM - 5.3

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the...

Published: Jun 16, 2026
Source: NVD
CVE-2026-7273 HIGH - 8.8

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions throughΒ 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Published: Jun 16, 2026
Source: NVD
CVE-2026-42014 MEDIUM - 6.6

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 16, 2026
Source: NVD
CVE-2026-1767 MEDIUM - 5.6

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calcula...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1766 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker co...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1765 MEDIUM - 5.6

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Deni...

Published: Jun 16, 2026
Source: NVD
CVE-2026-1764 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attac...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-12162 MEDIUM - 5.5

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-12161 HIGH - 8.8

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted altern...

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-9262 MEDIUM - 6.5

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9261 MEDIUM - 6.8

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9260 MEDIUM - 6.2

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9259 MEDIUM - 6.5

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9258 MEDIUM - 6.5

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_bo...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD