Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,981
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,741 - 1,760 of 34,478 CVEs
CVE-2026-48163 HIGH - 8.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not a...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-47965 HIGH - 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 12, 2026
Source: NVD

Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affecting search requests that use both server-side search result caching and Scoped Search API Keys. Under specific request ordering, cached search results could be reused across requ...

Vendor: typesense
Product: typesense
Published: Jun 12, 2026
Source: NVD
CVE-2026-47223 MEDIUM - 5.4

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Zip AvbHandler). A 32-bit unsigned integer overflow...

Vendor: M2Team
Product: NanaZip
Published: Jun 12, 2026
Source: NVD

Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially crafted request can trigger an unhandled exception during request processing, causing the server process to termin...

Vendor: typesense
Product: typesense
Published: Jun 12, 2026
Source: NVD
CVE-2026-44173 MEDIUM - 5.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege i...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-44172 CRITICAL - 9.8

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections,...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-44171 MEDIUM - 6.3

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain s...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-44170 CRITICAL - 9.8

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-44169 MEDIUM - 4.3

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been pa...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-44168 HIGH - 8.0

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not a...

Vendor: MariaDB
Product: server
Published: Jun 12, 2026
Source: NVD
CVE-2026-7387 HIGH - 8.8

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which allows a user with group-link permissions to esc...

Published: Jun 12, 2026
Source: NVD
CVE-2026-7184 MEDIUM - 6.5

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain remote cluster authentication tokens via a PATCH req...

Published: Jun 12, 2026
Source: NVD
CVE-2026-6961 HIGH - 7.6

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared channel file sync, which allows an attacker who controls a federated server to write files to arbitrary ...

Published: Jun 12, 2026
Source: NVD
CVE-2026-6739 MEDIUM - 6.7

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, which allows authenticated users with delegated user-management permissions to escalate privileges by alt...

Published: Jun 12, 2026
Source: NVD
CVE-2026-6689 MEDIUM - 4.3

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on update/patch), which allows an authenticated user holdi...

Published: Jun 12, 2026
Source: NVD
CVE-2026-6046 MEDIUM - 5.3

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via direct mess...

Published: Jun 12, 2026
Source: NVD
CVE-2026-53982 MEDIUM - 6.5

Capgo Console prior to 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associate...

Vendor: Cap-go
Product: console.capgo.app
Published: Jun 12, 2026
Source: NVD
CVE-2026-53981 HIGH - 7.6

Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verifica...

Vendor: Cap-go
Product: Cap-go
Published: Jun 12, 2026
Source: NVD
CVE-2026-47224 MEDIUM - 4.3

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap buffer-overflow read exists in the LVM2 physical-volume metadata parser in NanaZip (via the upstream 7-Zip LvmHandler). The vulnerability is triggered when opening...

Vendor: M2Team
Product: NanaZip
Published: Jun 12, 2026
Source: NVD