Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,364
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 161 - 180 of 3,181 CVEs
CVE-2026-26241 CRITICAL - 9.1

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2026-26240 CRITICAL - 9.1

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2025-66276 CRITICAL - 9.8

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2026-45328 CRITICAL - 9.3

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware perip...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-48030 CRITICAL - 9.9

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Vendor: composer
Product: pheditor/pheditor
Published: Jun 09, 2026
Source: GitHub
CVE-2026-48303 CRITICAL - 10.0

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Vendor: Adobe
Product: Adobe Campaign Classic (ACC)
Published: Jun 09, 2026
Source: NVD
CVE-2026-47938 CRITICAL - 10.0

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

Vendor: Adobe
Product: Adobe Campaign Classic (ACC)
Published: Jun 09, 2026
Source: NVD
CVE-2026-47928 CRITICAL - 9.6

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Vendor: Adobe
Product: ColdFusion
Published: Jun 09, 2026
Source: NVD
CVE-2026-36727 CRITICAL - 9.1

An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

Published: Jun 09, 2026
Source: NVD
CVE-2026-36721 CRITICAL - 9.8

A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

Published: Jun 09, 2026
Source: NVD
CVE-2026-30141 CRITICAL - 9.8

An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.

Published: Jun 09, 2026
Source: NVD
CVE-2026-10045 CRITICAL - 9.8

Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities allow attackers to read and write to memory, modify firmware stored in fla...

Vendor: Shenzhen Kangda Xin Intelligent Network Technology Co., Ltd
Product: DR300
Published: Jun 09, 2026
Source: NVD
CVE-2026-34691 CRITICAL - 9.3

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser whe...

Vendor: Adobe
Product: Adobe Experience Manager Forms JEE
Published: Jun 09, 2026
Source: NVD
CVE-2026-49841 CRITICAL - 9.8

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-w...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-49840 CRITICAL - 9.1

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(...

Vendor: signalwire
Product: freeswitch
Published: Jun 09, 2026
Source: NVD
CVE-2026-47643 CRITICAL - 9.8

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

Published: Jun 09, 2026
Source: NVD
CVE-2026-47291 CRITICAL - 9.8

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD
CVE-2026-47281 CRITICAL - 9.6

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: visual_studio_code
Published: Jun 09, 2026
Source: NVD
CVE-2026-45657 CRITICAL - 9.8

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: windows_11_23h2
Published: Jun 09, 2026
Source: NVD
CVE-2026-45602 CRITICAL - 9.1

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Jun 09, 2026
Source: NVD