Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,970
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,781 - 1,800 of 12,353 CVEs
CVE-2026-36608 HIGH - 8.8

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel t...

Published: Jun 03, 2026
Source: NVD
CVE-2026-36607 HIGH - 8.8

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords withou...

Published: Jun 03, 2026
Source: NVD
CVE-2026-36606 HIGH - 7.1

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mode. An attacker who obtains a backup file can decrypt it to recover all stored credentials including admin password, WiFi PSK, and DDNS credentials.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36603 HIGH - 8.1

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. UPnP is enabled by default through the admin interface, allowing any unauthenticated LAN device to create arbitrar...

Published: Jun 03, 2026
Source: NVD
CVE-2026-20230 HIGH - 8.6

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerab...

Vendor: Cisco
Product: Cisco Unified Communications Manager
Published: Jun 03, 2026
Source: NVD
CVE-2026-37462 HIGH - 7.3

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Published: Jun 03, 2026
Source: NVD
CVE-2026-36574 HIGH - 7.8

A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.

Published: Jun 03, 2026
Source: NVD
CVE-2026-5241 HIGH - 8.0

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, i...

Vendor: huggingface
Product: transformers
Published: Jun 03, 2026
Source: NVD
CVE-2026-37460 HIGH - 7.5

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Published: Jun 03, 2026
Source: NVD
CVE-2022-49042 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Hyper Backup Explorer
Published: Jun 03, 2026
Source: NVD
CVE-2022-49036 HIGH - 7.8

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: Synology Active Backup for Business Recovery Media Creator
Published: Jun 03, 2026
Source: NVD
CVE-2026-35085 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35084 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35083 HIGH - 8.8

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35082 HIGH - 8.8

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35081 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35080 HIGH - 8.1

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35079 HIGH - 8.1

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35078 HIGH - 8.1

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD
CVE-2026-35077 HIGH - 8.1

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Vendor: mbs-solutions
Product: universal_gateway_firmware
Published: Jun 03, 2026
Source: NVD