Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,758
Quick preset (or use dates below)
Clear Filters
Showing 1,901 - 1,920 of 13,436 CVEs
CVE-2026-8643 MEDIUM - 5.5

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Vendor: pypa
Product: pip
Published: Jun 01, 2026
Source: NVD
CVE-2026-45267 MEDIUM - 6.5

Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6.

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-45264 MEDIUM - 4.3

Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-45157 MEDIUM - 6.3

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could use this share token to also access the chunking upload directly and see temporar...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-45153 MEDIUM - 4.6

Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud Files app PIN. This issue has been patched in version 33.1.0.

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-42679 MEDIUM - 6.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.

Vendor: Mamunur Rashid
Product: Classified Listing
Published: Jun 01, 2026
Source: NVD
CVE-2026-42676 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

Vendor: myCred
Product: myCred
Published: Jun 01, 2026
Source: NVD
CVE-2026-42671 MEDIUM - 6.5

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

Vendor: Paolo
Product: GeoDirectory
Published: Jun 01, 2026
Source: NVD
CVE-2026-10275 MEDIUM - 5.0

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attac...

Product: OpenSC
Published: Jun 01, 2026
Source: NVD
CVE-2026-10274 MEDIUM - 6.3

A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAssetMetadata of the file src/mcp-server.ts of the component Axios Request Flow. Executing a manipulation of the argument assetPath can lead to server-side ...

Vendor: indrasishbanerjee
Product: aem-mcp-server
Published: Jun 01, 2026
Source: NVD
CVE-2026-10272 MEDIUM - 6.5

A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of the argument sid leads to improper authorization. It is possible to launch the attack re...

Vendor: a4m4
Product: Student-Management-System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10271 MEDIUM - 6.3

A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the component Admin Endpoint. This manipulation of the argument uid causes execution after redirect. It is possible to initiate th...

Vendor: a4m4
Product: Student-Management-System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10269 MEDIUM - 6.3

A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carri...

Vendor: decolua
Product: 9router
Published: Jun 01, 2026
Source: NVD
CVE-2026-48559 MEDIUM - 5.4

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victi...

Vendor: epoupon
Product: lms
Published: Jun 01, 2026
Source: NVD
CVE-2026-10533 MEDIUM - 5.0

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that acc...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: Jun 01, 2026
Source: NVD
CVE-2026-10265 MEDIUM - 6.3

A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly availa...

Vendor: itsourcecode
Product: Content Management System
Published: Jun 01, 2026
Source: NVD
CVE-2025-60495 MEDIUM - 5.5

A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60486 MEDIUM - 5.5

A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60485 MEDIUM - 5.5

A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Published: Jun 01, 2026
Source: NVD
CVE-2025-60483 MEDIUM - 5.5

A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.

Published: Jun 01, 2026
Source: NVD