Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,720
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,961 - 1,980 of 13,055 CVEs
CVE-2026-10224 MEDIUM - 5.3

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launc...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 01, 2026
Source: NVD
CVE-2026-10223 MEDIUM - 6.3

A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used ...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 01, 2026
Source: NVD
CVE-2026-10222 MEDIUM - 5.6

A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch the attack remotely. The attack requires a high level of comp...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 01, 2026
Source: NVD
CVE-2026-48208 MEDIUM - 6.5

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent ...

Vendor: OTRS AG
Product: OTRS, ((OTRS)) Community Edition
Published: Jun 01, 2026
Source: NVD
CVE-2026-48189 MEDIUM - 5.7

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected. This issue affects OTRS: * 7.0.X * 8....

Vendor: OTRS AG
Product: OTRS
Published: Jun 01, 2026
Source: NVD
CVE-2026-48187 MEDIUM - 5.7

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS: * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X Please note that ((OTR...

Vendor: OTRS AG
Product: OTRS, ((OTRS)) Community Edition
Published: Jun 01, 2026
Source: NVD
CVE-2026-20456 MEDIUM - 5.5

In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Jun 01, 2026
Source: NVD
CVE-2026-20454 MEDIUM - 6.4

In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Jun 01, 2026
Source: NVD
CVE-2026-20453 MEDIUM - 6.7

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Jun 01, 2026
Source: NVD
CVE-2026-10218 MEDIUM - 5.4

A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used...

Vendor: nextlevelbuilder
Product: GoClaw
Published: Jun 01, 2026
Source: NVD
CVE-2026-10217 MEDIUM - 6.3

A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper privilege management. Remote exploitation of the attack is possible. The exploi...

Vendor: nextlevelbuilder
Product: GoClaw
Published: Jun 01, 2026
Source: NVD
CVE-2026-10215 MEDIUM - 4.3

A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The attack may be initiated...

Vendor: Dolibarr
Product: ERP CRM
Published: Jun 01, 2026
Source: NVD
CVE-2026-10213 MEDIUM - 5.4

A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal. The attack can be initiated remotely. The exploit has bee...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10212 MEDIUM - 6.3

A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly avail...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10211 MEDIUM - 6.3

A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py. This manipulation causes incorrect authorization. It is possible to initiate the attack remotely. The exploit has been publicly...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10210 MEDIUM - 6.3

A vulnerability was found in AstrBotDevs AstrBot 4.23.6. Affected by this vulnerability is the function _sanitize_prompt_description of the file astrbot/core/skills/skill_manager.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and ...

Vendor: AstrBotDevs
Product: AstrBot
Published: Jun 01, 2026
Source: NVD
CVE-2026-10209 MEDIUM - 6.3

A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remo...

Vendor: code-projects
Product: Online Hospital Management System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10205 MEDIUM - 6.3

A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and m...

Vendor: Metasoft 美特软件
Product: MetaCRM
Published: Jun 01, 2026
Source: NVD
CVE-2026-10204 MEDIUM - 6.3

A weakness has been identified in OFCMS 1.1.3. The affected element is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SysUserController.java of the component JSON Query Interface. This manipulation causes sql injection. The attack may be initiated re...

Product: OFCMS
Published: Jun 01, 2026
Source: NVD
CVE-2026-10203 MEDIUM - 6.3

A security flaw has been discovered in OFCMS 1.1.3. Impacted is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemParamController.java of the component JSON Query Interface. The manipulation results in sql injection. The attack can be launched rem...

Product: OFCMS
Published: Jun 01, 2026
Source: NVD