Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

127,949 CVEs · High severity

CVEs (127,949, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 127,949 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-10843 HIGH 7.2 2026-06-04 A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive act…
CVE-2026-49771 HIGH 7.6 2026-06-04 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue a…
CVE-2026-50207 HIGH Patched 7.8 2026-06-04 The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
CVE-2026-50209 HIGH Patched 7.8 2026-06-04 Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external …
CVE-2026-50210 HIGH Patched 7.5 2026-06-04 The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
CVE-2026-50213 HIGH Patched 7.5 2026-06-04 The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
CVE-2026-3820 HIGH 7.2 2026-06-04 There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject specially crafted char…
CVE-2026-50205 HIGH Patched 8.2 2026-06-04 System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
CVE-2026-49193 HIGH Patched 7.5 2026-06-04 Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
CVE-2026-49194 HIGH Patched 8.8 2026-06-04 The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
CVE-2026-49202 HIGH Patched 8.6 2026-06-04 Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
CVE-2026-49203 HIGH Patched 8.3 2026-06-04 Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
CVE-2026-49190 HIGH Patched 8.8 2026-06-04 The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
CVE-2026-49187 HIGH Patched 7.5 2026-06-04 The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
CVE-2026-49189 HIGH Patched 7.8 2026-06-04 Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
CVE-2026-41010 HIGH Patched 8.2 2026-06-04 ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], …
CVE-2026-41860 HIGH Patched 8.8 2026-06-04 CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_…
CVE-2026-8829 HIGH Patched 7.5 2026-06-04 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) in…
CVE-2026-41011 HIGH Patched 8.2 2026-06-04 PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from…
CVE-2026-41858 HIGH Patched 7.5 2026-06-04 Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM bo…
CVE-2026-41859 HIGH Patched 7.8 2026-06-04 A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM l…
CVE-2026-10737 HIGH 7.5 2026-06-04 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up t…
CVE-2026-10777 HIGH 7.3 2026-06-03 A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality o…
CVE-2026-10771 HIGH 7.3 2026-06-03 A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTempl…
CVE-2026-44609 HIGH 7.3 2026-06-03 Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.