Search
30,126 CVEs
CVEs (30,126, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 30,126 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-44505 | MEDIUM | Patched | 5.3 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in hand… |
| CVE-2026-44716 | HIGH | Patched | 7.5 | 2026-06-10 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal … |
| CVE-2026-45782 | NONE | Patched | — | 2026-06-10 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-free in the cloud-hypervisor proc… |
| CVE-2026-46411 | MEDIUM | Patched | 6.5 | 2026-06-10 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of th… |
| CVE-2026-46432 | HIGH | 7.8 | 2026-06-10 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution throug… | |
| CVE-2026-46491 | HIGH | Patched | 8.6 | 2026-06-10 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file … |
| CVE-2026-46517 | HIGH | 7.8 | 2026-06-10 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chai… | |
| CVE-2026-46518 | HIGH | Patched | 7.7 | 2026-06-10 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerabili… |
| CVE-2026-46539 | MEDIUM | Patched | 5.9 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof:… |
| CVE-2026-46540 | MEDIUM | Patched | 6.5 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() ado… |
| CVE-2026-46541 | HIGH | Patched | 7.5 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, iIn handle_dht_get(), the DhtResults… |
| CVE-2026-46542 | MEDIUM | Patched | 4.3 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability ex… |
| CVE-2026-46543 | MEDIUM | Patched | 5.3 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash any full nod… |
| CVE-2026-46545 | HIGH | Patched | 7.5 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote, unauthenticated denial-of-… |
| CVE-2026-47838 | MEDIUM | Patched | 6.8 | 2026-06-10 | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a ca… |
| CVE-2026-53673 | HIGH | 8.1 | 2026-06-10 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private messag… | |
| CVE-2026-53674 | HIGH | 7.1 | 2026-06-10 | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers… | |
| CVE-2026-53675 | MEDIUM | 4.3 | 2026-06-10 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's comp… | |
| CVE-2026-44634 | NONE | Patched | — | 2026-06-10 | SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities i… |
| CVE-2026-46546 | MEDIUM | Patched | 5.4 | 2026-06-10 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially… |
| CVE-2026-45160 | MEDIUM | Patched | 6.5 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP se… |
| CVE-2026-45328 | CRITICAL | Patched | 9.3 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_serv… |
| CVE-2026-45329 | HIGH | Patched | 7.1 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp… |
| CVE-2026-45541 | HIGH | Patched | 7.5 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket… |
| CVE-2026-45542 | HIGH | Patched | 7.1 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Sche… |