Total
29997 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-22907 | 1 Sick | 2 Tdc-x401gl, Tdc-x401gl Firmware | 2026-06-17 | N/A | 9.9 CRITICAL |
| An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data. | |||||
| CVE-2026-22779 | 1 Neoteroi | 1 Blacksheep | 2026-06-17 | N/A | 5.3 MEDIUM |
| BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create a new HTTP request. Exploitation requires developers to pass unsanitized user input directly into headers.The server part is not affected because BlackSheep delegates to an underlying ASGI server handling of response headers. This vulnerability is fixed in 2.4.6. | |||||
| CVE-2026-22628 | 1 Fortinet | 1 Fortiswitchaxfixed | 2026-06-17 | N/A | 5.3 MEDIUM |
| An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file. | |||||
| CVE-2026-22204 | 1 Gvectors | 1 Wpdiscuz | 2026-06-17 | N/A | 3.7 LOW |
| wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and passed to wp_mail() functions, enables header injection to alter email recipients or inject additional headers. | |||||
| CVE-2026-21452 | 1 Msgpack | 1 Messagepack | 2026-06-17 | N/A | 7.5 HIGH |
| MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforcing any upper bound. A malicious .msgpack file of only a few bytes can therefore trigger unbounded heap allocation, resulting in JVM heap exhaustion, process termination, or service unavailability. This vulnerability is triggered during model loading / deserialization, making it a model format vulnerability suitable for remote exploitation. The vulnerability enables a remote denial-of-service attack against applications that deserialize untrusted .msgpack model files using MessagePack for Java. A specially crafted but syntactically valid .msgpack file containing an EXT32 object with an attacker-controlled, excessively large payload length can trigger unbounded memory allocation during deserialization. When the model file is loaded, the library trusts the declared length metadata and attempts to allocate a byte array of that size, leading to rapid heap exhaustion, excessive garbage collection, or immediate JVM termination with an OutOfMemoryError. The attack requires no malformed bytes, user interaction, or elevated privileges and can be exploited remotely in real-world environments such as model registries, inference services, CI/CD pipelines, and cloud-based model hosting platforms that accept or fetch .msgpack artifacts. Because the malicious file is extremely small yet valid, it can bypass basic validation and scanning mechanisms, resulting in complete service unavailability and potential cascading failures in production systems. Version 0.9.11 fixes the vulnerability. | |||||
| CVE-2026-21029 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations. | |||||
| CVE-2026-21027 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 3.3 LOW |
| Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function. | |||||
| CVE-2026-21026 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information. | |||||
| CVE-2026-21025 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2026-21022 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2026-21020 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions. | |||||
| CVE-2026-21017 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files. | |||||
| CVE-2026-21016 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2026-20993 | 1 Samsung | 1 Assistant | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information. | |||||
| CVE-2026-20990 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 8.1 HIGH |
| Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege. | |||||
| CVE-2026-20988 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.0 MEDIUM |
| Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability. | |||||
| CVE-2026-20983 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege. | |||||
| CVE-2026-20975 | 1 Samsung | 1 Cloud | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path. | |||||
| CVE-2026-20972 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 3.3 LOW |
| Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB. | |||||
| CVE-2026-1680 | 1 Danofficeit | 1 Local Admin Service | 2026-06-17 | N/A | 7.8 HIGH |
| Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions. | |||||
