Vulnerabilities (CVE)

Total 403285 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-21409 2026-06-17 N/A 5.9 MEDIUM
Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may be retrieved.
CVE-2026-21408 2026-06-17 N/A 7.3 HIGH
beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with SYSTEM privileges.
CVE-2026-21393 2026-06-17 N/A 5.4 MEDIUM
Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
CVE-2026-21389 1 Copeland 6 Xweb 300d Pro, Xweb 300d Pro Firmware, Xweb 500b Pro and 3 more 2026-06-17 N/A 8.0 HIGH
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.
CVE-2026-21388 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 3.7 LOW
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610
CVE-2026-21386 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 4.3 MEDIUM
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588
CVE-2026-21385 1 Qualcomm 474 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Apq8098 and 471 more 2026-06-17 N/A 7.8 HIGH
Memory corruption while using alignments for memory allocation.
CVE-2026-21382 1 Qualcomm 38 Cologne, Cologne Firmware, Fastconnect 6900 and 35 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when handling power management requests with improperly sized input/output buffers.
CVE-2026-21381 1 Qualcomm 206 Ar8035, Ar8035 Firmware, Cologne and 203 more 2026-06-17 N/A 7.6 HIGH
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
CVE-2026-21380 1 Qualcomm 46 Cologne, Cologne Firmware, Fastconnect 6900 and 43 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
CVE-2026-21378 1 Qualcomm 102 Aqt1000, Aqt1000 Firmware, Cologne and 99 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21376 1 Qualcomm 108 Aqt1000, Aqt1000 Firmware, Cologne and 105 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21375 1 Qualcomm 70 Cologne, Cologne Firmware, Fastconnect 6700 and 67 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21374 1 Qualcomm 108 Aqt1000, Aqt1000 Firmware, Cologne and 105 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
CVE-2026-21373 1 Qualcomm 108 Aqt1000, Aqt1000 Firmware, Cologne and 105 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21372 1 Qualcomm 56 Cologne, Cologne Firmware, Fastconnect 6700 and 53 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
CVE-2026-21371 1 Qualcomm 104 Aqt1000, Aqt1000 Firmware, Cologne and 101 more 2026-06-17 N/A 7.8 HIGH
Memory Corruption when retrieving output buffer with insufficient size validation.
CVE-2026-21367 1 Qualcomm 300 Ar8035, Ar8035 Firmware, Cologne and 297 more 2026-06-17 N/A 7.6 HIGH
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
CVE-2026-21264 1 Microsoft 1 Account 2026-06-17 N/A 9.3 CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21261 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-06-17 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.