Vulnerabilities (CVE)

Total 397935 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-26331 1 Dell 12 Latitude 3420, Latitude 3440, Latitude 5440 and 9 more 2026-06-17 N/A 7.8 HIGH
Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
CVE-2025-26330 1 Dell 1 Powerscale Onefs 2026-06-17 N/A 7.0 HIGH
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
CVE-2025-26326 2026-06-17 N/A 8.8 HIGH
A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept any password entered by the user and do not have an additional authentication or computer verification mechanism. Tests indicate that more than 1,000 systems use easy-to-guess passwords, many with less than 4 to 6 characters, including common sequences. This allows brute force attacks or trial-and-error attempts by malicious invaders. The vulnerability can be exploited by a remote attacker who knows or can guess the password used in the connection. As a result, the attacker gains complete access to the affected system and can execute commands, modify files, and compromise user security.
CVE-2025-26325 1 Shopxo 1 Shopxo 2026-06-17 N/A 9.8 CRITICAL
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
CVE-2025-26320 1 T0mer 1 Broadlinkmanager 2026-06-17 N/A 6.5 MEDIUM
t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.
CVE-2025-26319 1 Flowiseai 1 Flowise 2026-06-17 N/A 9.8 CRITICAL
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
CVE-2025-26318 2026-06-17 N/A 5.8 MEDIUM
hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.
CVE-2025-26312 2026-06-17 N/A N/A
SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
CVE-2025-26311 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted SWF file.
CVE-2025-26310 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted ABC file.
CVE-2025-26309 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
CVE-2025-26308 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
CVE-2025-26307 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
CVE-2025-26306 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file.
CVE-2025-26305 1 Libming 1 Libming 2026-06-17 N/A 8.2 HIGH
A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
CVE-2025-26304 1 Libming 1 Libming 2026-06-17 N/A 8.2 HIGH
A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.
CVE-2025-26278 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2025-26269 1 Dragonflydb 1 Dragonfly 2026-06-17 N/A 3.3 LOW
DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.
CVE-2025-26268 1 Dragonflydb 1 Dragonfly 2026-06-17 N/A 3.3 LOW
DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.
CVE-2025-26265 1 Openairinterface 1 Openairinterface5g 2026-06-17 N/A 6.5 MEDIUM
A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response.