Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26567
Total
1967
Critical
8010
High
8270
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11815 | UNKNOWN | — | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could … | Jun 10, 2026 |
| CVE-2026-10846 | UNKNOWN | — | NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address … | Jun 10, 2026 |
| CVE-2026-26241 | UNKNOWN | — | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash … | Jun 10, 2026 |
| CVE-2026-26240 | UNKNOWN | — | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash … | Jun 10, 2026 |
| CVE-2026-11837 | HIGH | 7.3 | A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without … | Jun 10, 2026 |
| CVE-2025-8444 | MEDIUM | 6.4 | The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the … | Jun 10, 2026 |
| CVE-2026-26239 | UNKNOWN | — | A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the … | Jun 10, 2026 |
| CVE-2026-26237 | UNKNOWN | — | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized … | Jun 10, 2026 |
| CVE-2026-24724 | UNKNOWN | — | An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the … | Jun 10, 2026 |
| CVE-2026-24720 | UNKNOWN | — | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, … | Jun 10, 2026 |
| CVE-2026-24719 | UNKNOWN | — | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then … | Jun 10, 2026 |
| CVE-2026-24717 | UNKNOWN | — | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then … | Jun 10, 2026 |
| CVE-2026-24716 | UNKNOWN | — | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can … | Jun 10, 2026 |
| CVE-2026-22899 | UNKNOWN | — | A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit … | Jun 10, 2026 |
| CVE-2026-22893 | UNKNOWN | — | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then … | Jun 10, 2026 |
| CVE-2025-66281 | UNKNOWN | — | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch … | Jun 10, 2026 |
| CVE-2025-66280 | UNKNOWN | — | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they … | Jun 10, 2026 |
| CVE-2025-66279 | UNKNOWN | — | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then … | Jun 10, 2026 |
| CVE-2025-66273 | UNKNOWN | — | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then … | Jun 10, 2026 |
| CVE-2025-62851 | UNKNOWN | — | A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability … | Jun 10, 2026 |
| CVE-2025-62850 | UNKNOWN | — | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can … | Jun 10, 2026 |
| CVE-2025-66276 | UNKNOWN | — | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later | Jun 10, 2026 |
| CVE-2025-59382 | UNKNOWN | — | QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version: | Jun 10, 2026 |
| CVE-2025-58468 | UNKNOWN | — | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or … | Jun 10, 2026 |
| CVE-2026-46532 | MEDIUM | 4.6 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid … | Jun 10, 2026 |