Severity: CRITICAL

30577 CVEs found

CVE-2026-47117
9.8 CRITICAL

OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model...

Published: 2026-06-02
Products: 0
CVE-2026-42074
9.8 CRITICAL

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool...

Published: 2026-06-02
Products: 1
Vendors:
gitlawb
CVE-2026-5076
9.8 CRITICAL

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset ke...

Published: 2026-06-02
Products: 0
CVE-2026-35075
9.8 CRITICAL

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

Published: 2026-06-03
Products: 0
CVE-2026-5241
9.6 CRITICAL

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The ...

Published: 2026-06-03
Products: 1
Vendors:
huggingface
CVE-2026-49185
9.8 CRITICAL

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Published: 2026-06-04
Products: 2
Vendors:
acer
CVE-2026-49186
9.8 CRITICAL

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish ro...

Published: 2026-06-04
Products: 2
Vendors:
acer
CVE-2026-49188
9.8 CRITICAL

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.

Published: 2026-06-04
Products: 2
Vendors:
acer
CVE-2026-49191
9.8 CRITICAL

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Published: 2026-06-04
Products: 2
Vendors:
acer
CVE-2026-50208
9.4 CRITICAL

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

Published: 2026-06-04
Products: 2
Vendors:
acer
CVE-2026-50211
9.8 CRITICAL

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

Published: 2026-06-04
Products: 2
Vendors:
acer
CVE-2026-4104
9.8 CRITICAL

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: fr...

Published: 2026-06-04
Products: 0
CVE-2019-25727
9.8 CRITICAL

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers ...

Published: 2026-06-04
Products: 0
CVE-2019-25729
9.8 CRITICAL

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter...

Published: 2026-06-04
Products: 0
CVE-2019-25738
9.8 CRITICAL

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action...

Published: 2026-06-04
Products: 0
CVE-2019-25741
9.8 CRITICAL

Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code....

Published: 2026-06-04
Products: 0
CVE-2026-25550
9.8 CRITICAL

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The servi...

Published: 2026-06-04
Products: 0