Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,978
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,081 - 2,100 of 34,601 CVEs

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal user can create a ticket with a reason containing @everyone, @here, user mentions, or role mentions. When the ticket is created, the bot posts the attacker-controlled reason in...

Vendor: duck-organization
Product: quest-bot
Published: Jun 11, 2026
Source: NVD

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository has a privileged deploy workflow that runs after the unprivileged build workflow completes. The build workflow runs on pull requests, and the deploy workflow checks out t...

Vendor: duck-organization
Product: quest-bot
Published: Jun 11, 2026
Source: NVD

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal user can create a reminder whose message contains @everyone or @here. When the reminder triggers, the bot sends the stored message back into the channel without suppressing mas...

Vendor: duck-organization
Product: quest-bot
Published: Jun 11, 2026
Source: NVD
CVE-2026-47170 HIGH - 7.7

Garlic-Hub manages digital signage network โ€” devices, content, and playlists โ€” from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HTTP requests to internal services via the uploadFromUrl endpoint. This allows internal port scanning,...

Vendor: garlic-signage
Product: garlic-hub
Published: Jun 11, 2026
Source: NVD

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a user with Manage Server / ManageGuild, but without Manage Roles or Administrator, can configure the botโ€™s AutoRole feature to assign an arbitrary role to new members. If the selected ...

Vendor: duck-organization
Product: quest-bot
Published: Jun 11, 2026
Source: NVD
CVE-2026-47167 MEDIUM - 5.3

Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository'...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke slash commands can use /automod add, /automod remove, and /automod list because the command has no Discord default permission requirement and no runtime ...

Vendor: duck-organization
Product: quest-bot
Published: Jun 11, 2026
Source: NVD
CVE-2026-47162 HIGH - 8.8

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A ...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of ...

Vendor: CyberArk Software, a Palo Alto Networks Company
Product: Conjur Enterprise
Published: Jun 11, 2026
Source: NVD

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipul...

Vendor: CyberArk Software, a Palo Alto Networks Company
Product: Conjur Cloud (Edge Finding only)
Published: Jun 11, 2026
Source: NVD

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could p...

Vendor: CyberArk Software, a Palo Alto Networks Company
Product: Idira Endpoint Privilege Manager
Published: Jun 11, 2026
Source: NVD
CVE-2026-11774 HIGH - 7.6

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap ...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 11, 2026
Source: NVD
CVE-2025-46315 HIGH - 7.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-46313 MEDIUM - 5.5

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-46308 MEDIUM - 5.3

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.

Vendor: Apple
Product: iOS and iPadOS, macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-46293 MEDIUM - 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-43339 MEDIUM - 5.5

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-43278 MEDIUM - 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-31272 HIGH - 7.8

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-30459 MEDIUM - 5.5

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD