Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,624
Quick preset (or use dates below)
Clear Filters
Showing 2,101 - 2,120 of 12,893 CVEs
CVE-2026-10621 HIGH - 7.5

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.

Vendor: Collibra
Product: Collibra Platform (SaaS), Collibra Platform (on-prem)
Published: Jun 02, 2026
Source: NVD
CVE-2025-69369 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0.

Vendor: Axiomthemes
Product: Racquet
Published: Jun 02, 2026
Source: NVD
CVE-2025-68886 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8.

Vendor: androThemes
Product: Cookiteer
Published: Jun 02, 2026
Source: NVD
CVE-2025-58897 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0.

Vendor: Axiomthemes
Product: Fermentio
Published: Jun 02, 2026
Source: NVD
CVE-2025-58707 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8.

Vendor: Axiomthemes
Product: Spin
Published: Jun 02, 2026
Source: NVD
CVE-2019-25719 HIGH - 8.6

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers ...

Vendor: Dräger
Product: Infinity Acute Care System, Standalone Infinity M540 patient monitor
Published: Jun 02, 2026
Source: NVD
CVE-2026-42685 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.

Vendor: Ahmad
Product: WP Job Portal
Published: Jun 02, 2026
Source: NVD
CVE-2026-42670 HIGH - 7.5

Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.

Vendor: Etoile Web Design Incorporated
Product: Five Star Restaurant Reservations
Published: Jun 02, 2026
Source: NVD
CVE-2026-42669 HIGH - 7.5

Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0.

Vendor: EventPrime
Product: EventPrime
Published: Jun 02, 2026
Source: NVD
CVE-2026-39551 HIGH - 8.1

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

Vendor: Elated-Themes
Product: Töbel
Published: Jun 02, 2026
Source: NVD
CVE-2026-39550 HIGH - 8.1

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

Vendor: Elated-Themes
Product: Aperitif
Published: Jun 02, 2026
Source: NVD
CVE-2025-58705 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue affects Crafti: from n/a through 1.12.

Vendor: Axiomthemes
Product: Crafti
Published: Jun 02, 2026
Source: NVD
CVE-2025-58024 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion. This issue affects Accordion FAQ: from n/a through 2.2.1.

Vendor: UnboundStudio
Product: Accordion FAQ
Published: Jun 02, 2026
Source: NVD
CVE-2025-53440 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. This issue affects Confidant: from n/a through 1.4.

Vendor: Axiomthemes
Product: Confidant
Published: Jun 02, 2026
Source: NVD
CVE-2025-52759 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a through 2.2.1.

Vendor: UnboundStudio
Product: Accordion FAQ
Published: Jun 02, 2026
Source: NVD
CVE-2026-3514 HIGH - 7.5

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication ...

Vendor: prefect
Product: prefect
Published: Jun 02, 2026
Source: NVD
CVE-2026-1784 HIGH - 8.8

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

Vendor: redhat
Product: openshift_container_platform
Published: Jun 02, 2026
Source: NVD
CVE-2026-8293 HIGH - 7.5

The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the em...

Published: Jun 02, 2026
Source: NVD
CVE-2026-25277 HIGH - 8.8

Memory corruption while using Strongbox due to buffer overflow.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Jun 01, 2026
Source: NVD
CVE-2026-25276 HIGH - 8.8

Memory corruption while using Strongbox due to missing bounds check.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Jun 01, 2026
Source: NVD