Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,326
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 201 - 220 of 3,181 CVEs
CVE-2026-40128 CRITICAL - 9.0

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or m...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server Java (Web Container)
Published: Jun 09, 2026
Source: NVD
CVE-2026-27671 CRITICAL - 9.8

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impa...

Vendor: SAP_SE
Product: SAP NetWeaver and ABAP Platform
Published: Jun 09, 2026
Source: NVD
CVE-2026-11697 CRITICAL - 9.6

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11671 CRITICAL - 9.6

Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11659 CRITICAL - 9.6

Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11654 CRITICAL - 9.6

Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11651 CRITICAL - 9.6

Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11638 CRITICAL - 9.6

Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11634 CRITICAL - 9.6

Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-47724 CRITICAL - 9.9

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47252 CRITICAL - 9.0

Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin

Vendor: go
Product: github.com/julien040/anyquery/plugins/chrome
Published: Jun 08, 2026
Source: GitHub

PHPSpreadsheet has a patch bypass for CVE-2026-34084

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Jun 08, 2026
Source: GitHub
CVE-2026-52778 CRITICAL - 9.8

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing...

Vendor: YesWiki
Product: yeswiki
Published: Jun 08, 2026
Source: NVD
CVE-2026-11393 CRITICAL - 9.0

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of anot...

Vendor: AWS
Product: AgentCore CLI
Published: Jun 08, 2026
Source: NVD
CVE-2026-46289 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. Fix bugs in the kvec and user variants of extract_iter_to_sg. This series is growing due to useful rem...

Vendor: Linux
Product: Linux
Published: Jun 08, 2026
Source: NVD
CVE-2026-41448 CRITICAL - 9.4

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path cons...

Vendor: AdguardTeam
Product: AdGuardHome
Published: Jun 08, 2026
Source: NVD
CVE-2026-39910 CRITICAL - 9.8

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvalidated PUT servers...

Vendor: STACKIT
Product: IaaS API
Published: Jun 08, 2026
Source: NVD
CVE-2026-25555 CRITICAL - 9.8

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied h...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-46442 CRITICAL - 9.9

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_A...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-46441 CRITICAL - 9.6

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceI...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD