Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,241 - 2,260 of 34,601 CVEs

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the ...

Published: Jun 10, 2026
Source: NVD

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OSยฎ software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, ...

Published: Jun 10, 2026
Source: NVD

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

Published: Jun 10, 2026
Source: NVD

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalPro...

Published: Jun 10, 2026
Source: NVD

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OSยฎ software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-S...

Published: Jun 10, 2026
Source: NVD

A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.

Vendor: Apple
Product: macOS Monterey
Published: Jun 10, 2026
Source: NVD
CVE-2022-26758 HIGH - 7.1

A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4.

Vendor: Apple
Product: macOS Monterey
Published: Jun 10, 2026
Source: NVD
CVE-2026-47768 MEDIUM - 5.5

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub

PDM wheel installation leads to Path Traversal via overridden write_to_fs

Vendor: pip
Product: pdm
Published: Jun 10, 2026
Source: GitHub

PDM: Project-Local State and Config Writes Follow Symlinks

Vendor: pip
Product: pdm
Published: Jun 10, 2026
Source: GitHub
CVE-2026-6893 HIGH - 8.8

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled...

Published: Jun 10, 2026
Source: NVD
CVE-2026-50127 MEDIUM - 5.9

Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictio...

Vendor: WeblateOrg
Product: weblate
Published: Jun 10, 2026
Source: NVD

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a ...

Vendor: mate-desktop
Product: atril
Published: Jun 10, 2026
Source: NVD
CVE-2026-1220 HIGH - 7.5

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Jun 10, 2026
Source: NVD

Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)

Vendor: go
Product: github.com/lxc/incus/v7
Published: Jun 10, 2026
Source: GitHub

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Vendor: actions
Product: anthropics/claude-code-action
Published: Jun 10, 2026
Source: GitHub

Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload

Vendor: npm
Product: baileys
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50639 MEDIUM - 6.5

Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::...

Vendor: PEVANS
Product: Metrics::Any::Adapter::SignalFx
Published: Jun 10, 2026
Source: NVD
CVE-2026-50638 CRITICAL - 9.1

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter...

Vendor: PEVANS
Product: Metrics::Any::Adapter::DogStatsd
Published: Jun 10, 2026
Source: NVD
CVE-2026-50637 HIGH - 8.2

Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the name...

Vendor: PEVANS
Product: Metrics::Any::Adapter::Statsd
Published: Jun 10, 2026
Source: NVD