Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,261 - 2,280 of 34,601 CVEs

CleanWipe Removal Tool (macOS), prior to 16.0.0.65,ย may be susceptible to an Local Privilege Escalation vulnerability, which is a type of issue whereby an attacker with limited privilege access on an affected system can escalate their privileges to gain administrative control.

Vendor: Broadcom
Product: Symantec Endpoint Protection CleanWipe Removal Tool
Published: Jun 10, 2026
Source: NVD
CVE-2026-10740 MEDIUM - 5.3

Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate this issue, users should upgrade to v1.8.2.

Vendor: AWS
Product: s2n-quic
Published: Jun 10, 2026
Source: NVD
CVE-2026-48061 MEDIUM - 5.9

Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header

Vendor: pip
Product: litestar
Published: Jun 10, 2026
Source: GitHub
CVE-2026-48060 HIGH - 8.1

Litestar has HTML Injection Through its CSRF Token

Vendor: pip
Product: litestar
Published: Jun 10, 2026
Source: GitHub

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub

nebula-mesh: Decrypted CA private key persists in heap after signing

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub

An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration fil...

Published: Jun 10, 2026
Source: NVD
CVE-2026-50570 HIGH - 8.5

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSaf...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50569 MEDIUM - 4.3

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeUR...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling strings.HasPrefix(path, safedir...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50567 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Unarchive in pkg/utils/zip.go joined each archive entry name with the destination directory via filepath.Join and wrote the result wi...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50566 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability contain...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50565 MEDIUM - 4.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-builder and no AutomountServiceAccountToken: false, so the kubelet...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50564 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs ...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50563 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50545 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fiel...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49824 HIGH - 8.5

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namesp...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49823 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types โ€” Secret, ConfigMap, and Package. The first two were namespace-validated by the...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49822 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent s...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49821 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying that Package.spec.environment.namespace matched Package...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD