Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,948
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,281 - 2,300 of 34,601 CVEs

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 10, 2026
Source: NVD
CVE-2026-46642 MEDIUM - 6.1

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file can execute arbitrary JavaScript in the editor's origin when the file is opened. The vulnerability is not in the label sanitizer (which works correctly on the rendering path) bu...

Vendor: jgraph
Product: drawio
Published: Jun 10, 2026
Source: NVD
CVE-2026-20260 MEDIUM - 4.3

In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files through specially crafted HTTP request paths, which a terminal emulator might int...

Vendor: Splunk
Product: Splunk SOAR
Published: Jun 10, 2026
Source: NVD
CVE-2026-20259 MEDIUM - 5.5

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign s...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20258 HIGH - 7.1

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could store a malicious script...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20257 MEDIUM - 5.7

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a classic dashboar...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20256 MEDIUM - 5.7

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could cause data exfiltration ...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20255 MEDIUM - 5.7

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious classi...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20254 MEDIUM - 5.7

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious classi...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20253 CRITICAL - 9.8

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowi...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20252 HIGH - 7.6

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could send server...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20251 HIGH - 8.8

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin'...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform, Splunk Secure Gateway
Published: Jun 10, 2026
Source: NVD
CVE-2026-11596 MEDIUM - 4.7

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.

Vendor: ConnectWise
Product: ScreenConnect
Published: Jun 10, 2026
Source: NVD
CVE-2026-11417 HIGH - 7.3

OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host run...

Vendor: AWS
Product: AWS Cloud Development Kit library
Published: Jun 10, 2026
Source: NVD
CVE-2026-47701 HIGH - 7.7

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

Vendor: go
Product: github.com/open-telemetry/opentelemetry-operator
Published: Jun 10, 2026
Source: GitHub
CVE-2026-47253 HIGH - 7.3

Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion

Vendor: go
Product: github.com/julien040/anyquery
Published: Jun 10, 2026
Source: GitHub
CVE-2026-47155 MEDIUM - 6.5

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

Vendor: pip
Product: vllm
Published: Jun 10, 2026
Source: GitHub
CVE-2025-53114 HIGH - 7.5

CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 through 8.0.8, bad clients that always send a fixed batch value when the server is using the acknowledgement extension may cause the unacknowledged mes...

Vendor: maven
Product: org.cometd.java:cometd-java-server-common
Published: Jun 10, 2026
Source: GitHub
CVE-2026-53698 MEDIUM - 6.5

Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.

Vendor: Silverpeas
Product: Silverpeas
Published: Jun 10, 2026
Source: NVD

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.

Vendor: NoMachine
Product: NoMachine
Published: Jun 10, 2026
Source: NVD