Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,327
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,441 - 2,460 of 33,671 CVEs
CVE-2026-8078 MEDIUM - 4.8

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-7765 MEDIUM - 5.3

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing an attacker who knows a valid public dashboard share token to read the issuer's pers...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-7186 MEDIUM - 5.4

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when ...

Vendor: checkmk
Product: checkmk
Published: Jun 08, 2026
Source: NVD
CVE-2026-11577 HIGH - 7.2

A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Grained Admin Permissions (FGAP) and escalate their privileges to a full realm administrator by importi...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7
Published: Jun 08, 2026
Source: NVD
CVE-2026-11515 MEDIUM - 5.3

A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input passw...

Vendor: SourceCodester
Product: Barangay Resident Profiling and Information Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11514 MEDIUM - 6.3

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11513 MEDIUM - 6.3

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11512 MEDIUM - 4.3

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos...

Vendor: itsourcecode
Product: Hospital Management System
Published: Jun 08, 2026
Source: NVD

A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. It is possible to launch the attack remo...

Vendor: Bolt
Product: CMS
Published: Jun 08, 2026
Source: NVD
CVE-2026-50752 HIGH - 7.4

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow ...

Vendor: checkpoint
Product: Quantum Security Gateway, Spark Firewalls
Published: Jun 08, 2026
Source: NVD
CVE-2026-50751 CRITICAL - 9.3

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Vendor: checkpoint
Product: Quantum Security Gateway, Spark Firewalls
Published: Jun 08, 2026
Source: NVD

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560โ€“574`). Any web content loaded inside the InAppBrowser can fire any pending Cor...

Vendor: Apache Software Foundation
Product: Cordova Plugin InAppBrowser
Published: Jun 08, 2026
Source: NVD
CVE-2026-3011 MEDIUM - 6.4

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' met...

Published: Jun 08, 2026
Source: NVD
CVE-2026-11569 MEDIUM - 5.4

A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored cross-site scripting when ...

Vendor: Red Hat
Product: Red Hat Quay 3
Published: Jun 08, 2026
Source: NVD
CVE-2026-11510 MEDIUM - 6.3

A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been released...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11509 MEDIUM - 6.3

A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote.

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11508 MEDIUM - 6.3

A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The ex...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11507 MEDIUM - 6.3

A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11506 MEDIUM - 6.3

A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to t...

Vendor: CodeAstro
Product: Leave Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11505 MEDIUM - 5.0

A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a ...

Vendor: GL.iNet
Product: A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000
Published: Jun 08, 2026
Source: NVD