Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,481 - 2,500 of 36,778 CVEs
CVE-2026-55743 CRITICAL - 9.6

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe() bl...

Vendor: tinyhumansai
Product: OpenHuman
Published: Jun 17, 2026
Source: NVD
CVE-2026-54812 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109.

Vendor: StylemixThemes
Product: Motors
Published: Jun 17, 2026
Source: NVD
CVE-2026-54810 HIGH - 7.5

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1.

Vendor: Nexi Payments
Product: Nexi XPay
Published: Jun 17, 2026
Source: NVD
CVE-2026-54415 HIGH - 8.1

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email ...

Vendor: Azuriom
Product: Azuriom CMS
Published: Jun 17, 2026
Source: NVD
CVE-2026-49502 HIGH - 7.4

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Unauthorized access.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-48142 MEDIUM - 4.8

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send reques...

Vendor: F5
Product: NGINX Open Source, NGINX Plus
Published: Jun 17, 2026
Source: NVD
CVE-2026-48117 MEDIUM - 6.8

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack in which an attacker could register an account using a victim's email address with an attacker-controlled password before the victim completed acco...

Vendor: fduflyer
Product: DroneAware-Node-Releases
Published: Jun 17, 2026
Source: NVD
CVE-2026-47103 CRITICAL - 9.8

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attack...

Vendor: fgmacedo
Product: python-statemachine
Published: Jun 17, 2026
Source: NVD
CVE-2026-42530 HIGH - 8.1

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This m...

Vendor: F5
Product: NGINX Open Source
Published: Jun 17, 2026
Source: NVD
CVE-2026-42055 HIGH - 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the lar...

Vendor: F5
Product: NGINX Open Source, NGINX Plus
Published: Jun 17, 2026
Source: NVD
CVE-2026-40641 MEDIUM - 4.8

Dell PowerFlex Manager, version(s) 4.6.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35162 MEDIUM - 4.3

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35067 MEDIUM - 5.7

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35066 HIGH - 7.1

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35065 HIGH - 8.8

Dell PowerFlex Manager, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Informa...

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-32804 HIGH - 8.1

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-22283 HIGH - 7.5

Dell PowerFlex Manager, version(s) Version prior to 4.8, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-12528 MEDIUM - 5.4

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 17, 2026
Source: NVD
CVE-2026-11311 HIGH - 8.1

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilt...

Vendor: F5
Product: NGINX Gateway Fabric
Published: Jun 17, 2026
Source: NVD
CVE-2026-10850 MEDIUM - 5.4

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.

Vendor: Plane
Product: Plane
Published: Jun 17, 2026
Source: NVD