Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 241 - 260 of 35,345 CVEs
CVE-2026-39904 MEDIUM - 6.5

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP...

Vendor: gophish
Product: gophish
Published: Jun 22, 2026
Source: NVD
CVE-2026-46606 HIGH - 7.8

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

Vendor: maven
Product: org.openidentityplatform.opendj:opendj-server-legacy
Published: Jun 22, 2026
Source: GitHub

motionEye: Authentication possible via password hash

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44795 HIGH - 8.5

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

Vendor: maven
Product: io.spinnaker.rosco:rosco-core
Published: Jun 22, 2026
Source: GitHub

OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`

Vendor: maven
Product: org.openidentityplatform.openam:openam-federation-library
Published: Jun 22, 2026
Source: GitHub

Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)

Vendor: go
Product: github.com/inspektor-gadget/inspektor-gadget
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44585 MEDIUM - 5.4

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44584 MEDIUM - 4.3

Paymenter doesn't reset email verification status after email change

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44583 MEDIUM - 5.3

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Vendor: nodejs
Product: node
Published: Jun 22, 2026
Source: NVD
CVE-2026-44274 HIGH - 7.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44273 MEDIUM - 6.0

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44272 HIGH - 8.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44271 HIGH - 8.1

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-10852 MEDIUM - 5.9

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

Vendor: IBM
Product: i
Published: Jun 22, 2026
Source: NVD
CVE-2026-44517 MEDIUM - 6.3

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

Vendor: go
Product: github.com/containers/buildah
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44203 CRITICAL - 9.3

OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 22, 2026
Source: GitHub

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44179 CRITICAL - 9.9

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

Vendor: maven
Product: com.xwiki.pro:xwiki-pro-macros
Published: Jun 22, 2026
Source: GitHub