Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,339
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,781 - 2,800 of 33,692 CVEs
CVE-2026-9088 LOW - 2.7

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leadin...

Published: Jun 05, 2026
Source: NVD

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Vendor: joomlacontenteditor.net
Product: Joomla Content Editor (JCE) extension for Joomla
Published: Jun 05, 2026
Source: NVD
CVE-2026-21837 HIGH - 8.8

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover an...

Vendor: HCLSoftware
Product: Digital Experience
Published: Jun 05, 2026
Source: NVD
CVE-2026-21826 MEDIUM - 6.1

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

Vendor: HCLSoftware
Product: Digital Experience & DX Compose
Published: Jun 05, 2026
Source: NVD
CVE-2026-21825 MEDIUM - 6.1

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

Vendor: HCLSoftware
Product: DX Compose
Published: Jun 05, 2026
Source: NVD
CVE-2026-10732 MEDIUM - 6.4

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written...

Product: decompress
Published: Jun 05, 2026
Source: NVD
CVE-2026-50593 HIGH - 7.3

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

Vendor: Graphite project
Product: Graphite
Published: Jun 05, 2026
Source: NVD
CVE-2026-7763 CRITICAL - 9.8

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a craf...

Published: Jun 05, 2026
Source: NVD
CVE-2026-7762 CRITICAL - 9.8

A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a cr...

Published: Jun 05, 2026
Source: NVD
CVE-2026-50592 MEDIUM - 6.4

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).

Vendor: Znuny
Product: Znuny
Published: Jun 05, 2026
Source: NVD
CVE-2026-50591 MEDIUM - 5.4

IN Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.

Vendor: Znuny
Product: Znuny
Published: Jun 05, 2026
Source: NVD
CVE-2026-50590 MEDIUM - 4.5

In Mimecast Incydr before 2.6.0, arbitrary file access can occur.

Vendor: Mimecast
Product: Incydr
Published: Jun 05, 2026
Source: NVD

OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atl...

Vendor: OpenAI
Product: OpenAI Atlas
Published: Jun 05, 2026
Source: NVD

A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV Map Handler. Performing a manipulation results in inefficient algorithmic complexity. The attack requires a local approach. The exp...

Vendor: bytedance
Product: InfiniStore
Published: Jun 05, 2026
Source: NVD
CVE-2026-50589 MEDIUM - 5.3

In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

Vendor: OpenStack
Product: Ironic
Published: Jun 05, 2026
Source: NVD
CVE-2026-11309 MEDIUM - 4.3

Insufficient policy enforcement in History in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11308 MEDIUM - 6.3

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11307 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11306 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11305 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD