Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 321 - 340 of 35,345 CVEs
CVE-2026-5139 MEDIUM - 5.4

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler, which allows any authenticated user to overwrite the global default...

Vendor: mattermost
Product: mattermost_server
Published: Jun 22, 2026
Source: NVD

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-for...

Vendor: ail project
Product: ail framework
Published: Jun 22, 2026
Source: NVD

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon,...

Vendor: ail project
Product: ail framework
Published: Jun 22, 2026
Source: NVD
CVE-2026-56447 HIGH - 7.2

MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka options such as plugin.libr...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-56446 HIGH - 7.2

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could direct log output to a PHP file in a web-accessibl...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the PHP session identifier (session_id()) as the OAuth ...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-56424 HIGH - 8.8

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature permission could cau...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-56423 HIGH - 8.8

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for each selected object. For Event Reports, EventReport...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-54100 HIGH - 8.3

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can captu...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers
Published: Jun 22, 2026
Source: NVD
CVE-2026-54099 HIGH - 8.8

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A co...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers
Published: Jun 22, 2026
Source: NVD
CVE-2026-42129 HIGH - 7.7

The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and in...

Vendor: Grafana
Product: Grafana OSS
Published: Jun 22, 2026
Source: NVD
CVE-2026-28381 CRITICAL - 9.6

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.

Vendor: Grafana
Product: Snowflake Datasource
Published: Jun 22, 2026
Source: NVD

An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links. This issue affects Canarytokens: from Docker tag sha-4aef1db90...

Vendor: Thinkst Applied Research
Product: Canarytokens
Published: Jun 22, 2026
Source: NVD

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program Files have excessive perm...

Vendor: Aruba
Product: ArubaSign
Published: Jun 22, 2026
Source: NVD
CVE-2026-10601 MEDIUM - 5.4

The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an att...

Vendor: Grafana
Product: Grafana OSS
Published: Jun 22, 2026
Source: NVD
CVE-2026-10561 CRITICAL - 10.0

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

Vendor: IBM
Product: Langflow OSS
Published: Jun 22, 2026
Source: NVD
CVE-2025-66389 HIGH - 7.5

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.

Published: Jun 22, 2026
Source: NVD
CVE-2025-33128 MEDIUM - 5.4

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...

Vendor: IBM
Product: Engineering Workflow Management
Published: Jun 22, 2026
Source: NVD
CVE-2025-2669 MEDIUM - 6.0

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.

Published: Jun 22, 2026
Source: NVD
CVE-2024-54178 MEDIUM - 6.5

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.

Vendor: IBM
Product: Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
Published: Jun 22, 2026
Source: NVD