Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

962
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 341 - 360 of 35,348 CVEs
CVE-2025-33128 MEDIUM - 5.4

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...

Vendor: IBM
Product: Engineering Workflow Management
Published: Jun 22, 2026
Source: NVD
CVE-2025-2669 MEDIUM - 6.0

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.

Published: Jun 22, 2026
Source: NVD
CVE-2024-54178 MEDIUM - 6.5

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.

Vendor: IBM
Product: Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
Published: Jun 22, 2026
Source: NVD

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object identifiers) without consistentl...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-11373 CRITICAL - 9.1

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol...

Vendor: JASEI
Product: Net::Statsite::Client
Published: Jun 22, 2026
Source: NVD

An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.

Vendor: pretix
Product: Venueless
Published: Jun 22, 2026
Source: NVD

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

Vendor: pretix
Product: Venueless
Published: Jun 22, 2026
Source: NVD
CVE-2026-12581 HIGH - 7.5

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

Vendor: Digiwin
Product: EasyFlow .NET
Published: Jun 22, 2026
Source: NVD
CVE-2026-12580 MEDIUM - 5.4

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.

Vendor: Digiwin
Product: EasyFlow .NET
Published: Jun 22, 2026
Source: NVD

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface....

Published: Jun 22, 2026
Source: NVD
CVE-2023-45796 HIGH - 8.1

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.

Vendor: Pilz
Product: PMI v8xx, PASvisu
Published: Jun 22, 2026
Source: NVD
CVE-2023-45795 HIGH - 7.8

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.

Vendor: Pilz
Product: PMI v8xx, PASvisu
Published: Jun 22, 2026
Source: NVD
CVE-2026-54665 MEDIUM - 5.3

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2026-44914 HIGH - 7.2

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not ch...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2026-44913 HIGH - 7.2

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2026-44911 MEDIUM - 6.3

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verif...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2025-66336 HIGH - 8.1

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anony...

Vendor: Apache Software Foundation
Product: Apache Doris MCP Server
Published: Jun 22, 2026
Source: NVD
CVE-2025-62198 MEDIUM - 5.4

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Atlas
Published: Jun 22, 2026
Source: NVD
CVE-2026-8157 HIGH - 8.8

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

Published: Jun 22, 2026
Source: NVD
CVE-2026-7859 MEDIUM - 5.3

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

Published: Jun 22, 2026
Source: NVD