Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

962
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,761 - 3,780 of 35,348 CVEs

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This iss...

Vendor: TYPO3
Product: TYPO3 CMS
Published: Jun 09, 2026
Source: NVD

Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to e...

Vendor: TYPO3
Product: TYPO3 CMS
Published: Jun 09, 2026
Source: NVD

Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0 through 11.5.50, 12.0.0 th...

Vendor: TYPO3
Product: TYPO3 CMS
Published: Jun 09, 2026
Source: NVD

Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to esc...

Vendor: TYPO3
Product: TYPO3 CMS
Published: Jun 09, 2026
Source: NVD
CVE-2026-52902 MEDIUM - 4.7

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.fo...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jun 09, 2026
Source: NVD
CVE-2026-4058 MEDIUM - 4.3

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2...

Published: Jun 09, 2026
Source: NVD
CVE-2026-46749 HIGH - 7.5

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could all...

Vendor: Siemens
Product: SINEC INS
Published: Jun 09, 2026
Source: NVD
CVE-2026-46748 HIGH - 8.8

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system acc...

Vendor: Siemens
Product: SINEC INS
Published: Jun 09, 2026
Source: NVD
CVE-2026-46747 MEDIUM - 4.3

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintend...

Vendor: Siemens
Product: SINEC INS
Published: Jun 09, 2026
Source: NVD
CVE-2026-46746 HIGH - 8.8

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed wh...

Vendor: Siemens
Product: SINEC INS
Published: Jun 09, 2026
Source: NVD
CVE-2026-41031 HIGH - 8.7

A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session...

Vendor: Skilja GmbH
Product: Vinna Process Monitor
Published: Jun 09, 2026
Source: NVD
CVE-2026-24349 HIGH - 7.1

A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All version...

Vendor: Siemens
Product: SIMATIC WinCC Unified PC Runtime V16, SIMATIC WinCC Unified PC Runtime V17, SIMATIC WinCC Unified PC Runtime V18, SIMATIC WinCC Unified PC Runtime V19, SIMATIC WinCC Unified PC Runtime V20, SIMATIC WinCC Unified PC Runtime V21
Published: Jun 09, 2026
Source: NVD

SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be accessed without prior authentication, allowing unauthenticated attackers to execute arbitrary SQL que...

Vendor: Nemon
Product: Nemon Trade Energy, Nemon Trade Energy CRM
Published: Jun 09, 2026
Source: NVD
CVE-2025-40808 MEDIUM - 6.1

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU8...

Published: Jun 09, 2026
Source: NVD
CVE-2025-10263 CRITICAL - 9.1

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher except...

Vendor: Arm
Product: C1-Ultra, C1-Premium, Neoverse V3, Neoverse V3AE, Neoverse V1, Neoverse N2, Neoverse N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1, Cortex-X1C, Cortex-A710, Cortex-A78, Cortex-A78AE, Cortex-A78C, Cortex-A77, Cortex-A76, Cortex-A76AE
Published: Jun 09, 2026
Source: NVD
CVE-2026-8677 MEDIUM - 6.4

The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible fo...

Published: Jun 09, 2026
Source: NVD
CVE-2026-8599 MEDIUM - 6.4

The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Content Field in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This make...

Published: Jun 09, 2026
Source: NVD
CVE-2026-8365 HIGH - 8.8

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_m...

Published: Jun 09, 2026
Source: NVD
CVE-2026-7542 MEDIUM - 6.5

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to and including 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via...

Published: Jun 09, 2026
Source: NVD
CVE-2026-6899 MEDIUM - 5.6

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.

Published: Jun 09, 2026
Source: NVD