Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
Showing 361 - 380 of 3,310 CVEs
CVE-2026-9311 CRITICAL - 9.0

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Vendor: ibm
Product: websphere_application_server
Published: Jun 01, 2026
Source: NVD
CVE-2026-8644 CRITICAL - 9.1

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Vendor: ibm
Product: websphere_application_server
Published: Jun 01, 2026
Source: NVD
CVE-2026-45132 CRITICAL - 10.0

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. T...

Vendor: CloudPirates-io
Product: helm-charts
Published: Jun 01, 2026
Source: NVD
CVE-2026-45131 CRITICAL - 10.0

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens witho...

Vendor: CloudPirates-io
Product: helm-charts
Published: Jun 01, 2026
Source: NVD
CVE-2026-42672 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

Vendor: Wp Directory Kit
Product: WP Directory Kit
Published: Jun 01, 2026
Source: NVD
CVE-2026-48879 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

Vendor: Sergey
Product: AIWU
Published: Jun 01, 2026
Source: NVD
CVE-2026-48866 CRITICAL - 9.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

Vendor: Rocketgenius Inc.
Product: Gravity Forms
Published: Jun 01, 2026
Source: NVD
CVE-2026-42682 CRITICAL - 9.1

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

Vendor: Tomdever
Product: wpForo Forum
Published: Jun 01, 2026
Source: NVD
CVE-2026-42680 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

Vendor: Wasiliy Strecker / ContestGallery developer
Product: Contest Gallery Pro
Published: Jun 01, 2026
Source: NVD
CVE-2026-47413 CRITICAL - 9.6

praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47428 CRITICAL - 9.6

Vitest browser mode serves unsanitized otelCarrier query parameter as inline script

Vendor: npm
Product: @vitest/browser
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47429 CRITICAL - 9.8

When Vitest UI server is listening, arbitrary file can be read and executed

Vendor: npm
Product: vitest
Published: Jun 01, 2026
Source: GitHub
CVE-2026-7858 CRITICAL - 9.8

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.

Published: Jun 01, 2026
Source: NVD
CVE-2026-42252 CRITICAL - 9.1

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag auth...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Jun 01, 2026
Source: NVD
CVE-2026-48188 CRITICAL - 9.1

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mo...

Vendor: OTRS AG
Product: OTRS, ((OTRS)) Community Edition
Published: Jun 01, 2026
Source: NVD
CVE-2026-10187 CRITICAL - 9.8

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is pos...

Vendor: Totolink
Product: N300RH
Published: May 31, 2026
Source: NVD
CVE-2018-25412 CRITICAL - 9.8

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them...

Vendor: Deltasql
Product: Delta Sql
Published: May 30, 2026
Source: NVD
CVE-2026-47416 CRITICAL - 9.6

praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47410 CRITICAL - 9.8

praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub

PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub