Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
Showing 401 - 420 of 3,520 CVEs
CVE-2026-25089 CRITICAL - 9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through ...

Vendor: Fortinet
Product: FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS
Published: Jun 09, 2026
Source: NVD
CVE-2026-10523 CRITICAL - 9.9

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Vendor: ivanti
Product: Sentry
Published: Jun 09, 2026
Source: NVD
CVE-2026-10520 CRITICAL - 10.0

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Vendor: ivanti
Product: Sentry
Published: Jun 09, 2026
Source: NVD
CVE-2026-7486 CRITICAL - 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection. This issue affects E-İmar: from 2.10.1.0 before 3.0.2.

Published: Jun 09, 2026
Source: NVD
CVE-2026-46325 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles memory regions (MRs) with page sizes different from the system PAGE_SIZE. The core issue is that rxe_set_page() is c...

Vendor: Linux
Product: Linux
Published: Jun 09, 2026
Source: NVD
CVE-2026-46316 CRITICAL - 9.3

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each entry with vgic_p...

Vendor: Linux
Product: Linux
Published: Jun 09, 2026
Source: NVD
CVE-2017-20251 CRITICAL - 9.8

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with...

Vendor: Themeisle
Product: Woody Code Snippets
Published: Jun 09, 2026
Source: NVD
CVE-2025-10263 CRITICAL - 9.1

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher except...

Vendor: Arm
Product: C1-Ultra, C1-Premium, Neoverse V3, Neoverse V3AE, Neoverse V1, Neoverse N2, Neoverse N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1, Cortex-X1C, Cortex-A710, Cortex-A78, Cortex-A78AE, Cortex-A78C, Cortex-A77, Cortex-A76, Cortex-A76AE
Published: Jun 09, 2026
Source: NVD
CVE-2009-10007 CRITICAL - 9.1

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

Vendor: ETHER
Product: Catalyst::Plugin::Authentication
Published: Jun 09, 2026
Source: NVD
CVE-2026-9698 CRITICAL - 9.8

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buf...

Vendor: perl
Product: dbi
Published: Jun 09, 2026
Source: NVD
CVE-2026-44083 CRITICAL - 9.8

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later

Vendor: QNAP Systems Inc.
Product: QuMagie
Published: Jun 09, 2026
Source: NVD
CVE-2026-5067 CRITICAL - 9.8

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy that does not guarantee NUL termination when th...

Published: Jun 09, 2026
Source: NVD
CVE-2026-44748 CRITICAL - 9.9

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to se...

Vendor: SAP_SE
Product: SAP NetWeaver AS ABAP and ABAP Platform
Published: Jun 09, 2026
Source: NVD
CVE-2026-40128 CRITICAL - 9.0

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or m...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server Java (Web Container)
Published: Jun 09, 2026
Source: NVD
CVE-2026-27671 CRITICAL - 9.8

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impa...

Vendor: SAP_SE
Product: SAP NetWeaver and ABAP Platform
Published: Jun 09, 2026
Source: NVD
CVE-2026-11697 CRITICAL - 9.6

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11671 CRITICAL - 9.6

Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11659 CRITICAL - 9.6

Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11654 CRITICAL - 9.6

Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11651 CRITICAL - 9.6

Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD