Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,976
Quick preset (or use dates below)
Clear Filters
Showing 421 - 440 of 3,520 CVEs
CVE-2026-11638 CRITICAL - 9.6

Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11634 CRITICAL - 9.6

Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-47724 CRITICAL - 9.9

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47252 CRITICAL - 9.0

Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin

Vendor: go
Product: github.com/julien040/anyquery/plugins/chrome
Published: Jun 08, 2026
Source: GitHub

PHPSpreadsheet has a patch bypass for CVE-2026-34084

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Jun 08, 2026
Source: GitHub
CVE-2026-52778 CRITICAL - 9.8

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing...

Vendor: YesWiki
Product: yeswiki
Published: Jun 08, 2026
Source: NVD
CVE-2026-11393 CRITICAL - 9.0

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of anot...

Vendor: AWS
Product: AgentCore CLI
Published: Jun 08, 2026
Source: NVD
CVE-2026-46289 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. Fix bugs in the kvec and user variants of extract_iter_to_sg. This series is growing due to useful rem...

Vendor: Linux
Product: Linux
Published: Jun 08, 2026
Source: NVD
CVE-2026-41448 CRITICAL - 9.4

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path cons...

Vendor: AdguardTeam
Product: AdGuardHome
Published: Jun 08, 2026
Source: NVD
CVE-2026-39910 CRITICAL - 9.8

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvalidated PUT servers...

Vendor: STACKIT
Product: IaaS API
Published: Jun 08, 2026
Source: NVD
CVE-2026-25555 CRITICAL - 9.8

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied h...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-46442 CRITICAL - 9.9

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_A...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-46441 CRITICAL - 9.6

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceI...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-44631 CRITICAL - 9.8

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-42535 CRITICAL - 9.1

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-29167 CRITICAL - 9.8

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-50751 CRITICAL - 9.3

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Vendor: checkpoint
Product: Quantum Security Gateway, Spark Firewalls
Published: Jun 08, 2026
Source: NVD
CVE-2026-11499 CRITICAL - 9.8

A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.

Vendor: Tenda
Product: HG7HG9, HG10
Published: Jun 08, 2026
Source: NVD
CVE-2024-58349 CRITICAL - 9.8

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute th...

Vendor: WP Travel Kit
Product: Travelscape
Published: Jun 08, 2026
Source: NVD
CVE-2024-58348 CRITICAL - 9.8

WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary co...

Vendor: background-image-cropper
Product: Background Image Cropper
Published: Jun 08, 2026
Source: NVD