Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,443
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 421 - 440 of 11,951 CVEs
CVE-2025-27511 HIGH - 7.2

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

Vendor: maven
Product: org.geoserver.extension:gs-db2
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48099 HIGH - 7.1

WsgiDAV encoded dot segments can escape filesystem share roots

Vendor: pip
Product: wsgidav
Published: Jun 11, 2026
Source: GitHub

DevGuard has improper authorization on public assets

Vendor: go
Product: github.com/l3montree-dev/devguard
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48059 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested ...

Vendor: maven
Product: io.netty:netty-codec-haproxy
Published: Jun 11, 2026
Source: GitHub
CVE-2026-53782 HIGH - 7.4

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, or other reserved destinations by supplying malicio...

Vendor: steipete
Product: summarize
Published: Jun 11, 2026
Source: NVD
CVE-2026-46622 HIGH - 8.1

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database โ€” through SQL injection, a leaked backup, a misconf...

Vendor: SolidInvoice
Product: SolidInvoice
Published: Jun 11, 2026
Source: NVD
CVE-2026-46489 HIGH - 8.1

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every ...

Vendor: SolidInvoice
Product: SolidInvoice
Published: Jun 11, 2026
Source: NVD
CVE-2026-52860 HIGH - 7.8

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD
CVE-2026-52859 HIGH - 8.2

Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stoppi...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD
CVE-2026-52858 HIGH - 7.8

Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and from statements found...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD
CVE-2026-48547 HIGH - 7.3

KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() cal...

Vendor: lingdojo
Product: kana-dojo
Published: Jun 11, 2026
Source: NVD
CVE-2026-47170 HIGH - 7.7

Garlic-Hub manages digital signage network โ€” devices, content, and playlists โ€” from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HTTP requests to internal services via the uploadFromUrl endpoint. This allows internal port scanning,...

Vendor: garlic-signage
Product: garlic-hub
Published: Jun 11, 2026
Source: NVD
CVE-2026-47162 HIGH - 8.8

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A ...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD
CVE-2026-11774 HIGH - 7.6

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap ...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 11, 2026
Source: NVD
CVE-2025-46315 HIGH - 7.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-31272 HIGH - 7.8

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-24284 HIGH - 8.8

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2026-48546 HIGH - 7.3

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull r...

Vendor: lingdojo
Product: kana-dojo
Published: Jun 11, 2026
Source: NVD
CVE-2026-46697 HIGH - 7.5

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($...

Vendor: stefanbohacek
Product: fediverse-embeds-wordpress-plugin
Published: Jun 11, 2026
Source: NVD
CVE-2026-49982 HIGH - 8.2

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when prefix, postfix, or template is supplied as a non-string value (Array, Buffer, or any object) whose includes(&...

Vendor: raszi
Product: node-tmp
Published: Jun 11, 2026
Source: NVD