Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,443
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 481 - 500 of 11,951 CVEs
CVE-2026-2049 HIGH - 7.8

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or o...

Published: Jun 10, 2026
Source: NVD
CVE-2026-10143 HIGH - 7.5

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.process_server_first_message() p...

Vendor: Dana Powers
Product: kafka-python
Published: Jun 10, 2026
Source: NVD
CVE-2026-10142 HIGH - 7.5

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a speciall...

Vendor: Dana Powers
Product: kafka-python
Published: Jun 10, 2026
Source: NVD
CVE-2022-26758 HIGH - 7.1

A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4.

Vendor: Apple
Product: macOS Monterey
Published: Jun 10, 2026
Source: NVD

PDM wheel installation leads to Path Traversal via overridden write_to_fs

Vendor: pip
Product: pdm
Published: Jun 10, 2026
Source: GitHub
CVE-2026-6893 HIGH - 8.8

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled...

Published: Jun 10, 2026
Source: NVD
CVE-2026-1220 HIGH - 7.5

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Jun 10, 2026
Source: NVD
CVE-2026-50637 HIGH - 8.2

Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the name...

Vendor: PEVANS
Product: Metrics::Any::Adapter::Statsd
Published: Jun 10, 2026
Source: NVD
CVE-2026-48060 HIGH - 8.1

Litestar has HTML Injection Through its CSRF Token

Vendor: pip
Product: litestar
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50570 HIGH - 8.5

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSaf...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50567 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Unarchive in pkg/utils/zip.go joined each archive entry name with the destination directory via filepath.Join and wrote the result wi...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49824 HIGH - 8.5

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namesp...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49823 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types โ€” Secret, ConfigMap, and Package. The first two were namespace-validated by the...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49822 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent s...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49821 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying that Package.spec.environment.namespace matched Package...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-20258 HIGH - 7.1

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could store a malicious script...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20252 HIGH - 7.6

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could send server...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20251 HIGH - 8.8

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin'...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform, Splunk Secure Gateway
Published: Jun 10, 2026
Source: NVD
CVE-2026-11417 HIGH - 7.3

OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host run...

Vendor: AWS
Product: AWS Cloud Development Kit library
Published: Jun 10, 2026
Source: NVD
CVE-2026-47701 HIGH - 7.7

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

Vendor: go
Product: github.com/open-telemetry/opentelemetry-operator
Published: Jun 10, 2026
Source: GitHub