Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,368
Quick preset (or use dates below)
Clear Filters
Showing 481 - 500 of 12,261 CVEs
CVE-2026-44693 HIGH - 8.8

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue ...

Vendor: pi-hole
Product: FTL
Published: Jun 10, 2026
Source: NVD
CVE-2026-42558 HIGH - 7.6

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users with DataSet permissions to use the Data Connector functiona...

Vendor: xibosignage
Product: xibo-cms
Published: Jun 10, 2026
Source: NVD
CVE-2026-53738 HIGH - 8.1

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

Vendor: Inisev
Product: Copy & Delete Posts
Published: Jun 10, 2026
Source: NVD
CVE-2026-50131 HIGH - 8.6

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the IPv4 validation logic present starting in...

Vendor: fedify-dev
Product: fedify, vocab-runtime
Published: Jun 10, 2026
Source: NVD
CVE-2026-48110 HIGH - 7.5

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled SSH strings, name-lists, and byte fields into owned allocations before applying field-specific bounds. A remote SSH peer could s...

Vendor: Eugeny
Product: russh
Published: Jun 10, 2026
Source: NVD
CVE-2026-46669 HIGH - 7.5

OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem 3 of https://eprint.iacr.org/2024/640.pdf but does not check that the scaling factor s is in ...

Vendor: openvm-org
Product: openvm
Published: Jun 10, 2026
Source: NVD
CVE-2026-42542 HIGH - 7.5

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3....

Vendor: taosdata
Product: TDengine
Published: Jun 10, 2026
Source: NVD
CVE-2026-2049 HIGH - 7.8

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or o...

Published: Jun 10, 2026
Source: NVD
CVE-2026-10143 HIGH - 7.5

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.process_server_first_message() p...

Vendor: Dana Powers
Product: kafka-python
Published: Jun 10, 2026
Source: NVD
CVE-2026-10142 HIGH - 7.5

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a speciall...

Vendor: Dana Powers
Product: kafka-python
Published: Jun 10, 2026
Source: NVD
CVE-2022-26758 HIGH - 7.1

A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4.

Vendor: Apple
Product: macOS Monterey
Published: Jun 10, 2026
Source: NVD

PDM wheel installation leads to Path Traversal via overridden write_to_fs

Vendor: pip
Product: pdm
Published: Jun 10, 2026
Source: GitHub
CVE-2026-6893 HIGH - 8.8

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled...

Published: Jun 10, 2026
Source: NVD
CVE-2026-1220 HIGH - 7.5

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Jun 10, 2026
Source: NVD
CVE-2026-50637 HIGH - 8.2

Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the name...

Vendor: PEVANS
Product: Metrics::Any::Adapter::Statsd
Published: Jun 10, 2026
Source: NVD
CVE-2026-48060 HIGH - 8.1

Litestar has HTML Injection Through its CSRF Token

Vendor: pip
Product: litestar
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50570 HIGH - 8.5

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSaf...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50567 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Unarchive in pkg/utils/zip.go joined each archive entry name with the destination directory via filepath.Join and wrote the result wi...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49824 HIGH - 8.5

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namesp...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49823 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types โ€” Secret, ConfigMap, and Package. The first two were namespace-validated by the...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD