Total CVEs

137,228

Critical Severity

3,305

High Severity

12,247

Last 7 Days

1,449
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 501 - 520 of 11,944 CVEs
CVE-2026-25700 HIGH - 7.2

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to admini...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 10, 2026
Source: NVD
CVE-2026-9045 HIGH - 7.8

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Published: Jun 10, 2026
Source: NVD
CVE-2026-8637 HIGH - 7.8

A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Published: Jun 10, 2026
Source: NVD
CVE-2026-6090 HIGH - 7.0

A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Published: Jun 10, 2026
Source: NVD
CVE-2026-53689 HIGH - 7.1

libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.

Vendor: sahlberg
Product: libnfs
Published: Jun 10, 2026
Source: NVD
CVE-2026-53473 HIGH - 7.3

A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational user clicks this link in the user interface, the embedded malicious code executes within the user's browse...

Vendor: kubev2v
Product: migration_planner_ui
Published: Jun 10, 2026
Source: NVD
CVE-2026-45564 HIGH - 8.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.sy...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-45549 HIGH - 8.5

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only โ€” no role check, no group ownership ...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-9758 HIGH - 7.3

Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted

Published: Jun 10, 2026
Source: NVD
CVE-2026-53435 HIGH - 8.8

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to imp...

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-52758 HIGH - 8.8

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the Po...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52755 HIGH - 7.8

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive ...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52754 HIGH - 8.8

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repo...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52752 HIGH - 7.8

Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling ...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52751 HIGH - 8.8

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File โ†’ Open Project, deserializes untrusted...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52750 HIGH - 7.8

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims cli...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49498 HIGH - 8.8

Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements. Authenticated attackers can inject SQL commands via crafted username parameters in Passwo...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49069 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.

Vendor: WPZOOM
Product: WPZOOM Portfolio
Published: Jun 10, 2026
Source: NVD
CVE-2025-71330 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to tri...

Vendor: image-size
Product: image-size
Published: Jun 10, 2026
Source: NVD
CVE-2025-71329 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF...

Vendor: image-size
Product: image-size
Published: Jun 10, 2026
Source: NVD