Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,364
Quick preset (or use dates below)
Clear Filters
Showing 501 - 520 of 12,261 CVEs
CVE-2026-49822 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent s...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-49821 HIGH - 7.7

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying that Package.spec.environment.namespace matched Package...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-20258 HIGH - 7.1

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could store a malicious script...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20252 HIGH - 7.6

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could send server...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-20251 HIGH - 8.8

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin'...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform, Splunk Secure Gateway
Published: Jun 10, 2026
Source: NVD
CVE-2026-11417 HIGH - 7.3

OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host run...

Vendor: AWS
Product: AWS Cloud Development Kit library
Published: Jun 10, 2026
Source: NVD
CVE-2026-47701 HIGH - 7.7

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

Vendor: go
Product: github.com/open-telemetry/opentelemetry-operator
Published: Jun 10, 2026
Source: GitHub
CVE-2026-47253 HIGH - 7.3

Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion

Vendor: go
Product: github.com/julien040/anyquery
Published: Jun 10, 2026
Source: GitHub
CVE-2025-53114 HIGH - 7.5

Acknowledgement extension out of memory

Vendor: maven
Product: org.cometd.java:cometd-java-server-common
Published: Jun 10, 2026
Source: GitHub
CVE-2026-49759 HIGH - 8.2

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause code...

Vendor: Erlang
Product: OTP
Published: Jun 10, 2026
Source: NVD
CVE-2026-46558 HIGH - 8.3

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.

Vendor: makeplane
Product: plane
Published: Jun 10, 2026
Source: NVD
CVE-2026-45569 HIGH - 8.1

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-mem...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-45567 HIGH - 8.3

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches.

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-45565 HIGH - 8.1

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-25700 HIGH - 7.2

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to admini...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 10, 2026
Source: NVD
CVE-2026-9045 HIGH - 7.8

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Published: Jun 10, 2026
Source: NVD
CVE-2026-8637 HIGH - 7.8

A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Published: Jun 10, 2026
Source: NVD
CVE-2026-6090 HIGH - 7.0

A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Published: Jun 10, 2026
Source: NVD
CVE-2026-53689 HIGH - 7.1

libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.

Vendor: sahlberg
Product: libnfs
Published: Jun 10, 2026
Source: NVD
CVE-2026-53473 HIGH - 7.3

A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational user clicks this link in the user interface, the embedded malicious code executes within the user's browse...

Vendor: kubev2v
Product: migration_planner_ui
Published: Jun 10, 2026
Source: NVD