Total CVEs

137,228

Critical Severity

3,305

High Severity

12,247

Last 7 Days

1,452
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 521 - 540 of 11,944 CVEs
CVE-2026-49396 HIGH - 7.1

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on a victim's agents. This issue has been patched in version 2.0.14.

Vendor: go
Product: github.com/nezhahq/nezha
Published: Jun 10, 2026
Source: GitHub

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

Vendor: npm
Product: @hulumi/drift
Published: Jun 10, 2026
Source: GitHub

@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened

Vendor: npm
Product: @hulumi/baseline
Published: Jun 10, 2026
Source: GitHub

@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

Vendor: npm
Product: @hulumi/policies
Published: Jun 10, 2026
Source: GitHub

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

Vendor: npm
Product: @hulumi/policies
Published: Jun 10, 2026
Source: GitHub

@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers

Vendor: npm
Product: @hulumi/policies
Published: Jun 10, 2026
Source: GitHub
CVE-2026-24067 HIGH - 8.4

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and...

Vendor: Slate Digital LLC
Product: Slate Digital Connect
Published: Jun 10, 2026
Source: NVD
CVE-2026-24066 HIGH - 8.4

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client&#...

Vendor: Slate Digital LLC
Product: Slate Digital Connect
Published: Jun 10, 2026
Source: NVD
CVE-2026-3018 HIGH - 7.5

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published: Jun 10, 2026
Source: NVD
CVE-2026-8071 HIGH - 8.8

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (includi...

Published: Jun 10, 2026
Source: NVD
CVE-2026-3326 HIGH - 8.6

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Published: Jun 10, 2026
Source: NVD
CVE-2026-11837 HIGH - 7.3

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links i...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0
Published: Jun 10, 2026
Source: NVD
CVE-2026-26239 HIGH - 8.1

A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2026-26237 HIGH - 7.5

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later

Vendor: QNAP Systems Inc.
Product: QuMagie
Published: Jun 10, 2026
Source: NVD
CVE-2026-24724 HIGH - 8.1

An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243...

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2026-24719 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2026-24716 HIGH - 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follow...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2026-22893 HIGH - 7.2

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5....

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66281 HIGH - 7.2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2025-66280 HIGH - 7.2

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the f...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD