Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,981
Quick preset (or use dates below)
Clear Filters
Showing 561 - 580 of 3,522 CVEs
CVE-2026-38967 CRITICAL - 9.8

CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

Published: Jun 02, 2026
Source: NVD
CVE-2026-0611 CRITICAL - 9.8

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying...

Published: Jun 02, 2026
Source: NVD
CVE-2026-47117 CRITICAL - 9.8

OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path th...

Vendor: maziyarpanahi
Product: openmed
Published: Jun 02, 2026
Source: NVD
CVE-2026-10629 CRITICAL - 9.1

SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server headers and ESP traffic), which allows an on-path attacker to compromise confidentiality, integrity, and authenticity of VoLTE signaling via p...

Vendor: Verizon
Product: VoLTE
Published: Jun 02, 2026
Source: NVD
CVE-2026-7312 CRITICAL - 10.0

CWEโ€‘522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obt...

Vendor: progress
Product: sitefinity
Published: Jun 02, 2026
Source: NVD
CVE-2026-7198 CRITICAL - 9.8

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.

Vendor: progress
Product: sitefinity
Published: Jun 02, 2026
Source: NVD
CVE-2026-42684 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

Vendor: Ahmad
Product: WP Job Portal
Published: Jun 02, 2026
Source: NVD
CVE-2025-53209 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.

Vendor: Themeisle
Product: Masteriyo LMS PRO
Published: Jun 02, 2026
Source: NVD
CVE-2026-8206 CRITICAL - 9.8

The Kirki โ€“ Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. Th...

Published: Jun 02, 2026
Source: NVD
CVE-2026-40965 CRITICAL - 10.0

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JW...

Vendor: Cloud Foundry Foundation
Product: uaa_release, CF Deployment
Published: Jun 01, 2026
Source: NVD
CVE-2018-25427 CRITICAL - 9.8

Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception hand...

Vendor: Armcode
Product: Arm Whois
Published: Jun 01, 2026
Source: NVD
CVE-2026-9319 CRITICAL - 9.0

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

Vendor: ibm
Product: websphere_application_server
Published: Jun 01, 2026
Source: NVD
CVE-2026-9311 CRITICAL - 9.0

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Vendor: ibm
Product: websphere_application_server
Published: Jun 01, 2026
Source: NVD
CVE-2026-8644 CRITICAL - 9.1

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Vendor: ibm
Product: websphere_application_server
Published: Jun 01, 2026
Source: NVD
CVE-2026-45132 CRITICAL - 10.0

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. T...

Vendor: CloudPirates-io
Product: helm-charts
Published: Jun 01, 2026
Source: NVD
CVE-2026-45131 CRITICAL - 10.0

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens witho...

Vendor: CloudPirates-io
Product: helm-charts
Published: Jun 01, 2026
Source: NVD
CVE-2026-42672 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

Vendor: Wp Directory Kit
Product: WP Directory Kit
Published: Jun 01, 2026
Source: NVD
CVE-2026-48879 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

Vendor: Sergey
Product: AIWU
Published: Jun 01, 2026
Source: NVD
CVE-2026-48866 CRITICAL - 9.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

Vendor: Rocketgenius Inc.
Product: Gravity Forms
Published: Jun 01, 2026
Source: NVD
CVE-2026-42682 CRITICAL - 9.1

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

Vendor: Tomdever
Product: wpForo Forum
Published: Jun 01, 2026
Source: NVD