Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,750
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 41 - 60 of 35,133 CVEs
CVE-2026-44273 MEDIUM - 6.0

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44272 HIGH - 8.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44271 HIGH - 8.1

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-10852 MEDIUM - 5.9

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

Vendor: IBM
Product: i
Published: Jun 22, 2026
Source: NVD
CVE-2026-44517 MEDIUM - 6.3

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

Vendor: go
Product: github.com/containers/buildah
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44203 CRITICAL - 9.3

OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 22, 2026
Source: GitHub

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44179 CRITICAL - 9.9

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

Vendor: maven
Product: com.xwiki.pro:xwiki-pro-macros
Published: Jun 22, 2026
Source: GitHub
CVE-2026-41579 MEDIUM - 3.3

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

Vendor: go
Product: github.com/opencontainers/runc
Published: Jun 22, 2026
Source: GitHub

OpenAM has LDAP Injection via `_queryId` Parameter

Vendor: maven
Product: org.openidentityplatform.openam:openam-core-rest
Published: Jun 22, 2026
Source: GitHub
CVE-2026-33731 MEDIUM - 6.5

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

Vendor: composer
Product: wwbn/avideo
Published: Jun 22, 2026
Source: GitHub
CVE-2026-33692 HIGH - 7.5

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

Vendor: composer
Product: wwbn/avideo
Published: Jun 22, 2026
Source: GitHub
CVE-2026-55443 MEDIUM - 5.1

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agen...

Vendor: langchain-ai
Product: langchain, langchain-anthropic
Published: Jun 22, 2026
Source: NVD
CVE-2026-53779 HIGH - 7.5

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with percent-encoded backslashes (%5C) that bypass the path.Clean() sanitization in handler/router.go. At...

Vendor: webp-sh
Product: webp_server_go
Published: Jun 22, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 22, 2026
Source: NVD

A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data.Β An adjacent attacker may exploit this vulnerability by supplying crafted DHCP responses, potentially re...

Vendor: TP-Link Systems Inc., TP Link Systems Inc.
Product: Archer MR200 v07, Archer MR200 v8, Archer MR402 v1, Archer VR2100 v1, Archer C20 v5, Archer C20 v6, TL-MR6400 v7
Published: Jun 22, 2026
Source: NVD
CVE-2026-56109 MEDIUM - 6.8

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_d...

Vendor: alsa-project
Product: alsa-lib
Published: Jun 22, 2026
Source: NVD
CVE-2026-42127 HIGH - 7.5

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token ...

Vendor: Grafana
Product: Grafana Enterprise, Grafana OSS
Published: Jun 22, 2026
Source: NVD
CVE-2026-12249 CRITICAL - 9.0

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plai...

Vendor: Canonical
Product: Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, Ubuntu 26.04 LTS
Published: Jun 22, 2026
Source: NVD

Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.

Vendor: Akaunting
Product: Akaunting
Published: Jun 22, 2026
Source: NVD