Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 581 - 600 of 34,871 CVEs
CVE-2026-47103 CRITICAL - 9.8

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attack...

Vendor: fgmacedo
Product: python-statemachine
Published: Jun 17, 2026
Source: NVD
CVE-2026-42530 HIGH - 8.1

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This m...

Vendor: F5
Product: NGINX Open Source
Published: Jun 17, 2026
Source: NVD
CVE-2026-42055 HIGH - 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the lar...

Vendor: F5
Product: NGINX Open Source, NGINX Plus
Published: Jun 17, 2026
Source: NVD
CVE-2026-40641 MEDIUM - 4.8

Dell PowerFlex Manager, version(s) 4.6.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35162 MEDIUM - 4.3

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35067 MEDIUM - 5.7

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35066 HIGH - 7.1

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35065 HIGH - 8.8

Dell PowerFlex Manager, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Informa...

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-32804 HIGH - 8.1

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-22283 HIGH - 7.5

Dell PowerFlex Manager, version(s) Version prior to 4.8, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-12528 MEDIUM - 5.4

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 17, 2026
Source: NVD
CVE-2026-11311 HIGH - 8.1

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilt...

Vendor: F5
Product: NGINX Gateway Fabric
Published: Jun 17, 2026
Source: NVD

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.

Vendor: Plane
Product: Plane
Published: Jun 17, 2026
Source: NVD
CVE-2024-47477 MEDIUM - 6.5

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.

Vendor: Dell
Product: PowerFlex Manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-54016 MEDIUM - 4.3

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub

Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.

Published: Jun 17, 2026
Source: NVD
CVE-2026-55738 HIGH - 8.8

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy() without guaranteeing null termination of the source. The POSIX ustar format permits these fixed-width ...

Vendor: rxi
Product: microtar
Published: Jun 17, 2026
Source: NVD
CVE-2026-54819 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

Vendor: Webilia Inc.
Product: Listdom
Published: Jun 17, 2026
Source: NVD
CVE-2026-54818 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

Vendor: VeronaLabs
Product: Slimstat Analytics
Published: Jun 17, 2026
Source: NVD
CVE-2026-54817 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

Vendor: FluxBuilder
Product: MStore API
Published: Jun 17, 2026
Source: NVD