Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 621 - 640 of 12,930 CVEs
CVE-2026-50623 MEDIUM - 6.5

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF.Β Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However not...

Vendor: Apache Software Foundation
Product: Apache CXF
Published: Jun 12, 2026
Source: NVD
CVE-2026-48914 MEDIUM - 6.7

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to a...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux for NVIDIA 26, Red Hat OpenShift Container Platform 4
Published: Jun 12, 2026
Source: NVD
CVE-2026-11847 MEDIUM - 4.3

TheΒ  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowing authenticated remote attackers to exploit this vulnerability to create directories in unintended system paths.

Vendor: IEI Integration Corp
Product: iVEC TANK-XM811
Published: Jun 12, 2026
Source: NVD
CVE-2026-11844 MEDIUM - 4.9

The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the intended directory scope.

Vendor: IEI Integration Corp
Product: iVEC TANK-XM811
Published: Jun 12, 2026
Source: NVD
CVE-2026-9271 MEDIUM - 5.9

Vulnerability Title

Published: Jun 12, 2026
Source: NVD
CVE-2026-12060 MEDIUM - 6.5

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unautho...

Vendor: Hepta Platforms
Product: Heptabase
Published: Jun 12, 2026
Source: NVD
CVE-2026-48613 MEDIUM - 5.9

SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to ...

Vendor: phpBB
Product: phpBB
Published: Jun 12, 2026
Source: NVD
CVE-2026-9125 MEDIUM - 6.4

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function...

Published: Jun 12, 2026
Source: NVD
CVE-2026-49482 MEDIUM - 4.3

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles ...

Vendor: MacWarrior
Product: clipbucket-v5
Published: Jun 12, 2026
Source: NVD
CVE-2026-47238 MEDIUM - 6.5

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 ...

Vendor: MacWarrior
Product: clipbucket-v5
Published: Jun 11, 2026
Source: NVD
CVE-2026-12033 MEDIUM - 5.3

Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12026 MEDIUM - 6.5

Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12025 MEDIUM - 5.3

Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12024 MEDIUM - 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12015 MEDIUM - 5.3

Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-53818 MEDIUM - 6.6

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 11, 2026
Source: NVD
CVE-2026-53815 MEDIUM - 6.5

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation in the affected feature, potentially exposing sensi...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 11, 2026
Source: NVD
CVE-2026-53808 MEDIUM - 6.5

OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affected apply path to apply workshop changes before th...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 11, 2026
Source: NVD
CVE-2026-48067 MEDIUM - 6.5

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

Vendor: composer
Product: filament/tables
Published: Jun 11, 2026
Source: GitHub
CVE-2026-53781 MEDIUM - 4.3

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attacke...

Vendor: steipete
Product: summarize
Published: Jun 11, 2026
Source: NVD