Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,013
Quick preset (or use dates below)
Clear Filters
Showing 681 - 700 of 13,341 CVEs
CVE-2025-30459 MEDIUM - 5.5

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-30431 MEDIUM - 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-24268 MEDIUM - 5.5

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-24165 MEDIUM - 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2026-46698 MEDIUM - 5.3

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the a...

Vendor: stefanbohacek
Product: fediverse-embeds-wordpress-plugin
Published: Jun 11, 2026
Source: NVD
CVE-2026-11986 MEDIUM - 4.9

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator w...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack
Published: Jun 11, 2026
Source: NVD
CVE-2026-11945 MEDIUM - 6.4

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed...

Vendor: DALIBO
Product: PostgreSQL Anonymizer
Published: Jun 11, 2026
Source: NVD
CVE-2026-48053 MEDIUM - 5.8

Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset

Vendor: pip
Product: kolibri
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48049 MEDIUM - 5.3

@hapi/inert has a static-file confinement bypass via sibling-prefix path

Vendor: npm
Product: @hapi/inert
Published: Jun 11, 2026
Source: GitHub
CVE-2026-4096 MEDIUM - 6.5

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

Vendor: ibm
Product: devops_plan
Published: Jun 11, 2026
Source: NVD
CVE-2026-3341 MEDIUM - 5.4

IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Vendor: langflow
Product: langflow_desktop
Published: Jun 11, 2026
Source: NVD
CVE-2024-45636 MEDIUM - 4.1

IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.

Vendor: IBM
Product: Security QRadar EDR
Published: Jun 11, 2026
Source: NVD
CVE-2026-48045 MEDIUM - 6.5

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

Vendor: pip
Product: zeroconf
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48043 MEDIUM - 5.3

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the...

Vendor: maven
Product: io.netty:netty-codec-http2
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48038 MEDIUM - 5.3

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

Vendor: npm
Product: joi
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48022 MEDIUM - 6.5

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

Vendor: npm
Product: @hapi/wreck
Published: Jun 11, 2026
Source: GitHub

free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence

Vendor: go
Product: github.com/free5gc/udr
Published: Jun 11, 2026
Source: GitHub
CVE-2026-49214 MEDIUM - 5.3

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to constr...

Vendor: guzzle
Product: psr7
Published: Jun 11, 2026
Source: NVD
CVE-2026-48998 MEDIUM - 5.3

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI ...

Vendor: guzzle
Product: psr7
Published: Jun 11, 2026
Source: NVD
CVE-2026-11561 MEDIUM - 5.3

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6...

Vendor: Soagen Informatics Technologies Software and Consulting Inc.
Product: Apinizer
Published: Jun 11, 2026
Source: NVD