Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
Showing 1,001 - 1,020 of 12,817 CVEs
CVE-2026-48546 HIGH - 7.3

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull r...

Vendor: lingdojo
Product: kana-dojo
Published: Jun 11, 2026
Source: NVD
CVE-2026-46697 HIGH - 7.5

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($...

Vendor: stefanbohacek
Product: fediverse-embeds-wordpress-plugin
Published: Jun 11, 2026
Source: NVD
CVE-2026-49982 HIGH - 8.2

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when prefix, postfix, or template is supplied as a non-string value (Array, Buffer, or any object) whose includes(&...

Vendor: raszi
Product: node-tmp
Published: Jun 11, 2026
Source: NVD

Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS

Vendor: go
Product: github.com/basekick-labs/arc
Published: Jun 11, 2026
Source: GitHub
CVE-2026-7870 HIGH - 8.8

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.

Vendor: ibm
Product: i
Published: Jun 11, 2026
Source: NVD
CVE-2026-7787 HIGH - 7.5

IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.

Vendor: langflow
Product: langflow
Published: Jun 11, 2026
Source: NVD
CVE-2026-53777 HIGH - 8.1

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling...

Vendor: PerryTS
Product: perry
Published: Jun 11, 2026
Source: NVD
CVE-2026-11816 HIGH - 8.1

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD...

Vendor: keras-team
Product: keras-team/keras
Published: Jun 11, 2026
Source: NVD
CVE-2026-10847 HIGH - 7.8

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation c...

Vendor: checkpoint
Product: Identity Agent
Published: Jun 11, 2026
Source: NVD
CVE-2026-48068 HIGH - 7.5

@grpc/grpc-js: A malformed request can cause a server crash

Vendor: npm
Product: @grpc/grpc-js
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48069 HIGH - 7.5

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

Vendor: npm
Product: @grpc/grpc-js
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48054 HIGH - 8.8

OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri

Vendor: npm
Product: @openzeppelin/wizard
Published: Jun 11, 2026
Source: GitHub

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Vendor: go
Product: github.com/traefik/traefik/v2
Published: Jun 11, 2026
Source: GitHub

Element Call reports full URLs of visited pages to analytics server

Vendor: npm
Product: @element-hq/element-call-embedded
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48006 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes....

Vendor: maven
Product: io.netty:netty-codec-redis
Published: Jun 11, 2026
Source: GitHub

PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing

Vendor: pip
Product: pdm
Published: Jun 11, 2026
Source: GitHub
CVE-2026-8589 HIGH - 7.3

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper san...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-7250 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsin...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-6552 HIGH - 8.7

GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improp...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-10087 HIGH - 8.7

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a target...

Vendor: GitLab
Product: GitLab
Published: Jun 11, 2026
Source: NVD