Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

1,999
Quick preset (or use dates below)
Clear Filters
Showing 1,021 - 1,040 of 13,341 CVEs

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This iss...

Vendor: TYPO3
Product: TYPO3 CMS
Published: Jun 09, 2026
Source: NVD
CVE-2026-52902 MEDIUM - 4.7

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.fo...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jun 09, 2026
Source: NVD
CVE-2026-4058 MEDIUM - 4.3

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2...

Published: Jun 09, 2026
Source: NVD
CVE-2026-46747 MEDIUM - 4.3

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintend...

Vendor: Siemens
Product: SINEC INS
Published: Jun 09, 2026
Source: NVD
CVE-2025-40808 MEDIUM - 6.1

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU8...

Published: Jun 09, 2026
Source: NVD
CVE-2026-8677 MEDIUM - 6.4

The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible fo...

Published: Jun 09, 2026
Source: NVD
CVE-2026-8599 MEDIUM - 6.4

The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Content Field in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This make...

Published: Jun 09, 2026
Source: NVD
CVE-2026-7542 MEDIUM - 6.5

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to and including 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via...

Published: Jun 09, 2026
Source: NVD
CVE-2026-6899 MEDIUM - 5.6

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate.

Published: Jun 09, 2026
Source: NVD
CVE-2026-49818 MEDIUM - 6.5

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS...

Vendor: Apache Software Foundation
Product: Apache Airflow Samba provider
Published: Jun 09, 2026
Source: NVD
CVE-2026-34905 MEDIUM - 6.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questi...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 09, 2026
Source: NVD
CVE-2026-34033 MEDIUM - 5.4

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML in...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 09, 2026
Source: NVD
CVE-2026-34031 MEDIUM - 6.5

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unin...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 09, 2026
Source: NVD
CVE-2026-33582 MEDIUM - 6.5

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are reco...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 09, 2026
Source: NVD
CVE-2026-28262 MEDIUM - 6.0

Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

Vendor: Dell
Product: iDRAC Tools
Published: Jun 09, 2026
Source: NVD
CVE-2026-25699 MEDIUM - 6.1

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and it...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 09, 2026
Source: NVD
CVE-2026-25688 MEDIUM - 6.1

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are r...

Vendor: Apache Software Foundation
Product: Apache Answer
Published: Jun 09, 2026
Source: NVD
CVE-2026-41985 MEDIUM - 5.1

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Vendor: Huawei
Product: HarmonyOS
Published: Jun 09, 2026
Source: NVD
CVE-2026-41984 MEDIUM - 5.2

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Vendor: Huawei
Product: HarmonyOS
Published: Jun 09, 2026
Source: NVD
CVE-2026-41983 MEDIUM - 4.3

DoS vulnerability in the browser kernel. Impact: Successful exploitation of this vulnerability may affect availability.

Vendor: Huawei
Product: HarmonyOS
Published: Jun 09, 2026
Source: NVD