Total CVEs

149,293

Critical Severity

4,762

High Severity

17,016

Last 7 Days

2,818
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 10,441 - 10,460 of 45,698 CVEs
CVE-2026-34915 MEDIUM - 6.1

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the scr...

Vendor: Revive
Product: Adserver
Published: Jun 23, 2026
Source: NVD
CVE-2026-34914 HIGH - 8.3

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are ...

Vendor: Revive
Product: Adserver
Published: Jun 23, 2026
Source: NVD
CVE-2026-34913 MEDIUM - 4.3

A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership rela...

Vendor: Revive
Product: Adserver
Published: Jun 23, 2026
Source: NVD
CVE-2026-34912 MEDIUM - 4.3

A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in i...

Vendor: Revive
Product: Adserver
Published: Jun 23, 2026
Source: NVD
CVE-2026-13007 HIGH - 7.5

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are se...

Vendor: tenable
Product: Tenable Identity Exposure
Published: Jun 23, 2026
Source: NVD
CVE-2026-12958 HIGH - 7.8

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate t...

Vendor: Amazon Web Services
Product: Language Servers for AWS
Published: Jun 23, 2026
Source: NVD
CVE-2026-12957 HIGH - 7.8

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This is...

Vendor: Amazon Web Services
Product: Language Servers for AWS
Published: Jun 23, 2026
Source: NVD

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it a...

Vendor: Python Software Foundation
Product: CPython
Published: Jun 23, 2026
Source: NVD
CVE-2025-61028 HIGH - 7.5

An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61027 HIGH - 7.5

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61025 HIGH - 7.5

An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61023 HIGH - 7.5

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61022 HIGH - 7.5

An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61021 HIGH - 7.5

An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61020 HIGH - 7.5

An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61019 HIGH - 7.5

An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61018 HIGH - 7.5

An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-13162 MEDIUM - 4.4

Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.

Vendor: ABB
Product: Control Builder A, 800xA for Advant Master
Published: Jun 23, 2026
Source: NVD

OctoPrint has XSS in its Suppressed Command Notifications

Vendor: pip
Product: OctoPrint
Published: Jun 23, 2026
Source: GitHub

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v1/org_team.go:8 returns all teams for any organization without requiring authentication. The route gr...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub