Total CVEs

149,718

Critical Severity

4,823

High Severity

17,239

Last 7 Days

2,994
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 11,021 - 11,040 of 46,123 CVEs

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

Vendor: maven
Product: org.openidentityplatform.opendj:opendj-server-legacy
Published: Jun 22, 2026
Source: GitHub

motionEye: Authentication possible via password hash

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44795 HIGH - 8.5

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of...

Vendor: maven
Product: io.spinnaker.rosco:rosco-core
Published: Jun 22, 2026
Source: GitHub

OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`

Vendor: maven
Product: org.openidentityplatform.openam:openam-federation-library
Published: Jun 22, 2026
Source: GitHub

Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)

Vendor: go
Product: github.com/inspektor-gadget/inspektor-gadget
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44585 MEDIUM - 5.4

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing serv...

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44584 MEDIUM - 4.3

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain its verified status a...

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44583 MEDIUM - 5.3

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the PAYPAL-CERT-URL HTTP header without validation, allowing attackers to control server-side HTTP request destination...

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Vendor: nodejs
Product: node
Published: Jun 22, 2026
Source: NVD
CVE-2026-44274 HIGH - 7.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44273 MEDIUM - 6.0

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44272 HIGH - 8.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44271 HIGH - 8.1

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-10852 MEDIUM - 5.9

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

Vendor: IBM
Product: i
Published: Jun 22, 2026
Source: NVD
CVE-2026-44517 MEDIUM - 6.3

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

Vendor: go
Product: github.com/containers/buildah
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44203 CRITICAL - 9.3

OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 22, 2026
Source: GitHub

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44179 CRITICAL - 9.9

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

Vendor: maven
Product: com.xwiki.pro:xwiki-pro-macros
Published: Jun 22, 2026
Source: GitHub
CVE-2026-41579 MEDIUM - 3.3

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string w...

Vendor: go
Product: github.com/opencontainers/runc
Published: Jun 22, 2026
Source: GitHub

OpenAM has LDAP Injection via `_queryId` Parameter

Vendor: maven
Product: org.openidentityplatform.openam:openam-core-rest
Published: Jun 22, 2026
Source: GitHub