Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,056
Quick preset (or use dates below)
Clear Filters
Showing 1,101 - 1,120 of 12,840 CVEs
CVE-2026-45549 HIGH - 8.5

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only โ€” no role check, no group ownership ...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-9758 HIGH - 7.3

Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted

Published: Jun 10, 2026
Source: NVD
CVE-2026-53435 HIGH - 8.8

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to imp...

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-52758 HIGH - 8.8

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the Po...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52755 HIGH - 7.8

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive ...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52754 HIGH - 8.8

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repo...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52752 HIGH - 7.8

Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling ...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52751 HIGH - 8.8

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File โ†’ Open Project, deserializes untrusted...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52750 HIGH - 7.8

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims cli...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49498 HIGH - 8.8

Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements. Authenticated attackers can inject SQL commands via crafted username parameters in Passwo...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49069 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.

Vendor: WPZOOM
Product: WPZOOM Portfolio
Published: Jun 10, 2026
Source: NVD
CVE-2025-71330 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to tri...

Vendor: image-size
Product: image-size
Published: Jun 10, 2026
Source: NVD
CVE-2025-71329 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF...

Vendor: image-size
Product: image-size
Published: Jun 10, 2026
Source: NVD
CVE-2026-49396 HIGH - 7.1

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on a victim's agents. This issue has been patched in version 2.0.14.

Vendor: go
Product: github.com/nezhahq/nezha
Published: Jun 10, 2026
Source: GitHub

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

Vendor: npm
Product: @hulumi/drift
Published: Jun 10, 2026
Source: GitHub

@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened

Vendor: npm
Product: @hulumi/baseline
Published: Jun 10, 2026
Source: GitHub

@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

Vendor: npm
Product: @hulumi/policies
Published: Jun 10, 2026
Source: GitHub

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

Vendor: npm
Product: @hulumi/policies
Published: Jun 10, 2026
Source: GitHub

@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers

Vendor: npm
Product: @hulumi/policies
Published: Jun 10, 2026
Source: GitHub
CVE-2026-24067 HIGH - 8.4

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and...

Vendor: Slate Digital LLC
Product: Slate Digital Connect
Published: Jun 10, 2026
Source: NVD