Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,751
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 101 - 120 of 35,119 CVEs

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature permission could cau...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for each selected object. For Event Reports, EventReport...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-54100 HIGH - 8.3

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can captu...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers
Published: Jun 22, 2026
Source: NVD
CVE-2026-54099 HIGH - 8.8

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A co...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers
Published: Jun 22, 2026
Source: NVD
CVE-2026-42129 HIGH - 7.7

The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and in...

Vendor: Grafana
Product: Grafana OSS
Published: Jun 22, 2026
Source: NVD
CVE-2026-28381 CRITICAL - 9.6

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.

Vendor: Grafana
Product: Snowflake Datasource
Published: Jun 22, 2026
Source: NVD

An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links. This issue affects Canarytokens: from Docker tag sha-4aef1db90...

Vendor: Thinkst Applied Research
Product: Canarytokens
Published: Jun 22, 2026
Source: NVD

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program Files have excessive perm...

Vendor: Aruba
Product: ArubaSign
Published: Jun 22, 2026
Source: NVD
CVE-2026-10601 MEDIUM - 5.4

The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an att...

Vendor: Grafana
Product: Grafana OSS
Published: Jun 22, 2026
Source: NVD
CVE-2026-10561 CRITICAL - 10.0

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

Vendor: IBM
Product: Langflow OSS
Published: Jun 22, 2026
Source: NVD
CVE-2025-66389 HIGH - 7.5

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.

Published: Jun 22, 2026
Source: NVD
CVE-2025-33128 MEDIUM - 5.4

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...

Vendor: IBM
Product: Engineering Workflow Management
Published: Jun 22, 2026
Source: NVD
CVE-2025-2669 MEDIUM - 6.0

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.

Published: Jun 22, 2026
Source: NVD
CVE-2024-54178 MEDIUM - 6.5

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.

Vendor: IBM
Product: Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
Published: Jun 22, 2026
Source: NVD

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object identifiers) without consistentl...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-11373 CRITICAL - 9.1

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol...

Vendor: JASEI
Product: Net::Statsite::Client
Published: Jun 22, 2026
Source: NVD

An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.

Vendor: pretix
Product: Venueless
Published: Jun 22, 2026
Source: NVD

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

Vendor: pretix
Product: Venueless
Published: Jun 22, 2026
Source: NVD
CVE-2026-12581 HIGH - 7.5

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

Vendor: Digiwin
Product: EasyFlow .NET
Published: Jun 22, 2026
Source: NVD
CVE-2026-12580 MEDIUM - 5.4

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.

Vendor: Digiwin
Product: EasyFlow .NET
Published: Jun 22, 2026
Source: NVD