Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,339
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,201 - 1,220 of 33,692 CVEs
CVE-2026-11986 MEDIUM - 4.9

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator w...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack
Published: Jun 11, 2026
Source: NVD
CVE-2026-49982 HIGH - 8.2

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when prefix, postfix, or template is supplied as a non-string value (Array, Buffer, or any object) whose includes(&...

Vendor: raszi
Product: node-tmp
Published: Jun 11, 2026
Source: NVD
CVE-2026-11945 MEDIUM - 6.4

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed...

Vendor: DALIBO
Product: PostgreSQL Anonymizer
Published: Jun 11, 2026
Source: NVD
CVE-2026-48062 CRITICAL - 9.8

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

Vendor: composer
Product: codeigniter4/framework
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48053 MEDIUM - 5.8

Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset

Vendor: pip
Product: kolibri
Published: Jun 11, 2026
Source: GitHub

Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS

Vendor: go
Product: github.com/basekick-labs/arc
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48049 MEDIUM - 5.3

@hapi/inert has a static-file confinement bypass via sibling-prefix path

Vendor: npm
Product: @hapi/inert
Published: Jun 11, 2026
Source: GitHub
CVE-2026-9648 CRITICAL - 9.1

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonat...

Published: Jun 11, 2026
Source: NVD
CVE-2026-7870 HIGH - 8.8

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.

Vendor: ibm
Product: i
Published: Jun 11, 2026
Source: NVD
CVE-2026-7787 HIGH - 7.5

IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.

Vendor: langflow
Product: langflow
Published: Jun 11, 2026
Source: NVD
CVE-2026-53777 HIGH - 8.1

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling...

Vendor: PerryTS
Product: perry
Published: Jun 11, 2026
Source: NVD
CVE-2026-4096 MEDIUM - 6.5

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

Vendor: ibm
Product: devops_plan
Published: Jun 11, 2026
Source: NVD
CVE-2026-3341 MEDIUM - 5.4

IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Vendor: langflow
Product: langflow_desktop
Published: Jun 11, 2026
Source: NVD
CVE-2026-11839 CRITICAL - 9.9

Unrestricted upload of file with dangerous type vulnerability in BaĹźarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

Vendor: BaĹźarsoft Information Technologies Inc.
Product: Rotaban
Published: Jun 11, 2026
Source: NVD
CVE-2024-45636 MEDIUM - 4.1

IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.

Vendor: IBM
Product: Security QRadar EDR
Published: Jun 11, 2026
Source: NVD

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details from modules/messaging/SentMail.php by supplying an arbitrary mail_id value.

Published: Jun 11, 2026
Source: NVD

A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic.

Published: Jun 11, 2026
Source: NVD

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the identity “remember me” cookie were set without the Secure attribute. In deployments where users could re...

Vendor: malach-it
Product: boruta-server
Published: Jun 11, 2026
Source: NVD
CVE-2026-38581 CRITICAL - 9.8

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without san...

Published: Jun 11, 2026
Source: NVD
CVE-2026-11816 HIGH - 8.1

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD...

Vendor: keras-team
Product: keras-team/keras
Published: Jun 11, 2026
Source: NVD