Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,287
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,341 - 1,360 of 33,692 CVEs

PDM: Project-Local State and Config Writes Follow Symlinks

Vendor: pip
Product: pdm
Published: Jun 10, 2026
Source: GitHub
CVE-2026-6893 HIGH - 8.8

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled...

Published: Jun 10, 2026
Source: NVD
CVE-2026-50127 MEDIUM - 5.9

Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictio...

Vendor: WeblateOrg
Product: weblate
Published: Jun 10, 2026
Source: NVD

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a ...

Vendor: mate-desktop
Product: atril
Published: Jun 10, 2026
Source: NVD
CVE-2026-1220 HIGH - 7.5

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Jun 10, 2026
Source: NVD

Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)

Vendor: go
Product: github.com/lxc/incus/v7
Published: Jun 10, 2026
Source: GitHub

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Vendor: actions
Product: anthropics/claude-code-action
Published: Jun 10, 2026
Source: GitHub

Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload

Vendor: npm
Product: baileys
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50639 MEDIUM - 6.5

Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::...

Vendor: PEVANS
Product: Metrics::Any::Adapter::SignalFx
Published: Jun 10, 2026
Source: NVD
CVE-2026-50638 CRITICAL - 9.1

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter...

Vendor: PEVANS
Product: Metrics::Any::Adapter::DogStatsd
Published: Jun 10, 2026
Source: NVD
CVE-2026-50637 HIGH - 8.2

Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the name...

Vendor: PEVANS
Product: Metrics::Any::Adapter::Statsd
Published: Jun 10, 2026
Source: NVD

CleanWipe Removal Tool (macOS), prior to 16.0.0.65,ย may be susceptible to an Local Privilege Escalation vulnerability, which is a type of issue whereby an attacker with limited privilege access on an affected system can escalate their privileges to gain administrative control.

Vendor: Broadcom
Product: Symantec Endpoint Protection CleanWipe Removal Tool
Published: Jun 10, 2026
Source: NVD
CVE-2026-10740 MEDIUM - 5.3

Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate this issue, users should upgrade to v1.8.2.

Vendor: AWS
Product: s2n-quic
Published: Jun 10, 2026
Source: NVD
CVE-2026-48061 MEDIUM - 5.9

Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header

Vendor: pip
Product: litestar
Published: Jun 10, 2026
Source: GitHub
CVE-2026-48060 HIGH - 8.1

Litestar has HTML Injection Through its CSRF Token

Vendor: pip
Product: litestar
Published: Jun 10, 2026
Source: GitHub

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub

nebula-mesh: Decrypted CA private key persists in heap after signing

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub

An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration fil...

Published: Jun 10, 2026
Source: NVD
CVE-2026-50570 HIGH - 8.5

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSaf...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50569 MEDIUM - 4.3

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeUR...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD