Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,368
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 121 - 140 of 3,181 CVEs
CVE-2026-47370 CRITICAL - 9.9

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.

Published: Jun 12, 2026
Source: NVD
CVE-2026-47369 CRITICAL - 9.9

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

Published: Jun 12, 2026
Source: NVD
CVE-2026-47367 CRITICAL - 9.9

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.

Vendor: Ubiquiti Inc
Product: UID Enterprise Agent
Published: Jun 12, 2026
Source: NVD
CVE-2026-47365 CRITICAL - 9.9

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

Vendor: WebPros
Product: WordPress-Toolkit
Published: Jun 12, 2026
Source: NVD
CVE-2026-45060 CRITICAL - 9.8

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patche...

Vendor: MacWarrior
Product: clipbucket-v5
Published: Jun 11, 2026
Source: NVD
CVE-2026-42846 CRITICAL - 9.8

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated direc...

Vendor: MacWarrior
Product: clipbucket-v5
Published: Jun 11, 2026
Source: NVD
CVE-2026-49060 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.

Vendor: Hippoo
Product: Hippoo Mobile App for WooCommerce
Published: Jun 11, 2026
Source: NVD
CVE-2026-42647 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

Vendor: Beardev
Product: JoomSport
Published: Jun 11, 2026
Source: NVD
CVE-2026-39494 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.

Vendor: WBW Plugins
Product: Product Filter by WBW
Published: Jun 11, 2026
Source: NVD
CVE-2026-12027 CRITICAL - 9.6

Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-41005 CRITICAL - 9.0

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to fa...

Vendor: Cloud Foundry
Product: UAA, CF Deployment
Published: Jun 11, 2026
Source: NVD
CVE-2026-49973 CRITICAL - 9.4

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable networ...

Vendor: nesquena
Product: hermes-webui
Published: Jun 11, 2026
Source: NVD
CVE-2026-49261 CRITICAL - 10.0

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 1...

Vendor: MariaDB
Product: server
Published: Jun 11, 2026
Source: NVD
CVE-2026-48062 CRITICAL - 9.8

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

Vendor: composer
Product: codeigniter4/framework
Published: Jun 11, 2026
Source: GitHub
CVE-2026-9648 CRITICAL - 9.1

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonat...

Published: Jun 11, 2026
Source: NVD
CVE-2026-11839 CRITICAL - 9.9

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

Vendor: Başarsoft Information Technologies Inc.
Product: Rotaban
Published: Jun 11, 2026
Source: NVD
CVE-2026-38581 CRITICAL - 9.8

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without san...

Published: Jun 11, 2026
Source: NVD
CVE-2026-48039 CRITICAL - 9.1

Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token

Vendor: pip
Product: meta-ads-mcp
Published: Jun 11, 2026
Source: GitHub
CVE-2026-7852 CRITICAL - 9.8

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.

Published: Jun 11, 2026
Source: NVD
CVE-2026-35273 CRITICAL - 9.8

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleS...

Vendor: Oracle Corporation
Product: PeopleSoft Enterprise PeopleTools
Published: Jun 11, 2026
Source: NVD