Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,853
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 121 - 140 of 12,881 CVEs
CVE-2026-20246 MEDIUM - 6.0

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this v...

Vendor: Cisco
Product: Cisco Umbrella Insights Virtual Appliance
Published: Jun 17, 2026
Source: NVD
CVE-2026-20220 MEDIUM - 6.3

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template...

Vendor: Cisco
Product: Cisco Crosswork Network Change Automation
Published: Jun 17, 2026
Source: NVD
CVE-2026-1288 MEDIUM - 5.5

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Published: Jun 17, 2026
Source: NVD
CVE-2026-12515 MEDIUM - 4.3

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to m...

Vendor: Red Hat
Product: Red Hat Hardened Images, Red Hat Satellite 6
Published: Jun 17, 2026
Source: NVD
CVE-2025-32748 MEDIUM - 4.3

Dell PowerFlex rack, version(s) RCM 3.7/3.7, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.

Vendor: Dell
Product: PowerFlex rack
Published: Jun 17, 2026
Source: NVD
CVE-2026-55748 MEDIUM - 6.0

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

Vendor: OpenStack
Product: Horizon
Published: Jun 17, 2026
Source: NVD
CVE-2026-48142 MEDIUM - 4.8

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send reques...

Vendor: F5
Product: NGINX Open Source, NGINX Plus
Published: Jun 17, 2026
Source: NVD
CVE-2026-48117 MEDIUM - 6.8

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack in which an attacker could register an account using a victim's email address with an attacker-controlled password before the victim completed acco...

Vendor: fduflyer
Product: DroneAware-Node-Releases
Published: Jun 17, 2026
Source: NVD
CVE-2026-40641 MEDIUM - 4.8

Dell PowerFlex Manager, version(s) 4.6.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35162 MEDIUM - 4.3

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35067 MEDIUM - 5.7

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-12528 MEDIUM - 5.4

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 17, 2026
Source: NVD
CVE-2024-47477 MEDIUM - 6.5

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.

Vendor: Dell
Product: PowerFlex Manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-54016 MEDIUM - 4.3

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54817 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

Vendor: FluxBuilder
Product: MStore API
Published: Jun 17, 2026
Source: NVD
CVE-2026-52716 MEDIUM - 6.5

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

Vendor: purethemes
Product: WorkScout-Core
Published: Jun 17, 2026
Source: NVD
CVE-2025-15657 MEDIUM - 5.3

Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

Vendor: Mojoomla
Product: School Management
Published: Jun 17, 2026
Source: NVD
CVE-2026-54015 MEDIUM - 6.4

Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54014 MEDIUM - 4.3

Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54009 MEDIUM - 6.5

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub