Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,671
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 121 - 140 of 35,133 CVEs

An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links. This issue affects Canarytokens: from Docker tag sha-4aef1db90...

Vendor: Thinkst Applied Research
Product: Canarytokens
Published: Jun 22, 2026
Source: NVD

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program Files have excessive perm...

Vendor: Aruba
Product: ArubaSign
Published: Jun 22, 2026
Source: NVD
CVE-2026-10601 MEDIUM - 5.4

The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an att...

Vendor: Grafana
Product: Grafana OSS
Published: Jun 22, 2026
Source: NVD
CVE-2026-10561 CRITICAL - 10.0

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

Vendor: IBM
Product: Langflow OSS
Published: Jun 22, 2026
Source: NVD
CVE-2025-66389 HIGH - 7.5

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.

Published: Jun 22, 2026
Source: NVD
CVE-2025-33128 MEDIUM - 5.4

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...

Vendor: IBM
Product: Engineering Workflow Management
Published: Jun 22, 2026
Source: NVD
CVE-2025-2669 MEDIUM - 6.0

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.

Published: Jun 22, 2026
Source: NVD
CVE-2024-54178 MEDIUM - 6.5

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.

Vendor: IBM
Product: Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
Published: Jun 22, 2026
Source: NVD

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object identifiers) without consistentl...

Vendor: misp
Product: misp
Published: Jun 22, 2026
Source: NVD
CVE-2026-11373 CRITICAL - 9.1

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol...

Vendor: JASEI
Product: Net::Statsite::Client
Published: Jun 22, 2026
Source: NVD

An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.

Vendor: pretix
Product: Venueless
Published: Jun 22, 2026
Source: NVD

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

Vendor: pretix
Product: Venueless
Published: Jun 22, 2026
Source: NVD
CVE-2026-12581 HIGH - 7.5

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

Vendor: Digiwin
Product: EasyFlow .NET
Published: Jun 22, 2026
Source: NVD
CVE-2026-12580 MEDIUM - 5.4

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.

Vendor: Digiwin
Product: EasyFlow .NET
Published: Jun 22, 2026
Source: NVD

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface....

Published: Jun 22, 2026
Source: NVD
CVE-2023-45796 HIGH - 8.1

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.

Vendor: Pilz
Product: PMI v8xx, PASvisu
Published: Jun 22, 2026
Source: NVD
CVE-2023-45795 HIGH - 7.8

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.

Vendor: Pilz
Product: PMI v8xx, PASvisu
Published: Jun 22, 2026
Source: NVD

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not ch...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD