Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,445
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,441 - 1,460 of 33,519 CVEs
CVE-2026-47911 HIGH - 7.8

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Acrobat Reader
Published: Jun 09, 2026
Source: NVD
CVE-2026-34416 MEDIUM - 6.1

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious input through the project request parameter. Attackers can craft a malicious URL containing unsanitized input that...

Vendor: brian-ruf
Product: OSCAL-GUI
Published: Jun 09, 2026
Source: NVD
CVE-2026-25557 MEDIUM - 5.4

Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject...

Vendor: Evoluted
Product: PHP Directory Listing Script
Published: Jun 09, 2026
Source: NVD
CVE-2026-11799 HIGH - 7.5

UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.

Vendor: Mozilla
Product: Focus for iOS, Klar for iOS
Published: Jun 09, 2026
Source: NVD
CVE-2025-71319 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF...

Vendor: image-size
Product: image-size
Published: Jun 09, 2026
Source: NVD

Net::IMAP: Command Injection via ID command argument

Vendor: rubygems
Product: net-imap
Published: Jun 09, 2026
Source: GitHub

A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.

Published: Jun 09, 2026
Source: NVD

A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.

Published: Jun 09, 2026
Source: NVD
CVE-2026-48306 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-48305 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-47910 MEDIUM - 6.3

Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue r...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47909 MEDIUM - 6.3

Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47908 HIGH - 7.8

Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47907 HIGH - 8.2

Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue r...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47906 HIGH - 8.6

Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious f...

Vendor: Adobe
Product: Dreamweaver Desktop
Published: Jun 09, 2026
Source: NVD
CVE-2026-47106 MEDIUM - 5.4

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search functionality that allows authenticated Banner ERP users to inject malicious payloads into faculty and course fields by exploiting missing HTML encoding dur...

Vendor: Ellucian
Product: Banner Self-Service
Published: Jun 09, 2026
Source: NVD
CVE-2026-34710 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-34709 HIGH - 7.8

Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Sampler
Published: Jun 09, 2026
Source: NVD
CVE-2026-32856 MEDIUM - 6.1

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in ...

Vendor: Ellucian
Product: Banner Self-Service
Published: Jun 09, 2026
Source: NVD
CVE-2026-11824 HIGH - 7.8

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attacke...

Vendor: SQLite
Product: SQLite
Published: Jun 09, 2026
Source: NVD