Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,364
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 141 - 160 of 3,181 CVEs

Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload

Vendor: npm
Product: baileys
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50638 CRITICAL - 9.1

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter...

Vendor: PEVANS
Product: Metrics::Any::Adapter::DogStatsd
Published: Jun 10, 2026
Source: NVD
CVE-2026-50566 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability contain...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50564 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs ...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50563 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50545 CRITICAL - 9.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fiel...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-20253 CRITICAL - 9.8

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowi...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD
CVE-2026-53476 CRITICAL - 9.6

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This...

Vendor: kubev2v
Product: assisted_migration_agent
Published: Jun 10, 2026
Source: NVD
CVE-2026-53475 CRITICAL - 9.3

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unau...

Vendor: kubev2v
Product: assisted_migration_agent
Published: Jun 10, 2026
Source: NVD
CVE-2026-53474 CRITICAL - 9.6

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Inj...

Vendor: kebev2v
Product: migration_assessment
Published: Jun 10, 2026
Source: NVD
CVE-2026-53471 CRITICAL - 9.6

A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authent...

Published: Jun 10, 2026
Source: NVD
CVE-2026-53470 CRITICAL - 9.6

A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker to bypass an ownership check and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images be...

Published: Jun 10, 2026
Source: NVD
CVE-2026-53469 CRITICAL - 9.1

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, lead...

Published: Jun 10, 2026
Source: NVD
CVE-2026-45558 CRITICAL - 9.9

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-45556 CRITICAL - 9.9

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_rest...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-45552 CRITICAL - 9.9

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request โ†’ @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, c...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-45550 CRITICAL - 9.1

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() โ€” which validates that the caller has some group, not that the target che...

Vendor: roxy-wi
Product: roxy-wi
Published: Jun 10, 2026
Source: NVD
CVE-2026-48031 CRITICAL - 9.1

Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery

Vendor: go
Product: github.com/dhax/go-base
Published: Jun 10, 2026
Source: GitHub
CVE-2025-6254 CRITICAL - 9.8

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers...

Published: Jun 10, 2026
Source: NVD
CVE-2026-9067 CRITICAL - 9.1

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to uplo...

Published: Jun 10, 2026
Source: NVD