Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
Showing 141 - 160 of 13,286 CVEs

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

Vendor: npm
Product: @anthropic-ai/claude-code
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54022 MEDIUM - 5.3

Open WebUI: Any authenticated user can read other users' private notes via Socket.IO

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54021 MEDIUM - 6.3

Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54019 MEDIUM - 6.5

Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-35069 MEDIUM - 5.7

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-20246 MEDIUM - 6.0

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this v...

Vendor: Cisco
Product: Cisco Umbrella Insights Virtual Appliance
Published: Jun 17, 2026
Source: NVD
CVE-2026-20220 MEDIUM - 6.3

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template...

Vendor: Cisco
Product: Cisco Crosswork Network Change Automation
Published: Jun 17, 2026
Source: NVD
CVE-2026-1288 MEDIUM - 5.5

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Published: Jun 17, 2026
Source: NVD
CVE-2026-12515 MEDIUM - 4.3

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to m...

Vendor: Red Hat
Product: Red Hat Hardened Images, Red Hat Satellite 6
Published: Jun 17, 2026
Source: NVD
CVE-2025-32748 MEDIUM - 4.3

Dell PowerFlex rack, version(s) RCM 3.7/3.7, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.

Vendor: Dell
Product: PowerFlex rack
Published: Jun 17, 2026
Source: NVD
CVE-2026-55748 MEDIUM - 6.0

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

Vendor: OpenStack
Product: Horizon
Published: Jun 17, 2026
Source: NVD
CVE-2026-48142 MEDIUM - 4.8

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send reques...

Vendor: F5
Product: NGINX Open Source, NGINX Plus
Published: Jun 17, 2026
Source: NVD
CVE-2026-48117 MEDIUM - 6.8

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack in which an attacker could register an account using a victim's email address with an attacker-controlled password before the victim completed acco...

Vendor: fduflyer
Product: DroneAware-Node-Releases
Published: Jun 17, 2026
Source: NVD
CVE-2026-40641 MEDIUM - 4.8

Dell PowerFlex Manager, version(s) 4.6.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35162 MEDIUM - 4.3

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-35067 MEDIUM - 5.7

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

Vendor: Dell
Product: PowerFlex
Published: Jun 17, 2026
Source: NVD
CVE-2026-12528 MEDIUM - 5.4

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 17, 2026
Source: NVD
CVE-2024-47477 MEDIUM - 6.5

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.

Vendor: Dell
Product: PowerFlex Manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-54016 MEDIUM - 4.3

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54817 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

Vendor: FluxBuilder
Product: MStore API
Published: Jun 17, 2026
Source: NVD