Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,970
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,941 - 1,960 of 34,447 CVEs
CVE-2025-46308 MEDIUM - 5.3

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.

Vendor: Apple
Product: iOS and iPadOS, macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-46293 MEDIUM - 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-43339 MEDIUM - 5.5

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-43278 MEDIUM - 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-31272 HIGH - 7.8

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-30459 MEDIUM - 5.5

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-30431 MEDIUM - 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-24284 HIGH - 8.8

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-24268 MEDIUM - 5.5

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2025-24165 MEDIUM - 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS
Published: Jun 11, 2026
Source: NVD
CVE-2026-49261 CRITICAL - 10.0

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 1...

Vendor: MariaDB
Product: server
Published: Jun 11, 2026
Source: NVD
CVE-2026-48546 HIGH - 7.3

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull r...

Vendor: lingdojo
Product: kana-dojo
Published: Jun 11, 2026
Source: NVD
CVE-2026-46698 MEDIUM - 5.3

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the a...

Vendor: stefanbohacek
Product: fediverse-embeds-wordpress-plugin
Published: Jun 11, 2026
Source: NVD
CVE-2026-46697 HIGH - 7.5

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($...

Vendor: stefanbohacek
Product: fediverse-embeds-wordpress-plugin
Published: Jun 11, 2026
Source: NVD

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

Published: Jun 11, 2026
Source: NVD
CVE-2026-11986 MEDIUM - 4.9

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator w...

Vendor: Red Hat
Product: Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack
Published: Jun 11, 2026
Source: NVD
CVE-2026-49982 HIGH - 8.2

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when prefix, postfix, or template is supplied as a non-string value (Array, Buffer, or any object) whose includes(&...

Vendor: raszi
Product: node-tmp
Published: Jun 11, 2026
Source: NVD
CVE-2026-11945 MEDIUM - 6.4

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed...

Vendor: DALIBO
Product: PostgreSQL Anonymizer
Published: Jun 11, 2026
Source: NVD
CVE-2026-48062 CRITICAL - 9.8

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

Vendor: composer
Product: codeigniter4/framework
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48053 MEDIUM - 5.8

Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset

Vendor: pip
Product: kolibri
Published: Jun 11, 2026
Source: GitHub