Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-10847 HIGH 7.8 2026-06-11 A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with …
CVE-2026-11816 HIGH Patched 8.1 2026-06-11 Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filte…
CVE-2026-38581 CRITICAL 9.8 2026-06-11 SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /sub…
CVE-2026-53661 NONE Patched — 2026-06-11 Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta …
CVE-2026-53723 MEDIUM Patched 5.8 2026-06-11 Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse respo…
CVE-2026-6338 NONE — 2026-06-11 A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a …
CVE-2026-8406 NONE — 2026-06-11 openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can reque…
CVE-2024-45636 MEDIUM Patched 4.1 2026-06-11 IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.
CVE-2026-11839 CRITICAL 9.9 2026-06-11 Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affe…
CVE-2026-3341 MEDIUM Patched 5.4 2026-06-11 IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized req…
CVE-2026-4096 MEDIUM Patched 6.5 2026-06-11 IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to cond…
CVE-2026-53777 HIGH Patched 8.1 2026-06-11 Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running proces…
CVE-2026-7787 HIGH Patched 7.5 2026-06-11 IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
CVE-2026-7870 HIGH 8.8 2026-06-11 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run wi…
CVE-2026-9648 CRITICAL 9.1 2026-06-11 The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside…
CVE-2026-11945 MEDIUM Patched 6.4 2026-06-11 PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular ke…
CVE-2026-44486 HIGH Patched 7.5 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in…
CVE-2026-44487 HIGH Patched 7.5 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a red…
CVE-2026-44488 HIGH Patched 7.5 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when reque…
CVE-2026-44489 LOW Patched 3.7 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still const…
CVE-2026-44490 MEDIUM Patched 4.8 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype…
CVE-2026-44492 HIGH Patched 8.6 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IP…
CVE-2026-44494 HIGH Patched 8.7 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that…
CVE-2026-44495 HIGH Patched 7.0 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config proc…
CVE-2026-44496 HIGH Patched 7.5 2026-06-11 Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression …