Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-10847 | HIGH | 7.8 | 2026-06-11 | A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with … | |
| CVE-2026-11816 | HIGH | Patched | 8.1 | 2026-06-11 | Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filte… |
| CVE-2026-38581 | CRITICAL | 9.8 | 2026-06-11 | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /sub… | |
| CVE-2026-53661 | NONE | Patched | — | 2026-06-11 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta … |
| CVE-2026-53723 | MEDIUM | Patched | 5.8 | 2026-06-11 | Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse respo… |
| CVE-2026-6338 | NONE | — | 2026-06-11 | A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a … | |
| CVE-2026-8406 | NONE | — | 2026-06-11 | openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can reque… | |
| CVE-2024-45636 | MEDIUM | Patched | 4.1 | 2026-06-11 | IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user. |
| CVE-2026-11839 | CRITICAL | 9.9 | 2026-06-11 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affe… | |
| CVE-2026-3341 | MEDIUM | Patched | 5.4 | 2026-06-11 | IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized req… |
| CVE-2026-4096 | MEDIUM | Patched | 6.5 | 2026-06-11 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to cond… |
| CVE-2026-53777 | HIGH | Patched | 8.1 | 2026-06-11 | Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running proces… |
| CVE-2026-7787 | HIGH | Patched | 7.5 | 2026-06-11 | IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. |
| CVE-2026-7870 | HIGH | 8.8 | 2026-06-11 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run wi… | |
| CVE-2026-9648 | CRITICAL | 9.1 | 2026-06-11 | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside… | |
| CVE-2026-11945 | MEDIUM | Patched | 6.4 | 2026-06-11 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular ke… |
| CVE-2026-44486 | HIGH | Patched | 7.5 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in… |
| CVE-2026-44487 | HIGH | Patched | 7.5 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a red… |
| CVE-2026-44488 | HIGH | Patched | 7.5 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when reque… |
| CVE-2026-44489 | LOW | Patched | 3.7 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still const… |
| CVE-2026-44490 | MEDIUM | Patched | 4.8 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype… |
| CVE-2026-44492 | HIGH | Patched | 8.6 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IP… |
| CVE-2026-44494 | HIGH | Patched | 8.7 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that… |
| CVE-2026-44495 | HIGH | Patched | 7.0 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config proc… |
| CVE-2026-44496 | HIGH | Patched | 7.5 | 2026-06-11 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression … |