Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-44705 HIGH Patched 8.2 2026-06-11 tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended tem…
CVE-2026-49982 HIGH Patched 8.2 2026-06-11 tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It…
CVE-2026-11986 MEDIUM Patched 4.9 2026-06-11 A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-r…
CVE-2026-3329 HIGH Patched 7.5 2026-06-11 A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
CVE-2026-46697 HIGH Patched 7.5 2026-06-11 Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Medi…
CVE-2026-46698 MEDIUM Patched 5.3 2026-06-11 Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_…
CVE-2026-47157 MEDIUM Patched 6.5 2026-06-11 aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs be…
CVE-2026-48546 HIGH Patched 7.3 2026-06-11 KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require fu…
CVE-2026-49261 CRITICAL Patched 10.0 2026-06-11 MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and …
CVE-2025-24165 MEDIUM Patched 5.5 2026-06-11 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to …
CVE-2025-24268 MEDIUM Patched 5.5 2026-06-11 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sens…
CVE-2025-24284 HIGH Patched 8.8 2026-06-11 This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.
CVE-2025-30431 MEDIUM Patched 5.5 2026-06-11 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access pr…
CVE-2025-30459 MEDIUM Patched 5.5 2026-06-11 A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
CVE-2025-31272 HIGH Patched 7.8 2026-06-11 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious co…
CVE-2025-43278 MEDIUM Patched 5.5 2026-06-11 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
CVE-2025-43339 MEDIUM Patched 5.5 2026-06-11 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.
CVE-2025-46293 MEDIUM Patched 5.5 2026-06-11 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
CVE-2025-46308 MEDIUM Patched 5.3 2026-06-11 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensiti…
CVE-2025-46313 MEDIUM Patched 5.5 2026-06-11 A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
CVE-2025-46315 HIGH Patched 7.5 2026-06-11 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
CVE-2026-11774 HIGH 7.6 2026-06-11 An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet …
CVE-2026-45176 HIGH Patched 7.8 2026-06-11 Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker coul…
CVE-2026-45177 CRITICAL Patched 9.1 2026-06-11 Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker coul…
CVE-2026-45178 HIGH Patched 8.1 2026-06-11 Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing s…