Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-44705 | HIGH | Patched | 8.2 | 2026-06-11 | tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended tem… |
| CVE-2026-49982 | HIGH | Patched | 8.2 | 2026-06-11 | tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It… |
| CVE-2026-11986 | MEDIUM | Patched | 4.9 | 2026-06-11 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-r… |
| CVE-2026-3329 | HIGH | Patched | 7.5 | 2026-06-11 | A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints. |
| CVE-2026-46697 | HIGH | Patched | 7.5 | 2026-06-11 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Medi… |
| CVE-2026-46698 | MEDIUM | Patched | 5.3 | 2026-06-11 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_… |
| CVE-2026-47157 | MEDIUM | Patched | 6.5 | 2026-06-11 | aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs be… |
| CVE-2026-48546 | HIGH | Patched | 7.3 | 2026-06-11 | KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require fu… |
| CVE-2026-49261 | CRITICAL | Patched | 10.0 | 2026-06-11 | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and … |
| CVE-2025-24165 | MEDIUM | Patched | 5.5 | 2026-06-11 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to … |
| CVE-2025-24268 | MEDIUM | Patched | 5.5 | 2026-06-11 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sens… |
| CVE-2025-24284 | HIGH | Patched | 8.8 | 2026-06-11 | This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox. |
| CVE-2025-30431 | MEDIUM | Patched | 5.5 | 2026-06-11 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access pr… |
| CVE-2025-30459 | MEDIUM | Patched | 5.5 | 2026-06-11 | A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data. |
| CVE-2025-31272 | HIGH | Patched | 7.8 | 2026-06-11 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious co… |
| CVE-2025-43278 | MEDIUM | Patched | 5.5 | 2026-06-11 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data. |
| CVE-2025-43339 | MEDIUM | Patched | 5.5 | 2026-06-11 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data. |
| CVE-2025-46293 | MEDIUM | Patched | 5.5 | 2026-06-11 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data. |
| CVE-2025-46308 | MEDIUM | Patched | 5.3 | 2026-06-11 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensiti… |
| CVE-2025-46313 | MEDIUM | Patched | 5.5 | 2026-06-11 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. |
| CVE-2025-46315 | HIGH | Patched | 7.5 | 2026-06-11 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data. |
| CVE-2026-11774 | HIGH | 7.6 | 2026-06-11 | An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet … | |
| CVE-2026-45176 | HIGH | Patched | 7.8 | 2026-06-11 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker coul… |
| CVE-2026-45177 | CRITICAL | Patched | 9.1 | 2026-06-11 | Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker coul… |
| CVE-2026-45178 | HIGH | Patched | 8.1 | 2026-06-11 | Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing s… |