Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-11626 | NONE | — | 2026-06-10 | CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, which is a type of issue whereby an attacker with lim… | |
| CVE-2026-50637 | HIGH | Patched | 8.2 | 2026-06-10 | Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separat… |
| CVE-2026-50638 | CRITICAL | Patched | 9.1 | 2026-06-10 | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mut… |
| CVE-2026-50639 | MEDIUM | Patched | 6.5 | 2026-06-10 | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow muti… |
| CVE-2026-1220 | HIGH | Patched | 7.5 | 2026-06-10 | Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-45106 | MEDIUM | Patched | 4.6 | 2026-06-10 | Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor w… |
| CVE-2026-46529 | HIGH | Patched | 7.8 | 2026-06-10 | Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26… |
| CVE-2026-46643 | NONE | Patched | — | 2026-06-10 | Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/usr/bin/wkhtmltopdf’) r… |
| CVE-2026-46683 | NONE | Patched | — | 2026-06-10 | Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability … |
| CVE-2026-50127 | MEDIUM | Patched | 5.9 | 2026-06-10 | Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ran… |
| CVE-2026-6893 | HIGH | 7.5 | 2026-06-10 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protoco… | |
| CVE-2022-26758 | HIGH | Patched | 7.1 | 2026-06-10 | A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue … |
| CVE-2022-48575 | LOW | Patched | 3.5 | 2026-06-10 | A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4. |
| CVE-2026-0266 | MEDIUM | Patched | 4.8 | 2026-06-10 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the we… |
| CVE-2026-0267 | MEDIUM | Patched | 5.5 | 2026-06-10 | An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecti… |
| CVE-2026-0268 | MEDIUM | Patched | 4.4 | 2026-06-10 | A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Pr… |
| CVE-2026-0269 | MEDIUM | Patched | 5.7 | 2026-06-10 | A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a… |
| CVE-2026-0270 | HIGH | Patched | 7.5 | 2026-06-10 | A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the abil… |
| CVE-2026-0271 | HIGH | Patched | 7.8 | 2026-06-10 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. … |
| CVE-2026-0272 | HIGH | Patched | 7.2 | 2026-06-10 | A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform… |
| CVE-2026-0273 | HIGH | Patched | 7.2 | 2026-06-10 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as … |
| CVE-2026-0274 | CRITICAL | 9.1 | 2026-06-10 | An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access an… | |
| CVE-2026-10142 | HIGH | Patched | 7.5 | 2026-06-10 | kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust me… |
| CVE-2026-10143 | HIGH | Patched | 7.5 | 2026-06-10 | kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze th… |
| CVE-2026-11604 | MEDIUM | Patched | 6.5 | 2026-06-10 | An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-bas… |