| CVE-2020-37248 |
|
08.06.2026 |
6.5 |
| CVE-2025-71315 |
drm/vkms: Convert to DRM's vblank timer |
08.06.2026 |
|
| CVE-2026-11522 |
Tenda W20E setPortMirror formSetPortMirror stack-based overflow |
08.06.2026 |
|
| CVE-2026-11523 |
Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow |
08.06.2026 |
|
| CVE-2026-11524 |
Tenda W20E Web Management modifyWifiFilterRules stack-based overflow |
08.06.2026 |
|
| CVE-2026-11528 |
Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow |
08.06.2026 |
|
| CVE-2026-11529 |
designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection |
08.06.2026 |
|
| CVE-2026-22164 |
GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical |
08.06.2026 |
|
| CVE-2026-29167 |
Apache HTTP Server: mod_ldap per-dir use-after-free |
08.06.2026 |
|
| CVE-2026-29170 |
Apache HTTP Server: mod_proxy_ftp XSS |
08.06.2026 |
|
| CVE-2026-34194 |
GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count |
08.06.2026 |
|
| CVE-2026-34355 |
Apache HTTP Server: mod_proxy_html buffer overflow |
08.06.2026 |
|
| CVE-2026-34356 |
Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow |
08.06.2026 |
|
| CVE-2026-36786 |
|
08.06.2026 |
|
| CVE-2026-42535 |
Apache HTTP Server: mod_dav_fs protected directory access |
08.06.2026 |
|
| CVE-2026-42536 |
Apache HTTP Server: mod_xml2enc heap overflow |
08.06.2026 |
|
| CVE-2026-42861 |
Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment |
08.06.2026 |
|
| CVE-2026-42862 |
Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment |
08.06.2026 |
|
| CVE-2026-42863 |
Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment |
08.06.2026 |
|
| CVE-2026-43951 |
Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash |
08.06.2026 |
|
| CVE-2026-44119 |
Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules |
08.06.2026 |
|
| CVE-2026-44185 |
Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` |
08.06.2026 |
|
| CVE-2026-44186 |
Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp |
08.06.2026 |
|
| CVE-2026-44631 |
Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow |
08.06.2026 |
|
| CVE-2026-46274 |
io-wq: check that the predecessor is hashed in io_wq_remove_pending() |
08.06.2026 |
|
| CVE-2026-46275 |
Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths |
08.06.2026 |
|
| CVE-2026-46440 |
Flowise: Basic Auth Credentials Exposed via API |
08.06.2026 |
|
| CVE-2026-46441 |
Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment |
08.06.2026 |
|
| CVE-2026-46442 |
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape |
08.06.2026 |
|
| CVE-2026-46443 |
Flowise: Credential Data Leak |
08.06.2026 |
|
| CVE-2026-46444 |
Flowise: Vector Store No Permission Checks |
08.06.2026 |
|
| CVE-2026-46475 |
Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover |
08.06.2026 |
|
| CVE-2026-46476 |
Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover |
08.06.2026 |
|
| CVE-2026-46477 |
Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover |
08.06.2026 |
|
| CVE-2026-46478 |
Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover |
08.06.2026 |
|
| CVE-2026-46479 |
Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover |
08.06.2026 |
|
| CVE-2026-46480 |
Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover |
08.06.2026 |
|
| CVE-2026-46656 |
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions |
08.06.2026 |
8.8 |
| CVE-2026-46657 |
Bludit's persistent authentication tokens not revoked upon account disablement |
08.06.2026 |
7.1 |
| CVE-2026-48488 |
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing |
08.06.2026 |
|
| CVE-2026-48913 |
Apache HTTP Server: mod_http2 memory corruption when file handles exhausted |
08.06.2026 |
|
| CVE-2026-49755 |
Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies |
08.06.2026 |
|
| CVE-2026-49756 |
Multipart form-data header injection in Req via unescaped name/filename/content_type |
08.06.2026 |
|
| CVE-2026-49975 |
Apache HTTP Server: mod_http2 denial of service |
08.06.2026 |
|
| CVE-2026-11516 |
UTT HiPER 2610G formNatStaticMap strcpy buffer overflow |
08.06.2026 |
|
| CVE-2026-11517 |
UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow |
08.06.2026 |
|
| CVE-2026-11518 |
SourceCodester Inventory System User Management users.php cross site scripting |
08.06.2026 |
|
| CVE-2026-11519 |
SourceCodester Inventory System Account Creation users_handler.php improper authorization |
08.06.2026 |
|
| CVE-2026-11520 |
SourceCodester Inventory System header.php cross site scripting |
08.06.2026 |
|
| CVE-2026-11521 |
Mohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionController.java improper authorization |
08.06.2026 |
|
| CVE-2026-25558 |
QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager |
08.06.2026 |
|
| CVE-2026-36789 |
|
08.06.2026 |
|
| CVE-2026-43972 |
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection |
08.06.2026 |
|
| CVE-2026-43973 |
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion |
08.06.2026 |
|
| CVE-2026-43974 |
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM |
08.06.2026 |
|
| CVE-2026-49232 |
Routinator exits when accepting an incoming HTTP or RTR connection fails |
08.06.2026 |
|
| CVE-2026-49233 |
Routinator cache path traversal using rogue rsync URIs |
08.06.2026 |
|
| CVE-2026-49234 |
Routinator crashes on specifically crafted ASN strings in the API |
08.06.2026 |
|
| CVE-2026-49235 |
Routinator crashes on specifically crafted RRDP XML files |
08.06.2026 |
|
| CVE-2026-11511 |
Bolt CMS HTML Attribute TextType.php HTML injection |
08.06.2026 |
|
| CVE-2026-11512 |
itsourcecode Hospital Management System billing.php cross site scripting |
08.06.2026 |
|
| CVE-2026-11513 |
itsourcecode Hospital Management System adminaccount.php sql injection |
08.06.2026 |
|
| CVE-2026-11514 |
itsourcecode Hospital Management System addpatient.php sql injection |
08.06.2026 |
|
| CVE-2026-11515 |
SourceCodester Barangay Resident Profiling and Information Management System Password Reset passsword_reset.php hard-coded password |
08.06.2026 |
|
| CVE-2026-11577 |
Keycloak: keycloak: privilege escalation via partialimport fgap permission bypass |
08.06.2026 |
|
| CVE-2026-7186 |
Fix stored XSS in URL dashboard widget via dangerous URI schemes |
08.06.2026 |
|
| CVE-2026-7765 |
User Messages widget leaked issuer messages on shared dashboards |
08.06.2026 |
|
| CVE-2026-8078 |
Fix stored XSS in global settings change log |
08.06.2026 |
|
| CVE-2026-8833 |
XSS in urls |
08.06.2026 |
|
| CVE-2026-9549 |
Fix XSS in service discovery active check output |
08.06.2026 |
|
| CVE-2026-11504 |
Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based overflow |
08.06.2026 |
|
| CVE-2026-11505 |
GL.iNet XE3000 glnassys hard-coded key |
08.06.2026 |
|
| CVE-2026-11506 |
CodeAstro Leave Management System search_staff_for_deletion.php sql injection |
08.06.2026 |
|
| CVE-2026-11507 |
CodeAstro Leave Management System delete_leave_type.php sql injection |
08.06.2026 |
|
| CVE-2026-11508 |
CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection |
08.06.2026 |
|
| CVE-2026-11509 |
CodeAstro Leave Management System search_staff_for_updation.php sql injection |
08.06.2026 |
|
| CVE-2026-11510 |
CodeAstro Leave Management System add_leave.php sql injection |
08.06.2026 |
|
| CVE-2026-11569 |
Quay: quay: stored xss via filedrop svg upload |
08.06.2026 |
|
| CVE-2026-3011 |
Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes' |
08.06.2026 |
6.4 |
| CVE-2026-47430 |
Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews |
08.06.2026 |
|
| CVE-2026-50751 |
User Authentication Bypass in VPN Remote Access and Mobile Access |
08.06.2026 |
|
| CVE-2026-50752 |
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1 |
08.06.2026 |
7.4 |
| CVE-2024-56120 |
|
08.06.2026 |
|
| CVE-2024-56121 |
|
08.06.2026 |
|
| CVE-2024-56122 |
|
08.06.2026 |
|
| CVE-2024-56123 |
|
08.06.2026 |
|
| CVE-2026-11500 |
Weaviate Static API Key client.go validateConfig authorization |
08.06.2026 |
|
| CVE-2026-11501 |
SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection |
08.06.2026 |
|
| CVE-2026-11502 |
JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect |
08.06.2026 |
|
| CVE-2026-11503 |
Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow |
08.06.2026 |
|
| CVE-2026-9506 |
Path Traversal Vulnerability in Bagisto |
08.06.2026 |
|
| CVE-2026-11497 |
D-Link DCS-5615 Boa Webserver boa.conf least privilege violation |
08.06.2026 |
|
| CVE-2026-11498 |
Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow |
08.06.2026 |
|
| CVE-2026-11499 |
Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow |
08.06.2026 |
|
| CVE-2026-3238 |
Samba: denial of service against ad dc wins server |
08.06.2026 |
|
| CVE-2026-41722 |
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) |
08.06.2026 |
8 |
| CVE-2026-41723 |
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) |
08.06.2026 |
8 |
| CVE-2026-41724 |
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) |
08.06.2026 |
8 |
| CVE-2026-11490 |
code-projects Online Music Site Search.php sql injection |
08.06.2026 |
|
| CVE-2026-11491 |
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting |
08.06.2026 |
|
| CVE-2026-11492 |
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation |
08.06.2026 |
|
| CVE-2026-11493 |
Tenda AC15 Samba smb.conf weak password |
08.06.2026 |
|
| CVE-2026-11494 |
TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation |
08.06.2026 |
|
| CVE-2026-11495 |
CodeAstro Ingredients Stock Management System add_stock.php sql injection |
08.06.2026 |
|
| CVE-2026-11483 |
SourceCodester Class and Exam Timetabling System archive4.php sql injection |
08.06.2026 |
|
| CVE-2026-11484 |
SourceCodester Class and Exam Timetabling System archive3.php sql injection |
08.06.2026 |
|
| CVE-2026-11485 |
SourceCodester Class and Exam Timetabling System archive2.php sql injection |
08.06.2026 |
|
| CVE-2026-11486 |
SourceCodester Class and Exam Timetabling System archive1.php sql injection |
08.06.2026 |
|
| CVE-2026-11487 |
Neovim View Branch secure.lua M.read command injection |
08.06.2026 |
|
| CVE-2026-11488 |
code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection |
08.06.2026 |
|
| CVE-2026-11489 |
code-projects Online Music Site AdminDeleteAlbum.php sql injection |
08.06.2026 |
|
| CVE-2026-11478 |
kokke tiny-regex-c Pattern re.c matchstar redos |
08.06.2026 |
|
| CVE-2026-11479 |
yoanbernabeu grepai Qdrant Backend chunker.go weak hash |
08.06.2026 |
|
| CVE-2026-11480 |
Chengdu Everbrite Network Technology BeikeShop Admin Design Builder Endpoint admin.php sql injection |
08.06.2026 |
|
| CVE-2026-11481 |
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash |
08.06.2026 |
|
| CVE-2026-11482 |
SourceCodester Class and Exam Timetabling System archive5.php sql injection |
08.06.2026 |
|
| CVE-2021-47982 |
WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset |
08.06.2026 |
|
| CVE-2021-47983 |
WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code |
08.06.2026 |
|
| CVE-2021-47984 |
WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS |
08.06.2026 |
|
| CVE-2022-50953 |
WordPress Plugin admin-word-count-column 2.2 Local File Read |
08.06.2026 |
|
| CVE-2023-54350 |
WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated |
08.06.2026 |
|
| CVE-2023-54351 |
WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments |
08.06.2026 |
|
| CVE-2023-54352 |
WordPress Seotheme Remote Code Execution Unauthenticated |
08.06.2026 |
|
| CVE-2024-58348 |
WordPress Background Image Cropper 1.2 Remote Code Execution |
08.06.2026 |
|
| CVE-2024-58349 |
WordPress Theme Travelscape 1.0.3 Arbitrary File Upload |
08.06.2026 |
|
| CVE-2026-11475 |
Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection |
08.06.2026 |
|
| CVE-2026-11476 |
Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization |
08.06.2026 |
|
| CVE-2026-11477 |
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect |
08.06.2026 |
|
| CVE-2026-11470 |
hs-web hsweb-framework File Upload FileUploadProperties.java denied path traversal |
08.06.2026 |
|
| CVE-2026-11471 |
SourceCodester Class and Exam Timetabling System index2.php sql injection |
08.06.2026 |
|
| CVE-2026-11472 |
SourceCodester Class and Exam Timetabling System index1.php sql injection |
08.06.2026 |
|
| CVE-2026-11473 |
jflyfox jfinal_cms AdvicefeedbackController.java list sql injection |
08.06.2026 |
|
| CVE-2026-11474 |
Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload |
08.06.2026 |
|
| CVE-2026-11469 |
jishenghua jshERP platformConfig Add Endpoint PlatformConfigService.java insertPlatformConfig server-side request forgery |
07.06.2026 |
|
| CVE-2026-11467 |
jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal |
08.06.2026 |
|
| CVE-2026-11468 |
SourceCodester Hospitals Patient Records Management System page room_types cross site scripting |
07.06.2026 |
|
| CVE-2026-11465 |
songquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic error |
08.06.2026 |
|
| CVE-2026-11466 |
zilliztech deep-searcher collection_router.py CollectionRouter.invoke access control |
08.06.2026 |
|
| CVE-2026-11464 |
JeecgBoot User List Endpoint SysUserController.java queryPageList information disclosure |
07.06.2026 |
|
| CVE-2026-11462 |
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization |
08.06.2026 |
|
| CVE-2026-11463 |
USCiLab Cereal Shared Pointer type confusion |
07.06.2026 |
|
| CVE-2026-11461 |
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization |
07.06.2026 |
|
| CVE-2026-11460 |
Boost Serialization improper validation of specified type of input |
08.06.2026 |
|