|
cve-2026-44742
|
Postorius: Postorius: Cross-Site Scripting via unescaped HTML in message subject |
MEDIUM
|
5.4
|
0.33%
|
cvelistv5 |
2026-06-28 |
|
cve-2026-42897
|
Microsoft Exchange Server Cross-Site Scripting Vulnerability |
HIGH
|
N/A
|
0.52%
|
cvelistv5 |
2026-05-15 |
|
cve-2026-42271
|
BerriAI LiteLLM Command Injection Vulnerability |
HIGH
|
N/A
|
12.75%
|
cvelistv5 |
2026-06-08 |
|
cve-2026-42208
|
LiteLLM: LiteLLM: Unauthorized data access and modification via SQL injection |
CRITICAL
|
9.8
|
5.77%
|
cvelistv5 |
2026-07-11 |
|
cve-2026-42018
|
JFrog Artifactory Improper Authentication Vulnerability |
HIGH
|
7.5
|
9.80%
|
cvelistv5 |
2026-09-11 |
|
cve-2026-42016
|
JFrog Artifactory Incorrect Authorization Vulnerability |
HIGH
|
8.1
|
8.64%
|
cvelistv5 |
2026-09-11 |
|
cve-2026-41948
|
Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access |
CRITICAL
|
9.4
|
1.89%
|
cvelistv5 |
2026-06-22 |
|
cve-2026-41679
|
Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass |
CRITICAL
|
10.0
|
7.36%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-41176
|
github.com/rclone/rclone: Rclone: Unauthorized access to administrative functions through unauthenticated Remote Control endpoint. |
CRITICAL
|
9.8
|
3.22%
|
cvelistv5 |
2026-06-30 |
|
cve-2026-41091
|
Microsoft Defender Link Following Vulnerability |
HIGH
|
N/A
|
0.44%
|
cvelistv5 |
2026-05-20 |
|
cve-2026-41089
|
Windows Netlogon Remote Code Execution Vulnerability |
CRITICAL
|
9.8
|
0.97%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-4020
|
Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API |
HIGH
|
7.5
|
2.24%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-39987
|
Marimo Remote Code Execution Vulnerability |
HIGH
|
N/A
|
37.87%
|
cvelistv5 |
2026-04-23 |
|
cve-2026-39813
|
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests. |
CRITICAL
|
9.8
|
0.72%
|
cvelistv5 |
2026-06-18 |
|
cve-2026-39808
|
Fortinet FortiSandbox OS Command Injection Vulnerability |
HIGH
|
N/A
|
47.36%
|
cvelistv5 |
2026-07-16 |
|
cve-2026-3965
|
whyour qinglong API express.ts protection mechanism |
MEDIUM
|
6.3
|
0.47%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-3910
|
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability |
HIGH
|
N/A
|
1.03%
|
cvelistv5 |
2026-03-13 |
|
cve-2026-3909
|
Google Skia Out-of-Bounds Write Vulnerability |
HIGH
|
N/A
|
0.70%
|
cvelistv5 |
2026-03-13 |
|
cve-2026-38992
|
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator. |
CRITICAL
|
9.8
|
0.73%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-3836
|
dnf5: dnf5: Denial of Service via path traversal in D-Bus locale configuration |
MEDIUM
|
5.5
|
N/A
|
cvelistv5 |
2026-06-28 |
|
cve-2026-36356
|
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint. |
CRITICAL
|
9.1
|
3.56%
|
cvelistv5 |
2026-07-05 |
|
cve-2026-35273
|
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability |
CRITICAL
|
N/A
|
9.44%
|
cvelistv5 |
2026-06-12 |
|
cve-2026-34926
|
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability |
HIGH
|
N/A
|
0.54%
|
cvelistv5 |
2026-05-21 |
|
cve-2026-34910
|
Ubiquiti UniFi OS Improper Input Validation Vulnerability |
HIGH
|
N/A
|
45.77%
|
cvelistv5 |
2026-06-23 |
|
cve-2026-34909
|
Ubiquiti UniFi OS Path Traversal Vulnerability |
HIGH
|
N/A
|
1.79%
|
cvelistv5 |
2026-06-23 |
|
cve-2026-34908
|
Ubiquiti UniFi OS Improper Access Control Vulnerability |
HIGH
|
N/A
|
15.21%
|
cvelistv5 |
2026-06-23 |
|
cve-2026-34621
|
Adobe Acrobat and Reader Prototype Pollution Vulnerability |
HIGH
|
8.6
|
2.18%
|
cvelistv5 |
2026-04-13 |
|
cve-2026-34486
|
Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass |
HIGH
|
7.5
|
6.56%
|
cvelistv5 |
2026-08-07 |
|
cve-2026-34234
|
CtrlPanel: Unauthenticated RCE using installer script |
CRITICAL
|
10.0
|
4.54%
|
cvelistv5 |
2026-07-24 |
|
cve-2026-34197
|
Apache ActiveMQ Improper Input Validation Vulnerability |
HIGH
|
N/A
|
15.49%
|
cvelistv5 |
2026-04-16 |