Vulnerebility JUNE H  ECV  KB  KEV |  2026()  2025() |
Vulnerebility Calendar  Top Vulnerebility  List of Attack  CWE   Anti-Debug Tricks


2026  January  February  March  April  May  June  July  August  September  October  November  December


DATE

NAME

INFO

CATEGORY

SUBCATE

30.6.26 CVE-2026-33017 Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-48558 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-43715 A use-after-free issue that could result in memory corruption when processing maliciously crafted web content. It was addressed with improved memory management. VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-43745 An out-of-bounds write issue that could result in an unexpected Safari crash when processing maliciously crafted web content. It was addressed with improved input validation. VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-43716 An unspecified issue that could result in an unexpected Safari crash when processing maliciously crafted web content. It was addressed with improved memory handling. VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-43707 A memory corruption issue that could result in an unexpected process crash when processing maliciously crafted web content. It was addressed with improved memory handling. VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-8037 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-48558 SimpleHelp Authentication Bypass Vulnerability VULNEREBILITY VULNEREBILITY
30.6.26 CVE-2026-46817 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. VULNEREBILITY VULNEREBILITY
29.6.26 CVE-2026-8461 An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2. VULNEREBILITY VULNEREBILITY
29.6.26 CVE-2026-55200 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution. VULNEREBILITY VULNEREBILITY
27.6.26 CVE-2026-43503 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. VULNEREBILITY VULNEREBILITY
27.6.26 CVE-2026-12957 Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. VULNEREBILITY VULNEREBILITY
27.6.26 CVE-2026-46331 In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. VULNEREBILITY VULNEREBILITY
27.6.26 CVE-2026-12569 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030 VULNEREBILITY VULNEREBILITY
25.6.26 CVE-2026-20245 A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. VULNEREBILITY VULNEREBILITY
24.6.26 CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability VULNEREBILITY VULNEREBILITY
24.6.26 CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability VULNEREBILITY VULNEREBILITY
24.6.26 CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability VULNEREBILITY VULNEREBILITY
24.6.26 CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability VULNEREBILITY VULNEREBILITY
23.6.26 CVE-2024-40766 An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. VULNEREBILITY VULNEREBILITY
23.6.26 CVE-2026-41947 (CVSS score: 9.1) - An authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. VULNEREBILITY VULNEREBILITY
23.6.26 CVE-2026-41948 (CVSS score: 9.4) - A path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization and access internal, private endpoints. VULNEREBILITY VULNEREBILITY
23.6.26 CVE-2026-41949 (CVSS score: 7.5/5.9) - An authorization bypass vulnerability in the file preview endpoint ("/console/api/files/{file_id}/preview") that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. VULNEREBILITY VULNEREBILITY
23.6.26 CVE-2026-41950 (CVSS score: 6.5) - An authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. VULNEREBILITY VULNEREBILITY
22.6.26 CVE-2026-50012 Debian Linux - squid - None Ubuntu Linux - Heap-based Buffer Overflow attack against cache digests VULNEREBILITY VULNEREBILITY
22.6.26 Squidbleed Debian Linux - squid - None Ubuntu Linux - Out-of-bounds Read attack against the FTP gateway VULNEREBILITY VULNEREBILITY
21.6.26 CVE-2026-11311 When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping.

VULNEREBILITY

VULNEREBILITY

21.6.26 CVE-2026-50107 When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are rendered directly into NGINX configuration templates without sanitization or escaping.

VULNEREBILITY

VULNEREBILITY

21.6.26 CVE-2026-48172 LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability.

VULNEREBILITY

VULNEREBILITY

21.6.26 CVE-2026-48558 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature.

VULNEREBILITY

VULNEREBILITY

20.6.26 CVE-2026-4020 The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it.

VULNEREBILITY

VULNEREBILITY

19.6.26 CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is configured to use the HTTP/3 QUIC module to reopen a QPACK encoder stream by means of a specially crafted HTTP/3 session, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.

VULNEREBILITY

VULNEREBILITY

19.6.26 CVE-2026-42055 (CVSS v4 score: 9.2) - A heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules that could be triggered by a remote unauthenticated attacker when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 MB, and execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.

VULNEREBILITY

VULNEREBILITY

19.6.26 CVE-2025-20701 About the security content of Beats Firmware Update 1B211

VULNEREBILITY

VULNEREBILITY

18.6.26 CVE-2023-52271 The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).

VULNEREBILITY

VULNEREBILITY

18.6.26 CVE-2025-61155 The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a handle to the driver device and send specially crafted IOCTL requests.

VULNEREBILITY

VULNEREBILITY

18.6.26 CVE-2025-1055 A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating system.

VULNEREBILITY

VULNEREBILITY

18.6.26 CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

17.6.26 CVE-2026-48907 A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

VULNEREBILITY

VULNEREBILITY

16.6.26 CVE-2026-25089 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

VULNEREBILITY

VULNEREBILITY

16.6.26 CVE-2026-39808 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

VULNEREBILITY

VULNEREBILITY

16.6.26 CVE-2026-39813 A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

VULNEREBILITY

VULNEREBILITY

16.6.26 CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

VULNEREBILITY

VULNEREBILITY

16.6.26 CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

VULNEREBILITY

VULNEREBILITY

15.6.26 CVE-2026-40217 LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

VULNEREBILITY

VULNEREBILITY

15.6.26 CVE-2026-47102 LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed.

VULNEREBILITY

VULNEREBILITY

15.6.26 CVE-2026-47101 LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions.

VULNEREBILITY

VULNEREBILITY

15.6.26 CVE-2026-42824 M365 Copilot Information Disclosure Vulnerability

VULNEREBILITY

VULNEREBILITY

15.6.26 CVE-2026-0257 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-10520

VULNEREBILITY

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-34910

VULNEREBILITY

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-34909 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-34908 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-52806 CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-10520 An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-34910 A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-34909 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-34908 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

VULNEREBILITY

VULNEREBILITY

14.6.26 CVE-2026-52806 CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)

VULNEREBILITY

VULNEREBILITY

13.6.26

CVE-2026-20253 In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

VULNEREBILITY

VULNEREBILITY

13.6.26

CVE-2024-20399

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands.

VULNEREBILITY

VULNEREBILITY

12.6.26

CVE-2026-27022

(CVSS score: 6.5) - A RediSearch Query Injection in @langchain/langgraph-checkpoint-redis that can be used to bypass access controls. (Affects @langchain/langgraph-checkpoint-redis versions before 1.0.1)

VULNEREBILITY

VULNEREBILITY

12.6.26

CVE-2026-28277

(CVSS score: 6.8) - An unsafe msgpack deserialization vulnerability in LangGraph that could be used to trigger object reconstruction when a checkpoint is loaded by an attacker who can modify checkpoint data. (Affects langgraph versions before 1.0.10)

VULNEREBILITY

VULNEREBILITY

12.6.26

CVE-2025-67644

(CVSS score: 7.3) - A SQL injection vulnerability exists in LangGraph's SQLite checkpoint implementation that allows attackers to manipulate SQL queries through metadata filter keys. (Affects langgraph-checkpoint-sqlite versions before 3.0.1)

VULNEREBILITY

VULNEREBILITY

12.6.26

CVE-2026-35273

Oracle Security Alert Advisory - CVE-2026-35273

VULNEREBILITY

VULNEREBILITY

10.6.26 CVE-2026-25089 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-5027 The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../'). VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-20245 (CVSS score: 7.8) - An improper encoding or escaping of output vulnerability in Cisco Catalyst SD-WAN Manager that could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-11645 (CVSS score: 8.8) - An out-of-bounds read and write vulnerability in Google Chrome V8 that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-7473 (CVSS score: 6.9) - An incomplete comparison with missing factors vulnerability in Arista Extensible Operating System (EOS) that could be exploited to process non-configured tunnel traffic. VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-47291 (CVSS score: 9.8) - An integer overflow or wraparound flaw in Windows HTTP.sys that allows an unauthorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44815 (CVSS score: 9.8) - A stack-based buffer overflow vulnerability in Windows DHCP Client that allows an unauthorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-45655 Windows BitLocker Security Feature Bypass Vulnerability VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-45658 Windows BitLocker Security Feature Bypass Vulnerability VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-50507 Windows BitLocker Security Feature Bypass Vulnerability VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-45586 (CVSS score: 7.8) - Windows Collaborative Translation Framework (CTFMON) privilege escalation vulnerability VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-49160 (CVSS score: 7.5) - HTTP.sys denial-of-service vulnerability VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44295 Code injection in pbjs static output from crafted schema names VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44294 Denial of service from crafted field names in generated code VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44292 Per-instance prototype injection in generated message constructors VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44291 Code generation gadget after prototype pollution VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44290 Process-wide denial of service when loading schemas with unsafe option paths VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44289 Denial of service through unbounded protobuf recursion VULNEREBILITY VULNEREBILITY
10.6.26 CVE-2026-44963 A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. VULNEREBILITY VULNEREBILITY
9.6.26 CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability VULNEREBILITY VULNEREBILITY
9.6.26 CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability VULNEREBILITY VULNEREBILITY
9.6.26 kernel/git/torvalds/linux.git nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. VULNEREBILITY VULNEREBILITY
9.6.26 CVE-2026-23111 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. VULNEREBILITY VULNEREBILITY
8.6.26 CVE-2026-50751 A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. VULNEREBILITY VULNEREBILITY
7.6.26 CVE-2026-49200 The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access. VULNEREBILITY VULNEREBILITY
7.6.26 CVE-2026-49201 The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection. VULNEREBILITY VULNEREBILITY
7.6.26 CVE-2024-21182 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. VULNEREBILITY VULNEREBILITY
7.6.26 CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY
6.6.26 CVE-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability VULNEREBILITY VULNEREBILITY
6.6.26 CVE-2026-20245 Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability VULNEREBILITY VULNEREBILITY
5.6.26 MiniPlasma Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY
5.6.26 CVE-2026-3300 The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). VULNEREBILITY VULNEREBILITY
5.6.26 CVE-2026-20230 Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability VULNEREBILITY VULNEREBILITY
4.6.26 CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. VULNEREBILITY VULNEREBILITY
4.6.26 CVE-2026-45247 Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2022-0492 Linux Kernel Improper Authentication Vulnerability VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2025-48595 Android Framework Integer Overflow Vulnerability VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2026-41100 Microsoft 365 Copilot for Android Spoofing Vulnerability VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2026-41101 Microsoft 365 Copilot for Android Spoofing Vulnerability VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2026-42832 Microsoft Office Spoofing Vulnerability VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. VULNEREBILITY VULNEREBILITY
3.6.26 Android Security Bulletin—June 2026 This Android Security Bulletin contains details of security vulnerabilities that affect Android devices. Security patch levels of 2026-06-05 or later address all of these issues. To learn how to check a device's security patch level, see Check and update your Android version. VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2025-48595 In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2016-6581 A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called "HPACK Bomb" attack. VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2025-53020 Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2016-8740 The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request. VULNEREBILITY VULNEREBILITY
3.6.26 CVE-2016-1546 The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows. VULNEREBILITY VULNEREBILITY
1.6.26 CVE-2026-8732 The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. VULNEREBILITY VULNEREBILITY