NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 18, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1601 6.1 MEDIUM
Network
- - Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in … CWE-79
Cross-site Scripting
CVE-2026-32856 2026-06-11 04:41 2026-06-10 Show GitHub Exploit DB Packet Storm
1602 5.4 MEDIUM
Network
- - Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HT… CWE-79
Cross-site Scripting
CVE-2026-25557 2026-06-11 04:41 2026-06-10 Show GitHub Exploit DB Packet Storm
1603 6.1 MEDIUM
Network
- - OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious input through the … CWE-79
Cross-site Scripting
CVE-2026-34416 2026-06-11 04:41 2026-06-10 Show GitHub Exploit DB Packet Storm
1604 6.1 MEDIUM
Network
- - OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embeddi… CWE-79
Cross-site Scripting
CVE-2026-25860 2026-06-11 04:41 2026-06-10 Show GitHub Exploit DB Packet Storm
1605 6.1 MEDIUM
Network
- - OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious content through th… CWE-79
Cross-site Scripting
CVE-2026-34417 2026-06-11 04:41 2026-06-10 Show GitHub Exploit DB Packet Storm
1606 7.8 HIGH
Local
microsoft windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2019
windows_server_2022
windows_server_2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2026-42978 2026-06-11 04:38 2026-06-10 Show GitHub Exploit DB Packet Storm
1607 7.0 HIGH
Local
microsoft windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_23h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2019
windows_server_2022
windows_server_2025
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. CWE-416
 Use After Free
CVE-2026-42984 2026-06-11 04:37 2026-06-10 Show GitHub Exploit DB Packet Storm
1608 7.5 HIGH
Network
apache
f5
debian
http_server
nginx
debian_linux
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 … CWE-789
 Memory Allocation with Excessive Size Value
CVE-2026-49975 2026-06-11 04:36 2026-06-9 Show GitHub Exploit DB Packet Storm
1609 7.3 HIGH
Network
apache http_server Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67. CWE-416
 Use After Free
CVE-2026-48913 2026-06-11 04:31 2026-06-9 Show GitHub Exploit DB Packet Storm
1610 8.8 HIGH
Network
hcltech digital_experience
digital_experience_compose
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the… CWE-78
OS Command 
CVE-2026-21837 2026-06-11 04:25 2026-06-5 Show GitHub Exploit DB Packet Storm
1611 6.1 MEDIUM
Network
hcltech digital_experience_compose
digital_experience
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected … CWE-601
Open Redirect
CVE-2026-21826 2026-06-11 04:24 2026-06-5 Show GitHub Exploit DB Packet Storm
1612 6.1 MEDIUM
Network
hcltech digital_experience_compose
digital_experience
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser. CWE-79
Cross-site Scripting
CVE-2026-21825 2026-06-11 04:24 2026-06-5 Show GitHub Exploit DB Packet Storm
1613 8.8 HIGH
Network
google chrome Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CWE-125
Out-of-bounds Read
CVE-2026-11279 2026-06-11 04:22 2026-06-5 Show GitHub Exploit DB Packet Storm
1614 6.5 MEDIUM
Network
google chrome Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: … CWE-346
 Origin Validation Error
CVE-2026-11278 2026-06-11 04:19 2026-06-5 Show GitHub Exploit DB Packet Storm
1615 - -
- - bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompres… CWE-121
Stack-based Buffer Overflow
CVE-2026-9669 2026-06-11 04:16 2026-06-9 Show GitHub Exploit DB Packet Storm
1616 - -
- - An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. CWE-20
 Improper Input Validation 
CVE-2026-9211 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1617 - -
- - Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and fu… CWE-20
 Improper Input Validation 
CVE-2026-9210 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1618 7.5 HIGH
Network
securly securly Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes). CWE-407
 Inefficient Algorithmic Complexity
CVE-2026-8889 2026-06-11 04:16 2026-06-4 Show GitHub Exploit DB Packet Storm
1619 - -
- - tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. T… CWE-22
Path Traversal
CVE-2026-7774 2026-06-11 04:16 2026-06-5 Show GitHub Exploit DB Packet Storm
1620 - -
- - Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests. CWE-787
 Out-of-bounds Write
CVE-2026-3088 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1621 7.5 HIGH
Network
- - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindIndex parameter of the formIPMacBindDel function. This vulnerability allows attacker… CWE-120
Classic Buffer Overflow
CVE-2026-36800 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1622 7.5 HIGH
Network
- - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formWifiRadioSet function. This vulnerability al… CWE-121
Stack-based Buffer Overflow
CVE-2026-36792 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1623 7.5 HIGH
Network
- - Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the ip parameter of the fromNetToolGet function. This vulnerability allows att… CWE-121
Stack-based Buffer Overflow
CVE-2026-36784 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1624 7.5 HIGH
Network
- - Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain multiple stack overflows in the fromVirtualSer function via the puVar2, puVar1, __s2, __s1_00, and… CWE-121
Stack-based Buffer Overflow
CVE-2026-36779 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1625 9.1 CRITICAL
Network
- - An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. CWE-287
Improper Authentication
CVE-2026-36727 2026-06-11 04:16 2026-06-10 Show GitHub Exploit DB Packet Storm
1626 5.4 MEDIUM
Network
google chrome Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low) CWE-451
 User Interface (UI) Misrepresentation of Critical Information
CVE-2026-11232 2026-06-11 04:11 2026-06-5 Show GitHub Exploit DB Packet Storm
1627 8.8 HIGH
Network
google chrome Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CWE-416
 Use After Free
CVE-2026-11230 2026-06-11 04:09 2026-06-5 Show GitHub Exploit DB Packet Storm
1628 6.1 MEDIUM
Physics
google chrome Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sever… CWE-269
 Improper Privilege Management
CVE-2026-11229 2026-06-11 04:09 2026-06-5 Show GitHub Exploit DB Packet Storm
1629 4.3 MEDIUM
Network
- - In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR ap… CWE-117
 Improper Output Neutralization for Logs
CVE-2026-20260 2026-06-11 03:36 2026-06-11 Show GitHub Exploit DB Packet Storm
1630 10.0 CRITICAL
Network
- - Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this i… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-47938 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1631 7.3 HIGH
Local
- - OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (e… CWE-78
OS Command 
CVE-2026-11417 2026-06-11 03:35 2026-06-11 Show GitHub Exploit DB Packet Storm
1632 6.4 MEDIUM
Network
- - The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all v… CWE-79
Cross-site Scripting
CVE-2025-8444 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1633 9.8 CRITICAL
Network
- - The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly rest… CWE-269
 Improper Privilege Management
CVE-2025-6254 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1634 7.5 HIGH
Network
- - The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the use… CWE-89
SQL Injection
CVE-2026-3018 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1635 6.4 MEDIUM
Network
- - The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input… CWE-79
Cross-site Scripting
CVE-2026-8613 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1636 4.4 MEDIUM
Network
- - The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output… CWE-79
Cross-site Scripting
CVE-2026-8853 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1637 6.4 MEDIUM
Network
- - The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, an… CWE-79
Cross-site Scripting
CVE-2026-9019 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1638 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4… CWE-79
Cross-site Scripting
CVE-2026-49069 2026-06-11 03:35 2026-06-10 Show GitHub Exploit DB Packet Storm
1639 8.1 HIGH
Network
google chrome Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML pa… CWE-20
NVD-CWE-noinfo
 Improper Input Validation 
CVE-2026-11689 2026-06-11 03:35 2026-06-9 Show GitHub Exploit DB Packet Storm
1640 5.4 MEDIUM
Network
google chrome Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Hig… CWE-20
NVD-CWE-noinfo
 Improper Input Validation 
CVE-2026-11666 2026-06-11 03:31 2026-06-9 Show GitHub Exploit DB Packet Storm
1641 6.5 MEDIUM
Network
google chrome Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a cra… CWE-20
NVD-CWE-noinfo
 Improper Input Validation 
CVE-2026-11658 2026-06-11 03:30 2026-06-9 Show GitHub Exploit DB Packet Storm
1642 6.5 MEDIUM
Network
google chrome Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page… CWE-20
 Improper Input Validation 
CVE-2026-11653 2026-06-11 03:29 2026-06-9 Show GitHub Exploit DB Packet Storm
1643 5.5 MEDIUM
Local
cilium ebpf A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipul… CWE-189
CWE-190
Numeric Errors
 Integer Overflow or Wraparound
CVE-2026-10722 2026-06-11 03:28 2026-06-3 Show GitHub Exploit DB Packet Storm
1644 7.8 HIGH
Local
synology active_backup_for_business_recovery_media_creator An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users t… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2022-49036 2026-06-11 03:20 2026-06-3 Show GitHub Exploit DB Packet Storm
1645 5.3 MEDIUM
Local
lmsys sglang A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service.… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-10775 2026-06-11 03:19 2026-06-4 Show GitHub Exploit DB Packet Storm
1646 - -
- - An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to e… CWE-78
OS Command 
CVE-2026-9151 2026-06-11 03:17 2026-06-11 Show GitHub Exploit DB Packet Storm
1647 2.7 LOW
Network
- - A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This… CWE-1220
 Insufficient Granularity of Access Control
CVE-2026-9088 2026-06-11 03:17 2026-06-5 Show GitHub Exploit DB Packet Storm
1648 8.5 HIGH
Network
- - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety val… CWE-269
CWE-732
 Improper Privilege Management
 Incorrect Permission Assignment for Critical Resource
CVE-2026-50570 2026-06-11 03:17 2026-06-11 Show GitHub Exploit DB Packet Storm
1649 4.3 MEDIUM
Network
- - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, HTTPTriggerSpec.Validate() valid… CWE-20
 Improper Input Validation 
CVE-2026-50569 2026-06-11 03:17 2026-06-11 Show GitHub Exploit DB Packet Storm
1650 3.6 LOW
Local
- - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/ut… CWE-41
 Improper Resolution of Path Equivalence
CVE-2026-50568 2026-06-11 03:17 2026-06-11 Show GitHub Exploit DB Packet Storm