NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3101 8.8 HIGH
Network
- - Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-11171 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3102 8.8 HIGH
Network
- - Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page… CWE-787
 Out-of-bounds Write
CVE-2026-11173 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3103 8.8 HIGH
Network
- - Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) CWE-416
 Use After Free
CVE-2026-11262 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3104 5.1 MEDIUM
Local
- - Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Ch… CWE-269
 Improper Privilege Management
CVE-2026-11276 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3105 - -
- - Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) CWE-20
 Improper Input Validation 
CVE-2026-11280 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3106 - -
- - Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low) CWE-472
 External Control of Assumed-Immutable Web Parameter
CVE-2026-11290 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3107 - -
- - A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio ra… - CVE-2026-7762 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3108 - -
- - A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio rang… - CVE-2026-7763 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3109 6.5 MEDIUM
Network
- - Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. CWE-200
Information Exposure
CVE-2026-47655 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3110 6.4 MEDIUM
Network
- - All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first bei… CWE-29
 Path Traversal: '\..\filename'
CVE-2026-10732 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3111 - -
- - Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration. - CVE-2026-21034 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3112 - -
- - Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information. - CVE-2026-21035 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3113 - -
- - Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. - CVE-2026-21036 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3114 - -
- - Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege. - CVE-2026-21037 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3115 - -
- - Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. - CVE-2026-21038 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3116 - -
- - In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerabili… CWE-95
Eval Injection
CVE-2026-8914 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3117 6.5 MEDIUM
Network
- - Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks that resolve to files or directories outside the d… CWE-59
Link Following
CVE-2026-11322 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3118 5.4 MEDIUM
Network
- - In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences. CWE-79
Cross-site Scripting
CVE-2026-50591 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3119 6.4 MEDIUM
Network
- - In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view). CWE-79
Cross-site Scripting
CVE-2026-50592 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3120 3.6 LOW
Local
- - A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the c… CWE-327
CWE-328
 Use of a Broken or Risky Cryptographic Algorithm
 Use of Weak Hash
CVE-2026-11330 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3121 6.1 MEDIUM
Network
- - Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code throug… CWE-79
Cross-site Scripting
CVE-2026-50230 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3122 7.2 HIGH
Network
- - Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject malicious scripts by exploiting unescaped template va… CWE-79
Cross-site Scripting
CVE-2026-50231 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3123 5.3 MEDIUM
Network
- - Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonr… CWE-548
 Exposure of Information Through Directory Listing
CVE-2026-50233 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3124 6.1 MEDIUM
Network
- - Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fail to properly sanitize user input before displaying it in search forms. Attacke… CWE-79
Cross-site Scripting
CVE-2026-50235 2026-06-5 23:59 2026-06-5 Show GitHub Exploit DB Packet Storm
3125 7.8 HIGH
Local
- - A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument deli… CWE-88
Argument Injection
CVE-2026-11332 2026-06-5 23:56 2026-06-5 Show GitHub Exploit DB Packet Storm
3126 - -
- - Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. - CVE-2026-38500 2026-06-5 23:16 2026-06-5 Show GitHub Exploit DB Packet Storm
3127 6.5 MEDIUM
Network
vmware spring_cloud_function Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Functio… CWE-674
 Uncontrolled Recursion
CVE-2026-40989 2026-06-5 22:49 2026-06-2 Show GitHub Exploit DB Packet Storm
3128 6.5 MEDIUM
Network
vmware spring_cloud_function OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring C… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-40990 2026-06-5 22:47 2026-06-2 Show GitHub Exploit DB Packet Storm
3129 7.3 HIGH
Local
aiohttp aiohttp AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most appli… CWE-502
 Deserialization of Untrusted Data
CVE-2026-34993 2026-06-5 22:44 2026-06-3 Show GitHub Exploit DB Packet Storm
3130 7.5 HIGH
Network
aiohttp aiohttp AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin r… CWE-346
 Origin Validation Error
CVE-2026-47265 2026-06-5 22:39 2026-06-3 Show GitHub Exploit DB Packet Storm
3131 7.8 HIGH
Local
- - A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via … CWE-416
 Use After Free
CVE-2026-50261 2026-06-5 22:27 2026-06-5 Show GitHub Exploit DB Packet Storm
3132 5.5 MEDIUM
Local
- - An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding … CWE-125
Out-of-bounds Read
CVE-2026-50262 2026-06-5 22:27 2026-06-5 Show GitHub Exploit DB Packet Storm
3133 7.8 HIGH
Local
- - An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFro… CWE-787
 Out-of-bounds Write
CVE-2026-50264 2026-06-5 22:27 2026-06-5 Show GitHub Exploit DB Packet Storm
3134 3.3 LOW
Local
- - A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV Map Handler. Performing a mani… CWE-404
CWE-407
 Improper Resource Shutdown or Release
 Inefficient Algorithmic Complexity
CVE-2026-11312 2026-06-5 22:27 2026-06-5 Show GitHub Exploit DB Packet Storm
3135 3.6 LOW
Local
- - A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of… CWE-327
CWE-328
 Use of a Broken or Risky Cryptographic Algorithm
 Use of Weak Hash
CVE-2026-11329 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3136 7.2 HIGH
Network
- - A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-10871 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3137 7.2 HIGH
Network
- - A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command inj… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-10872 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3138 7.2 HIGH
Network
- - A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead to os command inject… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-10873 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3139 6.3 MEDIUM
Network
- - A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument soc… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10874 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3140 6.3 MEDIUM
Network
- - A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. The manipulation of the argument… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10875 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3141 7.2 HIGH
Network
- - The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `sa… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-10586 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3142 6.3 MEDIUM
Network
- - A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper… CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-10876 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3143 7.3 HIGH
Network
- - A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of the file /admin/login.php of the component Admin Login… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10877 2026-06-5 22:26 2026-06-5 Show GitHub Exploit DB Packet Storm
3144 6.1 MEDIUM
Network
citeum opencti OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-message observable bo… CWE-79
Cross-site Scripting
CVE-2026-35212 2026-06-5 22:07 2026-06-3 Show GitHub Exploit DB Packet Storm
3145 3.1 LOW
Network
djangoproject django An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requ… CWE-524
 Use of Cache Containing Sensitive Information
CVE-2026-35193 2026-06-5 22:03 2026-06-3 Show GitHub Exploit DB Packet Storm
3146 5.3 MEDIUM
Network
djangoproject django An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header va… CWE-1023
 Incomplete Comparison with Missing Factors
CVE-2026-48587 2026-06-5 22:03 2026-06-3 Show GitHub Exploit DB Packet Storm
3147 4.3 MEDIUM
Network
djangoproject django An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-6873 2026-06-5 21:58 2026-06-3 Show GitHub Exploit DB Packet Storm
3148 3.1 LOW
Network
djangoproject django An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a … CWE-319
Cleartext Transmission of Sensitive Information
CVE-2026-7666 2026-06-5 21:46 2026-06-3 Show GitHub Exploit DB Packet Storm
3149 5.3 MEDIUM
Network
djangoproject django An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitive… CWE-178
 Improper Handling of Case Sensitivity
CVE-2026-8404 2026-06-5 21:38 2026-06-3 Show GitHub Exploit DB Packet Storm
3150 5.3 MEDIUM
Network
exim exim Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client. CWE-839
 Numeric Range Comparison Without Minimum Check
CVE-2026-48840 2026-06-5 20:16 2026-05-30 Show GitHub Exploit DB Packet Storm