feed · advisories

Security Advisories

Recent CVEs from the NVD, ranked by CVSS score. High and critical severity tracked by default.

— · — · CVSS 10 · Jun 9

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does…

NVD detail →
— · — · CVSS 9.9 · Jun 11

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

NVD detail →
— · — · CVSS 9.9 · Jun 9

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of…

NVD detail →
flowiseai · flowise · CVSS 9.9 · Jun 8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit…

NVD detail →
— · — · CVSS 9.8 · Jun 12

The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.

NVD detail →
CVE-2026-7852 CRITICAL
— · — · CVSS 9.8 · Jun 11

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.

NVD detail →
— · — · CVSS 9.8 · Jun 11

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue…

NVD detail →
— · — · CVSS 9.8 · Jun 10

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service…

NVD detail →
CVE-2025-6254 CRITICAL
— · — · CVSS 9.8 · Jun 10

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can…

NVD detail →
— · — · CVSS 9.8 · Jun 9

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

NVD detail →
microsoft · windows 10 1607 · CVSS 9.8 · Jun 9

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

NVD detail →
microsoft · windows 11 23h2 · CVSS 9.8 · Jun 9

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

NVD detail →
microsoft · windows 10 1607 · CVSS 9.8 · Jun 9

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

NVD detail →
— · — · CVSS 9.8 · Jun 9

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

NVD detail →
CVE-2026-8025 CRITICAL
— · — · CVSS 9.8 · Jun 9

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026. NOTE: The vendor…

NVD detail →
CVE-2026-7486 CRITICAL
— · — · CVSS 9.8 · Jun 9

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection. This issue affects E-İmar: from 2.10.1.0 before 3.0.2.

NVD detail →
— · — · CVSS 9.8 · Jun 9

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers…

NVD detail →
CVE-2026-9698 CRITICAL
perl · dbi · CVSS 9.8 · Jun 9

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can…

NVD detail →
— · — · CVSS 9.8 · Jun 8

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines…

NVD detail →
— · — · CVSS 9.8 · Jun 8

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers…

NVD detail →