Live feed All digests
2026-06-15 2026-06-16 →

Security Digest — 2026-06-15

2108
Total vulnerabilities
175
Critical
899
High
9
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-10520An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote CRITICAL10.0NVD2026-06-09
CVE-2026-47938Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) CRITICAL10.0NVD2026-06-09
CVE-2026-48303Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerabilCRITICAL10.0NVD2026-06-09
CVE-2026-46695Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers CRITICAL10.0NVD2026-06-10
CVE-2026-49261MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,CRITICAL10.0NVD2026-06-11
CVE-2026-47131vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__CRITICAL10.0NVD2026-06-12
CVE-2026-47137vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) CRITICAL10.0NVD2026-06-12
CVE-2026-47140vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins CRITICAL10.0NVD2026-06-12
CVE-2026-47208vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerabilityCRITICAL10.0NVD2026-06-12
CVE-2026-50086The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing keCRITICAL10.0NVD2026-06-12
CVE-2026-52704Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder aCRITICAL10.0NVD2026-06-15
CVE-2026-40772Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.CRITICAL10.0NVD2026-06-15
CVE-2026-48836Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.CRITICAL10.0NVD2026-06-15
CVE-2026-44748SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtaiCRITICAL9.9NVD2026-06-09
CVE-2026-10523An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allowCRITICAL9.9NVD2026-06-09
CVE-2026-45552Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, thCRITICAL9.9NVD2026-06-10
CVE-2026-45556Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POCRITICAL9.9NVD2026-06-10
CVE-2026-45558Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, thCRITICAL9.9NVD2026-06-10
CVE-2026-50545Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-50563Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-50564Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-50566Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-11839Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows CRITICAL9.9NVD2026-06-11
CVE-2026-47365Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticatedCRITICAL9.9NVD2026-06-12
CVE-2026-47367A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerabilityCRITICAL9.9NVD2026-06-12
CVE-2026-47369A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerabilityCRITICAL9.9NVD2026-06-12
CVE-2026-47370A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerabilityCRITICAL9.9NVD2026-06-12
CVE-2026-46716Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to beCRITICAL9.9NVD2026-06-12
CVE-2026-39591Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.CRITICAL9.9NVD2026-06-15
CVE-2026-49766Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.CRITICAL9.9NVD2026-06-15
CVE-2026-27671Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP CRITICAL9.8NVD2026-06-09
CVE-2026-5067A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendiCRITICAL9.8NVD2026-06-09
CVE-2026-9698DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseCRITICAL9.8NVD2026-06-09
CVE-2026-46325In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizCRITICAL9.8NVD2026-06-09
CVE-2026-7486Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software InCRITICAL9.8NVD2026-06-09
CVE-2026-25089A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FCRITICAL9.8NVD2026-06-09
CVE-2026-8025Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information TCRITICAL9.8NVD2026-06-09
CVE-2026-26142Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.CRITICAL9.8NVD2026-06-09
CVE-2026-38615DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.CRITICAL9.8NVD2026-06-09
CVE-2026-44815Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.CRITICAL9.8NVD2026-06-09