| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-10520 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote | CRITICAL | 10.0 | NVD | 2026-06-09 |
| CVE-2026-47938 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) | CRITICAL | 10.0 | NVD | 2026-06-09 |
| CVE-2026-48303 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerabil | CRITICAL | 10.0 | NVD | 2026-06-09 |
| CVE-2026-46695 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers | CRITICAL | 10.0 | NVD | 2026-06-10 |
| CVE-2026-49261 | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, | CRITICAL | 10.0 | NVD | 2026-06-11 |
| CVE-2026-47131 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__ | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-47137 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-47140 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-47208 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-50086 | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-52704 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a | CRITICAL | 10.0 | NVD | 2026-06-15 |
| CVE-2026-40772 | Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions. | CRITICAL | 10.0 | NVD | 2026-06-15 |
| CVE-2026-48836 | Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | CRITICAL | 10.0 | NVD | 2026-06-15 |
| CVE-2026-44748 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai | CRITICAL | 9.9 | NVD | 2026-06-09 |
| CVE-2026-10523 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow | CRITICAL | 9.9 | NVD | 2026-06-09 |
| CVE-2026-45552 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-45556 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-45558 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50545 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50563 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50564 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50566 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-11839 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows | CRITICAL | 9.9 | NVD | 2026-06-11 |
| CVE-2026-47365 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-47367 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-47369 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-47370 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-46716 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-39591 | Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions. | CRITICAL | 9.9 | NVD | 2026-06-15 |
| CVE-2026-49766 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. | CRITICAL | 9.9 | NVD | 2026-06-15 |
| CVE-2026-27671 | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-5067 | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-9698 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when Raise | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-46325 | In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix iova-to-va conversion for MR page siz | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-7486 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software In | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-25089 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-8025 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-26142 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-38615 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. | CRITICAL | 9.8 | NVD | 2026-06-09 |
| CVE-2026-44815 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | CRITICAL | 9.8 | NVD | 2026-06-09 |