Live feed All digests
← 2026-06-15 2026-06-16 2026-06-17 →

Security Digest — 2026-06-16

2150
Total vulnerabilities
184
Critical
766
High
8
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-46695Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers CRITICAL10.0NVD2026-06-10
CVE-2026-49261MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,CRITICAL10.0NVD2026-06-11
CVE-2026-47131vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__CRITICAL10.0NVD2026-06-12
CVE-2026-47137vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) CRITICAL10.0NVD2026-06-12
CVE-2026-47140vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins CRITICAL10.0NVD2026-06-12
CVE-2026-47208vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerabilityCRITICAL10.0NVD2026-06-12
CVE-2026-50086The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing keCRITICAL10.0NVD2026-06-12
CVE-2026-52704Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder aCRITICAL10.0NVD2026-06-15
CVE-2026-40772Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.CRITICAL10.0NVD2026-06-15
CVE-2026-48836Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.CRITICAL10.0NVD2026-06-15
CVE-2026-45552Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, thCRITICAL9.9NVD2026-06-10
CVE-2026-45556Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POCRITICAL9.9NVD2026-06-10
CVE-2026-45558Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, thCRITICAL9.9NVD2026-06-10
CVE-2026-50545Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-50563Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-50564Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-50566Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.9NVD2026-06-10
CVE-2026-11839Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows CRITICAL9.9NVD2026-06-11
CVE-2026-47365Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticatedCRITICAL9.9NVD2026-06-12
CVE-2026-47367A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerabilityCRITICAL9.9NVD2026-06-12
CVE-2026-47369A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerabilityCRITICAL9.9NVD2026-06-12
CVE-2026-47370A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerabilityCRITICAL9.9NVD2026-06-12
CVE-2026-46716Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to beCRITICAL9.9NVD2026-06-12
CVE-2026-39591Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.CRITICAL9.9NVD2026-06-15
CVE-2026-49766Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.CRITICAL9.9NVD2026-06-15
CVE-2026-49774Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code IncCRITICAL9.9NVD2026-06-16
CVE-2026-40750Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web ShCRITICAL9.9NVD2026-06-16
CVE-2025-6254The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8CRITICAL9.8NVD2026-06-10
CVE-2026-20253In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or trCRITICAL9.8NVD2026-06-10
CVE-2026-46614Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applicCRITICAL9.8NVD2026-06-10
CVE-2026-35273Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment ManaCRITICAL9.8NVD2026-06-11
CVE-2026-11561Improper neutralization of special elements used in an expression language statement ('expression language injection') vCRITICAL9.8NVD2026-06-11
CVE-2026-7852Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code IncluCRITICAL9.8NVD2026-06-11
CVE-2026-38581SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitraCRITICAL9.8NVD2026-06-11
CVE-2026-49060Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issCRITICAL9.8NVD2026-06-11
CVE-2026-42846ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature CRITICAL9.8NVD2026-06-11
CVE-2026-45060ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php enCRITICAL9.8NVD2026-06-11
CVE-2026-48611Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or CRITICAL9.8NVD2026-06-12
CVE-2026-49875Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessaryCRITICAL9.8NVD2026-06-12
CVE-2026-50628A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allCRITICAL9.8NVD2026-06-12