| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-46695 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers | CRITICAL | 10.0 | NVD | 2026-06-10 |
| CVE-2026-49261 | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, | CRITICAL | 10.0 | NVD | 2026-06-11 |
| CVE-2026-47131 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__ | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-47137 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-47140 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-47208 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-50086 | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke | CRITICAL | 10.0 | NVD | 2026-06-12 |
| CVE-2026-52704 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a | CRITICAL | 10.0 | NVD | 2026-06-15 |
| CVE-2026-40772 | Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions. | CRITICAL | 10.0 | NVD | 2026-06-15 |
| CVE-2026-48836 | Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | CRITICAL | 10.0 | NVD | 2026-06-15 |
| CVE-2026-45552 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-45556 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-45558 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50545 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50563 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50564 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-50566 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.9 | NVD | 2026-06-10 |
| CVE-2026-11839 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows | CRITICAL | 9.9 | NVD | 2026-06-11 |
| CVE-2026-47365 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-47367 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-47369 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-47370 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-46716 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be | CRITICAL | 9.9 | NVD | 2026-06-12 |
| CVE-2026-39591 | Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions. | CRITICAL | 9.9 | NVD | 2026-06-15 |
| CVE-2026-49766 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. | CRITICAL | 9.9 | NVD | 2026-06-15 |
| CVE-2026-49774 | Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inc | CRITICAL | 9.9 | NVD | 2026-06-16 |
| CVE-2026-40750 | Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Sh | CRITICAL | 9.9 | NVD | 2026-06-16 |
| CVE-2025-6254 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8 | CRITICAL | 9.8 | NVD | 2026-06-10 |
| CVE-2026-20253 | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or tr | CRITICAL | 9.8 | NVD | 2026-06-10 |
| CVE-2026-46614 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic | CRITICAL | 9.8 | NVD | 2026-06-10 |
| CVE-2026-35273 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana | CRITICAL | 9.8 | NVD | 2026-06-11 |
| CVE-2026-11561 | Improper neutralization of special elements used in an expression language statement ('expression language injection') v | CRITICAL | 9.8 | NVD | 2026-06-11 |
| CVE-2026-7852 | Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclu | CRITICAL | 9.8 | NVD | 2026-06-11 |
| CVE-2026-38581 | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitra | CRITICAL | 9.8 | NVD | 2026-06-11 |
| CVE-2026-49060 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation.
This iss | CRITICAL | 9.8 | NVD | 2026-06-11 |
| CVE-2026-42846 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature | CRITICAL | 9.8 | NVD | 2026-06-11 |
| CVE-2026-45060 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php en | CRITICAL | 9.8 | NVD | 2026-06-11 |
| CVE-2026-48611 | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or | CRITICAL | 9.8 | NVD | 2026-06-12 |
| CVE-2026-49875 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary | CRITICAL | 9.8 | NVD | 2026-06-12 |
| CVE-2026-50628 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all | CRITICAL | 9.8 | NVD | 2026-06-12 |