| | CVE-2026-47638 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47639 | Microsoft | medium | 5.4 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47640 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47641 | Microsoft | medium | 4.6 | 0.5%
| | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform sp… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-47643 | Microsoft | critical | 9.8 | 0.8%
| | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-48560 | Microsoft | medium | 5.4 | 0.9%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to pe… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-48562 | Microsoft | medium | 4.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-48565 | Microsoft | high | 7.8 | 0.4%
| | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privilege… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-48569 | Microsoft | high | 7.1 | 0.4%
| | Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-49161 | Microsoft | high | 7.8 | 0.2%
| | Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security f… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-50511 | Microsoft | high | 7.8 | 0.3%
| | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an aut… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-50512 | Microsoft | high | 7.8 | 0.3%
| | Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker t… | Jun 9, 2026 | Jul 23, 2026 |
| | CVE-2026-44963 | Veeam | critical | 9.4 | — | | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain… | Jun 9, 2026 | Jun 10, 2026 |
| | CVE-2026-41731 | Apache | high | 8.1 | 0.5%
| | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust… | Jun 9, 2026 | Aug 5, 2026 |
| | CVE-2026-11837 | Red Hat | high | 7.3 | 0.0%
| | A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The… | Jun 10, 2026 | Jun 10, 2026 |
| | CVE-2026-40988 | VMware | high | 7.5 | 0.3%
| | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Lo… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-40993 | VMware | high | 7.3 | 0.2%
| | An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataReposi… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41003 | VMware | high | 7.6 | 0.2%
| | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code o… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41008 | VMware | medium | 6.1 | 0.2%
| | Spring Security Authorization Server's authorization endpoint performs insufficient validation of th… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41694 | VMware | low | 3.7 | 0.1%
| | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and Lo… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41696 | VMware | medium | 5.9 | 0.3%
| | Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding … | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41706 | VMware | medium | 6.1 | 0.2%
| | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication reque… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41714 | VMware | medium | 4.0 | 0.1%
| | Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41717 | VMware | high | 8.1 | 0.3%
| | Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability.… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41726 | VMware | medium | 6.5 | 0.3%
| | When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap withou… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41727 | VMware | medium | 6.5 | 0.2%
| | Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header value… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41728 | VMware | high | 7.5 | 0.3%
| | Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41729 | VMware | high | 8.1 | 0.4%
| | Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when proces… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41730 | VMware | medium | 5.3 | 0.2%
| | Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentia… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41732 | VMware | high | 8.1 | 0.3%
| | JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning t… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-41837 | VMware | medium | 5.3 | 0.2%
| | Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-param… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-47838 | VMware | medium | 6.8 | 0.1%
| | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN val… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-25700 | Apache | medium | — | 0.4%
| | Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affect… | Jun 10, 2026 | Jun 19, 2026 |
| | CVE-2026-20251 | Splunk | high | 8.8 | 0.6%
| | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versio… | Jun 10, 2026 | Jun 15, 2026 |
| | CVE-2026-20252 | Splunk | high | 7.6 | 0.3%
| | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve… | Jun 10, 2026 | Jun 15, 2026 |
| | CVE-2026-20253 | Splunk | critical | 9.8 | 88.2%
| ⚠ KEV | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated use… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-20254 | Splunk | medium | 5.7 | 0.3%
| | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve… | Jun 10, 2026 | Jun 15, 2026 |
| | CVE-2026-20255 | Splunk | medium | 5.7 | 0.2%
| | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve… | Jun 10, 2026 | Jun 15, 2026 |
| | CVE-2026-20256 | Splunk | medium | 5.7 | 0.3%
| | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve… | Jun 10, 2026 | Jun 15, 2026 |
| | CVE-2026-20257 | Splunk | medium | 5.7 | 0.2%
| | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve… | Jun 10, 2026 | Jun 15, 2026 |
| | CVE-2026-20258 | Splunk | high | 7.1 | 0.2%
| | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve… | Jun 10, 2026 | Jun 15, 2026 |
| | CVE-2026-20259 | Splunk | medium | 5.5 | 0.0%
| | In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4… | Jun 10, 2026 | Jun 12, 2026 |
| | CVE-2026-6893 | Red Hat | high | 8.8 | — | | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability… | Jun 10, 2026 | Jun 10, 2026 |
| | CVE-2026-10143 | Red Hat | high | 7.5 | — | | A flaw was found in kafka-python. A malicious or machine-in-the-middle broker could exploit a denial… | Jun 10, 2026 | Jun 10, 2026 |
| | CVE-2026-47342 | Apache | high | 8.8 | 0.4%
| | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-50223 | Apache | high | 8.8 | 0.7%
| | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low… | Jun 10, 2026 | Jul 23, 2026 |
| | CVE-2026-40987 | VMware | high | 7.1 | 0.2%
| | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client file… | Jun 11, 2026 | Sep 4, 2026 |
| | CVE-2026-40992 | VMware | medium | 5.0 | 0.1%
| | Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set t… | Jun 11, 2026 | Sep 4, 2026 |
| | CVE-2026-41001 | VMware | medium | 5.3 | 0.1%
| | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis… | Jun 11, 2026 | Sep 4, 2026 |
| | CVE-2026-41699 | VMware | high | 8.1 | 0.4%
| | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated G… | Jun 11, 2026 | Jul 23, 2026 |