The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-20256 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk rol... read CVE-2026-20256
Published: June 10, 2026; 2:16:41 PM -0400V3.1: 5.7 MEDIUM
-
CVE-2025-24165 - A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
Published: June 11, 2026; 3:16:26 PM -0400 -
CVE-2025-43278 - This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
Published: June 11, 2026; 3:16:33 PM -0400 -
CVE-2025-46313 - A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Published: June 11, 2026; 3:16:34 PM -0400 -
CVE-2026-47631 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Published: June 09, 2026; 1:17:35 PM -0400V3.1: 5.4 MEDIUM
-
CVE-2026-47292 - Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Published: June 09, 2026; 1:17:34 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-47287 - Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Published: June 09, 2026; 1:17:34 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-47284 - Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: June 09, 2026; 1:17:34 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-47281 - Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Published: June 09, 2026; 1:17:33 PM -0400V3.1: 9.6 CRITICAL
-
CVE-2026-45650 - User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
Published: June 09, 2026; 1:17:32 PM -0400V3.1: 4.3 MEDIUM
-
CVE-2024-39011 - Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.
Published: July 30, 2024; 4:15:04 PM -0400V3.1: 9.8 CRITICAL
-
CVE-2026-20257 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk rol... read CVE-2026-20257
Published: June 10, 2026; 2:16:41 PM -0400V3.1: 5.7 MEDIUM
-
CVE-2026-46476 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2.
Published: June 08, 2026; 12:16:41 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-20258 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk rol... read CVE-2026-20258
Published: June 10, 2026; 2:16:41 PM -0400V3.1: 5.4 MEDIUM
-
CVE-2026-46477 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover. This issue has been patched in version 3.1.2.
Published: June 08, 2026; 12:16:42 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-46478 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2.
Published: June 08, 2026; 12:16:42 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-46479 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2.
Published: June 08, 2026; 12:16:42 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-50261 - A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those ... read CVE-2026-50261
Published: June 05, 2026; 8:16:39 AM -0400V3.1: 7.8 HIGH
-
CVE-2026-50262 - An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information discl... read CVE-2026-50262
Published: June 05, 2026; 8:16:39 AM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-52858 - Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python inter... read CVE-2026-52858
Published: June 11, 2026; 3:16:47 PM -0400V3.1: 7.8 HIGH