U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-20256 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk rol... read CVE-2026-20256
    Published: June 10, 2026; 2:16:41 PM -0400

    V3.1: 5.7 MEDIUM

  • CVE-2025-24165 - A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
    Published: June 11, 2026; 3:16:26 PM -0400

  • CVE-2025-43278 - This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
    Published: June 11, 2026; 3:16:33 PM -0400

  • CVE-2025-46313 - A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
    Published: June 11, 2026; 3:16:34 PM -0400

  • CVE-2026-47631 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
    Published: June 09, 2026; 1:17:35 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2026-47292 - Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
    Published: June 09, 2026; 1:17:34 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-47287 - Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
    Published: June 09, 2026; 1:17:34 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-47284 - Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
    Published: June 09, 2026; 1:17:34 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-47281 - Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
    Published: June 09, 2026; 1:17:33 PM -0400

    V3.1: 9.6 CRITICAL

  • CVE-2026-45650 - User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
    Published: June 09, 2026; 1:17:32 PM -0400

    V3.1: 4.3 MEDIUM

  • CVE-2024-39011 - Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.
    Published: July 30, 2024; 4:15:04 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-20257 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk rol... read CVE-2026-20257
    Published: June 10, 2026; 2:16:41 PM -0400

    V3.1: 5.7 MEDIUM

  • CVE-2026-46476 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2.
    Published: June 08, 2026; 12:16:41 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-20258 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk rol... read CVE-2026-20258
    Published: June 10, 2026; 2:16:41 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2026-46477 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover. This issue has been patched in version 3.1.2.
    Published: June 08, 2026; 12:16:42 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-46478 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2.
    Published: June 08, 2026; 12:16:42 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-46479 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2.
    Published: June 08, 2026; 12:16:42 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-50261 - A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those ... read CVE-2026-50261
    Published: June 05, 2026; 8:16:39 AM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-50262 - An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information discl... read CVE-2026-50262
    Published: June 05, 2026; 8:16:39 AM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-52858 - Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python inter... read CVE-2026-52858
    Published: June 11, 2026; 3:16:47 PM -0400

    V3.1: 7.8 HIGH

Created September 20, 2022 , Updated August 27, 2024