31 vulnerabilities across 15 products scored HIGH or above on June 09, 2026.
- CRITICAL: 25
- HIGH: 6
[CRITICAL] ivanti/sentry
1 CVE | CVSS 3.1: 9.9 | AAS 14.2
cpe:2.3:a:ivanti:sentry:*:*:*:*:*:*:*:*(< R10.5.2)cpe:2.3:a:ivanti:sentry:*:*:*:*:*:*:*:*(< R10.6.2)cpe:2.3:a:ivanti:sentry:*:*:*:*:*:*:*:*(< R10.7.1)
Ivanti Sentry before R10.5.2, R10.6.2, and R10.7.1 is vulnerable to a critical authentication bypass (CVE-2026-10523, CVSS 9.9) that allows unauthenticated attackers to create arbitrary administrative accounts and assume full administrative control. Organizations operating affected Sentry instances must apply vendor patches immediately or restrict Sentry network access to trusted networks only. Functional exploits are publicly available.
- CVE-2026-10523 (CVSS 3.1: 9.9)
[CRITICAL] npm/shell-quote
1 CVE | CVSS 4.0: 9.2 | AAS 13.5
cpe:2.3:a:npm:shell-quote:*:*:*:*:*:*:*:*
The npm package shell-quote before patched versions contains a critical command injection vulnerability (CVE-2026-9277, CVSS 9.2) that allows attackers to bypass the quote() function’s escaping by injecting unescaped line terminators in object inputs, enabling arbitrary command execution on systems using this package. Developers and operators using shell-quote must update immediately to available patches. Functional exploits are known to exist in the wild.
- CVE-2026-9277 (CVSS 4.0: 9.2)
[CRITICAL] ivanti/standalone_sentry
1 CVE | CVSS 3.1: 10.0 | AAS 13.3
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*(< 10.5.2)cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*(>= 10.6.0, < 10.6.2)
Ivanti Standalone Sentry before R10.5.2, R10.6.2, and R10.7.1 is vulnerable to a critical OS command injection flaw (CVE-2026-10520, CVSS 10.0) that allows unauthenticated remote attackers to execute arbitrary commands with root privileges. Organizations running affected Standalone Sentry deployments must apply vendor patches immediately or isolate systems pending remediation. This vulnerability is being actively exploited in the wild.
- CVE-2026-10520 (CVSS 3.1: 10.0)
[CRITICAL] fortinet/fortisandbox
1 CVE | CVSS 3.1: 9.8 | AAS 13.1
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*(>= 4.2.0, <= 4.2.8)cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*(>= 4.4.0, < 4.4.9)cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*(>= 5.0.0, < 5.0.6)cpe:2.3:a:fortinet:fortisandbox_cloud:*:*:*:*:*:*:*:*(>= 5.0.4, < 5.0.6)cpe:2.3:a:fortinet:fortisandbox_paas:*:*:*:*:*:*:*:*(>= 5.0.4, < 5.0.6)
Fortinet FortiSandbox 5.0.0-5.0.5, 4.4.0-4.4.8, and 4.2 (all versions), plus Cloud and PaaS 5.0.4-5.0.5, contain a critical OS command injection vulnerability (CVE-2026-25089, CVSS 9.8) that allows unauthenticated attackers to execute arbitrary commands via crafted HTTP requests. Organizations deploying affected FortiSandbox instances must apply vendor patches immediately. Proof-of-concept exploits are publicly available.
- CVE-2026-25089 (CVSS 3.1: 9.8)
[CRITICAL] adobe/coldfusion
6 CVEs | CVSS 3.1: 9.6 | AAS 13.1
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*(< 2025.9)cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*(< 2023.20)
Adobe ColdFusion 2023.19, 2025.8 and earlier contain multiple critical vulnerabilities, including a path traversal flaw, that enable attackers to bypass security features and gain unauthorized access to files and directories (CVSS 9.6 maximum). These vulnerabilities require user interaction such as opening a malicious file. Organizations running affected ColdFusion versions must apply Adobe’s security patches immediately.
- CVE-2026-47932 (CVSS 3.1: 8.8)
- CVE-2026-47928 (CVSS 3.1: 9.6)
- CVE-2026-47930 (CVSS 3.1: 8.1)
- CVE-2026-47929 (CVSS 3.1: 8.4)
- CVE-2026-47960 (CVSS 3.1: 7.4)
- CVE-2026-47931 (CVSS 3.1: 8.4)
[CRITICAL] microsoft/windows
11 CVEs | CVSS 3.1: 9.8 | AAS 13.1
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*(< 10.0.14393.9234)cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*(< 10.0.14393.9234)cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*(< 10.0.17763.8880)cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*(< 10.0.17763.8880)cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*(< 10.0.19044.7417)
Microsoft Windows is affected by 11 critical vulnerabilities including multiple HTTP.sys flaws (CVSS 9.8 maximum) that allow unauthenticated remote code execution over the network. The lead vulnerability involves an integer overflow in HTTP.sys enabling attackers to execute arbitrary code remotely. All Windows systems must apply Microsoft security updates immediately.
- CVE-2026-47291 (CVSS 3.1: 9.8)
- CVE-2026-45657 (CVSS 3.1: 9.8)
- CVE-2026-44815 (CVSS 3.1: 9.8)
- CVE-2026-42904 (CVSS 3.1: 9.6)
- CVE-2026-49160 (CVSS 3.1: 7.5)
- CVE-2026-45602 (CVSS 3.1: 9.1)
- CVE-2026-45648 (CVSS 3.1: 8.8)
- CVE-2026-45586 (CVSS 3.1: 7.8)
- CVE-2026-48574 (CVSS 3.1: 7.8)
- CVE-2026-48583 (CVSS 3.1: 7.8)
- CVE-2026-47653 (CVSS 3.1: 8.8)
[CRITICAL] microsoft/visual_studio_code
2 CVEs | CVSS 3.1: 9.6 | AAS 12.9
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*(>= 1.0.0, < 1.123.2)
Microsoft Visual Studio Code is affected by two critical vulnerabilities, including at least one privilege escalation flaw (CVSS 9.6), that allow attackers to elevate privileges over the network via improper input validation. Developers and organizations using Visual Studio Code must apply vendor updates immediately. These vulnerabilities are currently exploitable.
- CVE-2026-47281 (CVSS 3.1: 9.6)
- CVE-2026-40376 (CVSS 3.1: 7.5)
[CRITICAL] microsoft/exchange_server
1 CVE | CVSS 3.1: 8.8 | AAS 12.6
cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:*(< 15.02.2562.043)
Microsoft Exchange Server contains a critical server-side request forgery vulnerability (CVE-2026-45504, CVSS 8.8) that allows authorized attackers to elevate privileges over the network. Organizations operating Exchange Server must apply vendor security patches immediately to prevent privilege escalation by trusted users. This vulnerability is currently exploitable.
- CVE-2026-45504 (CVSS 3.1: 8.8)
[CRITICAL] sap/sap_netweaver_as_abap_and_abap_platform
1 CVE | CVSS 3.1: 9.8 | AAS 12.1
cpe:2.3:a:sap:sap_netweaver_as_abap_and_abap_platform:*:*:*:*:*:*:*:*
SAP NetWeaver AS ABAP and ABAP Platform contain a critical RFC protocol validation vulnerability (CVE-2026-27671, CVSS 9.8) that allows unauthenticated attackers to send crafted requests leading to memory corruption and compromising the confidentiality, integrity, and availability of affected systems. Organizations running vulnerable SAP deployments must apply vendor security patches immediately. Functional exploits are known to exist.
- CVE-2026-27671 (CVSS 3.1: 9.8)
[HIGH] veeam/backup_and_replication
1 CVE | CVSS 4.0: 9.4 | AAS 11.8
cpe:2.3:a:veeam:backup_and_replication:*:*:*:*:*:*:*:*
Veeam Backup and Replication contains a critical remote code execution vulnerability (CVE-2026-44963, CVSS 9.4) that allows authenticated domain users to execute arbitrary code on the Backup Server. Organizations deploying Veeam Backup and Replication must apply vendor security patches immediately to prevent code execution by internal users. Proof-of-concept code is publicly available.
- CVE-2026-44963 (CVSS 4.0: 9.4)
[HIGH] apptha/pica_photo_gallery
1 CVE | CVSS 4.0: 8.8 | AAS 11.7
cpe:2.3:a:apptha:pica_photo_gallery:*:*:*:*:*:*:*:*(>= 1.0, < 1.1)
The WordPress Plugin PICA Photo Gallery 1.0 contains a critical SQL injection vulnerability (CVE-2017-20247, CVSS 8.8) that allows unauthenticated attackers to execute arbitrary SQL queries via the aid parameter and extract sensitive database information including user credentials. WordPress administrators running this plugin must disable and remove it immediately. Functional exploits are publicly available.
- CVE-2017-20247 (CVSS 4.0: 8.8)
[HIGH] quanticalabs/car_park_booking_system
1 CVE | CVSS 4.0: 8.8 | AAS 11.7
cpe:2.3:a:quanticalabs:car_park_booking_system:*:*:*:*:*:*:*:*(>= 13, < 14)
The WordPress Car Park Booking System Plugin version 13 October 17 contains a critical time-based SQL injection vulnerability (CVE-2017-20243, CVSS 8.8) allowing unauthenticated attackers to manipulate database queries via the space_id parameter and extract sensitive database information. WordPress administrators running this plugin must update or remove it immediately. Functional exploits are publicly available.
- CVE-2017-20243 (CVSS 4.0: 8.8)
[HIGH] missilesilo/kittycatfish
1 CVE | CVSS 4.0: 8.8 | AAS 11.7
cpe:2.3:a:missilesilo:kittycatfish:*:*:*:*:*:*:*:*(>= 2.2, < 2.2)
The WordPress Plugin KittyCatfish 2.2 contains a critical SQL injection vulnerability (CVE-2017-20246, CVSS 8.8) that allows unauthenticated attackers to read database contents by exploiting an unescaped kc_ad parameter via blind SQL injection techniques. WordPress administrators running this plugin must update or remove it immediately. Functional exploits are publicly available.
- CVE-2017-20246 (CVSS 4.0: 8.8)
[HIGH] ollie_armstrong/simply_poll
1 CVE | CVSS 4.0: 8.8 | AAS 11.7
cpe:2.3:a:ollie_armstrong:simply_poll:*:*:*:*:*:*:*:*(>= 1.4.1, < 1.4.2)
The WordPress Plugin Simply Poll 1.4.1 contains a critical SQL injection vulnerability (CVE-2016-20062, CVSS 8.8) that allows unauthenticated attackers to extract database information by injecting SQL code through the pollid POST parameter. WordPress administrators running this plugin must update or remove it immediately to prevent unauthorized database access. Functional exploits are publicly available.
- CVE-2016-20062 (CVSS 4.0: 8.8)
[HIGH] pheditor/pheditor
1 CVE | CVSS 3.1: 9.9 | AAS 11.7
cpe:2.3:a:pheditor:pheditor:*:*:*:*:*:*:*:*
pheditor contains a critical OS command injection vulnerability (CVE-2026-48030, CVSS 9.9) that allows authenticated users to execute arbitrary commands by injecting shell metacharacters into the dir POST parameter, completely bypassing the command whitelist and achieving remote code execution with web server privileges. Organizations deploying pheditor must apply vendor patches immediately. Proof-of-concept code is publicly available.
- CVE-2026-48030 (CVSS 3.1: 9.9)