2026-06-04 to 2026-06-18

Weekly Security Digest

Comprehensive summary of vulnerabilities and security news from the past 14 days.

3139
New CVEs
305
Critical
1251
High Severity
11
Added to KEV

Severity Distribution

CRITICAL 305 (10%)
HIGH 1251 (40%)
MEDIUM 1123 (36%)
LOW 78 (2%)

Quick Stats

Total CVEs Published 3139
CISA KEV Additions 11
Security News Articles 160
News Sources 4

🎯 High-Risk Vulnerabilities

Ranked by EPSS Score
CVE-2014-0160 HIGH ⚠️ KEV

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process m...

7.5
CVSS
100.0%
EPSS
CVE-2014-6271 CRITICAL ⚠️ KEV

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as...

9.8
CVSS
100.0%
EPSS
CVE-2015-1635 CRITICAL ⚠️ KEV

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests...

9.8
CVSS
100.0%
EPSS
CVE-2017-5638 CRITICAL ⚠️ KEV

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows re...

9.8
CVSS
100.0%
EPSS
CVE-2017-9841 CRITICAL ⚠️ KEV

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by a...

9.8
CVSS
100.0%
EPSS
CVE-2019-11510 CRITICAL ⚠️ KEV

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary ...

10.0
CVSS
100.0%
EPSS
CVE-2019-0708 CRITICAL ⚠️ KEV

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially...

9.8
CVSS
100.0%
EPSS
CVE-2018-13379 CRITICAL ⚠️ KEV

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to ...

9.1
CVSS
100.0%
EPSS
CVE-2019-19781 CRITICAL ⚠️ KEV

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal....

9.8
CVSS
100.0%
EPSS
CVE-2020-5902 CRITICAL ⚠️ KEV

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility,...

9.8
CVSS
100.0%
EPSS

Last data sync: 2026-06-18T15:30:38.169810

Generated by InfoSecCenter Security Intelligence Hub