Total CVEs

149,824

Critical Severity

4,834

High Severity

17,268

Last 7 Days

2,960
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 46,229 CVEs
CVE-2026-61609 HIGH - 7.5

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

Vendor: composer
Product: pterodactyl/panel
Published: Jul 28, 2026
Source: GitHub
CVE-2026-54545 HIGH - 7.1

@wakaru/cli arbitrary file write during bundle unpack

Vendor: npm
Product: @wakaru/cli
Published: Jul 28, 2026
Source: GitHub
CVE-2026-47427 HIGH - 7.5

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

Vendor: go
Product: github.com/github/github-mcp-server
Published: Jul 28, 2026
Source: GitHub
CVE-2026-45293 HIGH - 8.6

WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability

Vendor: composer
Product: wp-coding-standards/wpcs
Published: Jul 28, 2026
Source: GitHub
CVE-2026-43910 HIGH - 8.2

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

Vendor: maven
Product: io.appium:java-client
Published: Jul 28, 2026
Source: GitHub

Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able to supply crafted graph data could set an image path to a malicious URI. When a victim rendered the affected graph, the browser could resolve the ...

Vendor: pivotick
Product: pivotick
Published: Jul 28, 2026
Source: NVD

Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-layout and cycle-detection components. Node identifiers matching properties inherited from Object.prototype, such as constructor, toString, or __proto__, were not handled as ordin...

Vendor: pivotick
Product: pivotick
Published: Jul 28, 2026
Source: NVD

Pivotickโ€™s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpolating it into both the data-node-name attribute and the body of a generated <span> element. Because the node-reference tokenizer rejected only square brackets, a crafted nod...

Vendor: pivotick
Product: pivotick
Published: Jul 28, 2026
Source: NVD

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queu...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
Published: Jul 28, 2026
Source: NVD

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapid...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All
Published: Jul 28, 2026
Source: NVD
CVE-2026-7187 HIGH - 8.8

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported.

Published: Jul 28, 2026
Source: NVD

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursively traversed graph edges, while the JSON viewer recursively processed each level of a nodeโ€™s data structure. A specially crafted graph containing an e...

Vendor: Pivotick
Product: Pivotick
Published: Jul 28, 2026
Source: NVD

Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data were interpolated directly into HTML used to construct the modal headers. An attacker able to supply or modify graph data could insert a malicious HTM...

Vendor: Pivotick
Product: Pivotick
Published: Jul 28, 2026
Source: NVD

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document. When rendering a graph node, the vulnerable code assigns the SVG icon markup directly to the innerHTML property of a live SVG element. An attacker ab...

Vendor: pivotick
Product: pivotick
Published: Jul 28, 2026
Source: NVD

Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially crafted ZIP, gzip, or zlib-compressed capture containing data that expands to a very large size during processing. Because the application decompresse...

Vendor: lookyloo
Product: lookyloo
Published: Jul 28, 2026
Source: NVD

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.

Vendor: joomdle.com
Product: Joomdle component for Joomla
Published: Jul 28, 2026
Source: NVD

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.

Vendor: joomdle.com
Product: Joomdle component for Joomla
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came the requirement to be able to switch between versions. Switching from v1 to v2 reduces the number of valid grant references,...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came the requirement to be able to switch between versions. Switching from v1 to v2 reduces the number of valid grant references,...

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD

A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. This can cause corruption of memory management state in Xen.

Vendor: Xen
Product: Xen
Published: Jul 28, 2026
Source: NVD