Total CVEs

150,882

Critical Severity

5,031

High Severity

17,660

Last 7 Days

2,100
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,141 - 2,160 of 47,287 CVEs
CVE-2026-65706 HIGH - 7.8

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0&#...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 23, 2026
Source: NVD
CVE-2026-65705 HIGH - 7.8

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates th...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 23, 2026
Source: NVD
CVE-2026-65704 HIGH - 7.8

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative si...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 23, 2026
Source: NVD
CVE-2026-65703 HIGH - 7.8

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the exi...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 23, 2026
Source: NVD
CVE-2026-64785 MEDIUM - 5.3

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 v...

Vendor: Apple
Product: swift-nio-http2
Published: Jul 23, 2026
Source: NVD
CVE-2026-63359 CRITICAL - 9.8

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other inform...

Vendor: Appriss Insights
Product: Victim Information Notification Exchange (VINE)
Published: Jul 23, 2026
Source: NVD
CVE-2026-60122 HIGH - 7.8

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized...

Vendor: gpsd
Product: gpsd
Published: Jul 23, 2026
Source: NVD
CVE-2026-25800 HIGH - 7.5

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragmen...

Vendor: quinn-rs
Product: quinn
Published: Jul 23, 2026
Source: NVD
CVE-2026-15212 HIGH - 8.8

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from t...

Vendor: wpo365
Product: WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
Published: Jul 23, 2026
Source: NVD
CVE-2026-12353 MEDIUM - 5.3

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

Vendor: Red Hat
Product: Red Hat Certificate System 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 23, 2026
Source: NVD

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.

Vendor: npm
Product: react-router
Published: Jul 23, 2026
Source: GitHub
CVE-2026-53668 MEDIUM - 6.9

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has bee...

Vendor: npm
Product: react-router-dom
Published: Jul 23, 2026
Source: GitHub
CVE-2026-53667 MEDIUM - 6.9

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This...

Vendor: npm
Product: react-router
Published: Jul 23, 2026
Source: GitHub
CVE-2026-53666 MEDIUM - 6.1

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the...

Vendor: npm
Product: react-router
Published: Jul 23, 2026
Source: GitHub
CVE-2026-47219 HIGH - 7.5

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method ...

Vendor: npm
Product: find-my-way
Published: Jul 23, 2026
Source: GitHub
CVE-2026-65010 MEDIUM - 6.6

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in ...

Vendor: huggingface
Product: datasets
Published: Jul 23, 2026
Source: NVD
CVE-2026-63765 HIGH - 8.2

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, th...

Vendor: chatwoot
Product: chatwoot
Published: Jul 23, 2026
Source: NVD
CVE-2026-16756 HIGH - 7.5

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhaust...

Vendor: AWS
Product: aws-smithy-http-server
Published: Jul 23, 2026
Source: NVD

A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.

Vendor: Kubernetes
Product: kubernetes-client/java
Published: Jul 23, 2026
Source: NVD
CVE-2026-6516 CRITICAL - 10.0

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Published: Jul 23, 2026
Source: NVD