Total CVEs

150,703

Critical Severity

4,956

High Severity

17,517

Last 7 Days

2,047
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,721 - 1,740 of 47,108 CVEs
CVE-2026-55985 MEDIUM - 4.3

The web management interface inΒ  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to...

Vendor: Tycon Systems
Product: TPDIN-Monitor-WEB2
Published: Jul 24, 2026
Source: NVD
CVE-2025-71408 HIGH - 7.8

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line...

Vendor: ntlk
Product: ntlk
Published: Jul 24, 2026
Source: NVD
CVE-2026-62323 MEDIUM - 6.3

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62379 CRITICAL - 9.8

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jul 24, 2026
Source: GitHub
CVE-2026-62280 MEDIUM - 6.1

OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jul 24, 2026
Source: GitHub

OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass

Vendor: maven
Product: org.openidentityplatform.openam:openam-auth-webauthn
Published: Jul 24, 2026
Source: GitHub
CVE-2026-57497 MEDIUM - 5.3

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

Vendor: go
Product: github.com/quic-go/webtransport-go
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55502 HIGH - 7.1

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55499 MEDIUM - 4.3

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55497 MEDIUM - 6.5

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55496 MEDIUM - 4.3

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-55495 MEDIUM - 4.3

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Jul 24, 2026
Source: GitHub
CVE-2026-66041 HIGH - 8.8

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66040 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD ...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66039 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_pac...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66038 MEDIUM - 6.5

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() functi...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66037 MEDIUM - 6.5

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_ob...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-66036 HIGH - 8.8

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -re...

Vendor: FFmpeg
Product: FFmpeg
Published: Jul 24, 2026
Source: NVD
CVE-2026-62835 CRITICAL - 9.3

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: azure_portal
Published: Jul 24, 2026
Source: NVD
CVE-2026-57531 MEDIUM - 5.4

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs h...

Vendor: Milkdown
Product: milkdown
Published: Jul 24, 2026
Source: NVD