Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,288
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 11,967 CVEs
CVE-2026-55470 HIGH - 7.5

HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55760 HIGH - 7.5

handlebars.java FileTemplateLoader Path Traversal

Vendor: maven
Product: com.github.jknack:handlebars
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55409 HIGH - 7.6

Filament: Disabled RichEditor field state can be used for XSS

Vendor: composer
Product: filament/forms
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55405 HIGH - 7.6

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

Vendor: maven
Product: dev.langchain4j:langchain4j-mariadb
Published: Jun 17, 2026
Source: GitHub
CVE-2026-28737 HIGH - 8.7

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-24791 HIGH - 8.1

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-22555 HIGH - 8.1

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54018 HIGH - 7.7

Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54017 HIGH - 7.7

Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54013 HIGH - 7.6

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54012 HIGH - 7.1

Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54011 HIGH - 8.7

Open WebUI: Stored XSS in Mermaid Markdown Preview

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54010 HIGH - 8.3

Open WebUI: Forged chat-file link allows cross-user file read and deletion

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54008 HIGH - 8.5

Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub

Open WebUI: Cross-origin postMessage confirmation bypass via action:submit

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54328 HIGH - 7.3

Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts

Vendor: npm
Product: @earendil-works/pi-coding-agent
Published: Jun 17, 2026
Source: GitHub
CVE-2026-26231 HIGH - 8.5

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-28699 HIGH - 8.1

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52797 HIGH - 8.5

Gogs: Overwriting critical files results in a denial of service

Vendor: go
Product: gogs.io/gogs
Published: Jun 16, 2026
Source: GitHub
CVE-2026-28744 HIGH - 8.1

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub