Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 12,930 CVEs
CVE-2026-55877 MEDIUM - 6.1

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

Vendor: composer
Product: symfony/ux-icons
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55776 MEDIUM - 6.5

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55770 MEDIUM - 6.8

OpenBao: LDAPi ldaputil (wrong escape func)

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55650 MEDIUM - 4.4

Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure

Vendor: npm
Product: @outerbase/studio
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55423 MEDIUM - 6.1

Langflow: Logout button does not clear session

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub

py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()

Vendor: pip
Product: py7zr
Published: Jun 19, 2026
Source: GitHub

py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size

Vendor: pip
Product: py7zr
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55187 MEDIUM - 5.8

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Vendor: go
Product: github.com/axllent/mailpit
Published: Jun 19, 2026
Source: GitHub

Open Redirect Bypass in miniflux-v2

Vendor: go
Product: miniflux.app/v2
Published: Jun 19, 2026
Source: GitHub

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55847 MEDIUM - 6.1

Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering

Vendor: maven
Product: io.qameta.allure:allure-generator
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55846 MEDIUM - 6.2

Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read

Vendor: maven
Product: io.qameta.allure:allure-commandline
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55837 MEDIUM - 6.8

dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens

Vendor: pip
Product: dbt-mcp
Published: Jun 19, 2026
Source: GitHub

go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)

Vendor: go
Product: go.qbee.io/transport
Published: Jun 19, 2026
Source: GitHub

Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass

Vendor: composer
Product: craftcms/commerce
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54911 MEDIUM - 6.5

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

Vendor: pip
Product: ujson
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54779 MEDIUM - 5.9

CoreWCF: SAML token replay protection is inoperative

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54778 MEDIUM - 6.2

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

Vendor: nuget
Product: CoreWCF.UnixDomainSocket
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54777 MEDIUM - 6.5

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

Vendor: nuget
Product: CoreWCF.NetNamedPipe
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54776 MEDIUM - 4.4

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

Vendor: nuget
Product: CoreWCF.UnixDomainSocket
Published: Jun 19, 2026
Source: GitHub