Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,874
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 13,261 CVEs
CVE-2026-55832 MEDIUM - 6.1

tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

Vendor: rust
Product: tract-onnx
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55767 MEDIUM - 5.8

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

Vendor: composer
Product: guzzlehttp/guzzle
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55766 MEDIUM - 4.8

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

Vendor: composer
Product: guzzlehttp/psr7
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55689 MEDIUM - 6.8

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

Vendor: go
Product: github.com/openfga/openfga
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55568 MEDIUM - 5.9

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

Vendor: composer
Product: guzzlehttp/guzzle
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55414 MEDIUM - 5.3

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

Vendor: maven
Product: nl.nl-portal:form
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55375 MEDIUM - 5.3

canto-saas-api: OAuth credentials exposed in URL query string and exception messages

Vendor: composer
Product: jleehr/canto-saas-api
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55374 MEDIUM - 4.8

canto-saas-api: Authenticated API requests can be redirected via unencoded path variables

Vendor: composer
Product: jleehr/canto-saas-api
Published: Jun 19, 2026
Source: GitHub
CVE-2026-52866 MEDIUM - 6.5

An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

Vendor: Apollo Pharmacy
Product: Blood Glucose Monitoring System (Model No. APG-01 BT)
Published: Jun 19, 2026
Source: NVD
CVE-2026-50034 MEDIUM - 6.5

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

Vendor: Apollo Pharmacy
Product: Blood Glucose Monitoring System (Model No. APG-01 BT)
Published: Jun 19, 2026
Source: NVD
CVE-2026-12050 MEDIUM - 4.3

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a bound parameter, allowing an authenticated pgAdmin u...

Vendor: pgadmin.org
Product: pgAdmin 4
Published: Jun 19, 2026
Source: NVD
CVE-2026-12049 MEDIUM - 4.3

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated victim who clicked /mfa/validate?next=<extern...

Vendor: pgadmin.org
Product: pgAdmin 4
Published: Jun 19, 2026
Source: NVD
CVE-2026-56077 MEDIUM - 6.5

PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows attackers to access sensitive data by registering agents with duplicate IDs. Attackers can exploit the lack of agent ID uniqueness enforcement to share ledger instances and expose ...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-56074 MEDIUM - 5.5

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentia...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-49205 MEDIUM - 6.5

phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4 other write endpo...

Vendor: thorsten
Product: phpMyFAQ
Published: Jun 18, 2026
Source: NVD
CVE-2026-22674 MEDIUM - 4.8

Hashgraph Guardian through 3.5.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers...

Vendor: hashgraph
Product: guardian
Published: Jun 18, 2026
Source: NVD
CVE-2026-44663 MEDIUM - 6.1

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl() in src/lib/OpenEXRCore/internal_ht.cpp leads to a heap-buffer overflow when decoding a crafted HTJ2K...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Jun 18, 2026
Source: NVD
CVE-2025-15661 MEDIUM - 6.5

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME respons...

Vendor: libssh2
Product: libssh2
Published: Jun 18, 2026
Source: NVD
CVE-2026-55591 MEDIUM - 5.8

Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints

Vendor: npm
Product: signalk-server
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56099 MEDIUM - 5.3

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

Vendor: openbsd
Product: src
Published: Jun 18, 2026
Source: NVD