Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,624
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 35,133 CVEs
CVE-2026-52801 HIGH - 8.1

Gogs has the ability to import local repositories via Mirror Settings

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52800 HIGH - 8.8

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52799 HIGH - 7.5

Gogs Missing Authorization in Attachment Download

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-52798 HIGH - 8.9

Gogs has Stored XSS in `.ipynb` Preview

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub

Gogs has DoS in rendering issue index pattern

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-50179 MEDIUM - 4.2

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

Vendor: npm
Product: @actual-app/web
Published: Jun 22, 2026
Source: GitHub
CVE-2026-54353 HIGH - 8.5

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

Vendor: npm
Product: @budibase/backend-core
Published: Jun 22, 2026
Source: GitHub
CVE-2026-54352 CRITICAL - 9.6

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-54351 HIGH - 8.2

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-49229 HIGH - 8.3

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

Vendor: npm
Product: @actual-app/sync-server
Published: Jun 22, 2026
Source: GitHub

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-50136 HIGH - 7.4

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-50132 HIGH - 7.3

Budibase has an Account Impersonation Issue โ€” Chat Identity Link Hijacking via Missing Consent & CSRF

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-48487 MEDIUM - 6.5

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

Vendor: pip
Product: zeroconf
Published: Jun 22, 2026
Source: GitHub
CVE-2026-48170 CRITICAL - 9.1

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

Vendor: npm
Product: scim-patch
Published: Jun 22, 2026
Source: GitHub

Gogs has SSRF in webhook deliveries

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-48167 MEDIUM - 6.4

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plan...

Vendor: filamentphp
Product: filament
Published: Jun 22, 2026
Source: NVD
CVE-2026-48166 MEDIUM - 5.3

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an ...

Vendor: filamentphp
Product: filament
Published: Jun 22, 2026
Source: NVD
CVE-2025-71358 HIGH - 8.1

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims using pickle.load().

Vendor: picklescan
Product: picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2025-71344 HIGH - 8.1

picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._run_pip calls in __reduce__ methods bypass picklescan detecti...

Vendor: picklescan
Product: picklescan
Published: Jun 22, 2026
Source: NVD