Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,257
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1 - 20 of 35,861 CVEs
CVE-2026-55166 CRITICAL - 9.9

Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55165 MEDIUM - 4.8

Lemur: JWT verifier honors attacker-supplied alg, enabling ATO

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55164 MEDIUM - 4.9

Lemur user-update path stores plaintext passwords

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55163 MEDIUM - 6.3

Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55162 MEDIUM - 6.3

Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48722 MEDIUM - 5.5

nextflow auth login command has incorrect default permissions

Vendor: maven
Product: io.nextflow:nextflow
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48702 HIGH - 7.5

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

Vendor: go
Product: github.com/sigstore/rekor
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48529 MEDIUM - 6.0

GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion

Vendor: go
Product: github.com/github/github-mcp-server
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48508 HIGH - 8.8

Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48504 MEDIUM - 5.3

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

Vendor: rust
Product: opentelemetry_sdk
Published: Jun 25, 2026
Source: GitHub
CVE-2026-46560 HIGH - 7.5

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

Vendor: maven
Product: org.openidentityplatform.openam:openam-radius
Published: Jun 25, 2026
Source: GitHub

OpenAM Arbitrary OAuth Token Minting via Push Registration

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 25, 2026
Source: GitHub

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

Vendor: npm
Product: @anthropic-ai/claude-code
Published: Jun 25, 2026
Source: GitHub

OpenAM has Unsafe Java Deserialization via SNS

Vendor: maven
Product: org.openidentityplatform.openam:openam-push-notification
Published: Jun 25, 2026
Source: GitHub
CVE-2026-8666 HIGH - 7.7

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell com...

Published: Jun 25, 2026
Source: NVD
CVE-2026-8665 HIGH - 7.7

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.

Published: Jun 25, 2026
Source: NVD
CVE-2026-8664 MEDIUM - 6.0

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in shell command construction.

Published: Jun 25, 2026
Source: NVD
CVE-2026-8660 HIGH - 7.7

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands.

Published: Jun 25, 2026
Source: NVD
CVE-2026-8592 HIGH - 7.7

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.

Published: Jun 25, 2026
Source: NVD
CVE-2026-9155 HIGH - 8.8

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.

Published: Jun 25, 2026
Source: NVD