Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,638
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1 - 20 of 36,815 CVEs
CVE-2026-44840 HIGH - 7.5

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Vendor: go
Product: github.com/dgraph-io/dgraph/v25
Published: Jun 29, 2026
Source: GitHub

OpenAM OAuth Authorization Bypass via PKCE Challenge

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 29, 2026
Source: GitHub

OpenAM OAuth Client Impersonation via JWKS Resolver Cache

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 29, 2026
Source: GitHub

OpenAM Authenticated RCE via Groovy Sandbox Escape

Vendor: maven
Product: org.openidentityplatform.openam:openam-scripting
Published: Jun 29, 2026
Source: GitHub
CVE-2026-57346 HIGH - 7.1

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.

Vendor: Epiphyt
Product: Embed Privacy
Published: Jun 29, 2026
Source: NVD
CVE-2026-25707 HIGH - 8.8

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

Vendor: SUSE
Product: libzypp
Published: Jun 29, 2026
Source: NVD
CVE-2026-13601 HIGH - 7.1

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-contro...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 29, 2026
Source: NVD
CVE-2026-13557 MEDIUM - 4.3

A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site scripting. The attack may...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13556 MEDIUM - 4.3

A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiat...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13555 HIGH - 7.3

A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit ...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13554 MEDIUM - 4.3

A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name leads to cross site sc...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13553 HIGH - 7.3

A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The expl...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD
CVE-2026-13552 HIGH - 7.3

A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the argument amen_id results in sql injection. It is possible to initiate the attack remotely. T...

Vendor: itsourcecode
Product: Online Hotel Management System
Published: Jun 29, 2026
Source: NVD

Eclipse tinydtls before commitΒ b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate handshake message with a spe...

Published: Jun 29, 2026
Source: NVD
CVE-2026-57966 MEDIUM - 4.4

A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 29, 2026
Source: NVD
CVE-2026-57965 MEDIUM - 5.1

A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 29, 2026
Source: NVD
CVE-2026-57676 MEDIUM - 4.3

Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User Avatar: from n/a through 4.9.

Vendor: Matteo Manna
Product: Simple User Avatar
Published: Jun 29, 2026
Source: NVD
CVE-2026-22078 HIGH - 7.3

Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

Vendor: OPPO
Product: O+ Connect
Published: Jun 29, 2026
Source: NVD
CVE-2026-13595 MEDIUM - 6.8

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 29, 2026
Source: NVD
CVE-2026-13551 HIGH - 7.3

A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed pu...

Vendor: itsourcecode
Product: Baptism Information Management System
Published: Jun 29, 2026
Source: NVD