Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,531
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 35,159 CVEs
CVE-2026-55863 MEDIUM - 5.3

motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution

Vendor: pip
Product: motioneye
Published: Jun 23, 2026
Source: GitHub

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

Vendor: pip
Product: motioneye
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55448 MEDIUM - 6.3

Mise's local credential_command executes untrusted config

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55441 HIGH - 8.6

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54557 MEDIUM - 5.5

mise HTTP backend uses raw version path for install symlink destination

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub

OctoPrint has possible file exfiltration via query parameters on upload endpoints

Vendor: pip
Product: OctoPrint
Published: Jun 23, 2026
Source: GitHub
CVE-2026-53925 HIGH - 7.8

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

Vendor: pip
Product: glances
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54350 CRITICAL - 10.0

Budibase has nonymous NoSQL operator injection via published-app query templates

Vendor: npm
Product: @budibase/server
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55173 HIGH - 8.1

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

Vendor: composer
Product: wwbn/avideo
Published: Jun 23, 2026
Source: GitHub

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-45049 HIGH - 8.3

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

Vendor: maven
Product: org.openidentityplatform.openam:openam-federation
Published: Jun 23, 2026
Source: GitHub
CVE-2026-45048 HIGH - 8.5

OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jun 23, 2026
Source: GitHub

OctoPrint has XSS in its Suppressed Command Notifications

Vendor: pip
Product: OctoPrint
Published: Jun 23, 2026
Source: GitHub

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52813 CRITICAL - 10.0

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs: LFS dedupe path leaks private repo content across tenants

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52809 MEDIUM - 6.8

Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub