Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 181 - 200 of 34,990 CVEs

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

Vendor: rubygems
Product: concurrent-ruby
Published: Jun 19, 2026
Source: GitHub

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

Vendor: rubygems
Product: concurrent-ruby
Published: Jun 19, 2026
Source: GitHub

Oj: Integer Overflow in Oj.load 2GB String Handling

Vendor: rubygems
Product: oj
Published: Jun 19, 2026
Source: GitHub

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

Vendor: rubygems
Product: oj
Published: Jun 19, 2026
Source: GitHub

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

Vendor: rubygems
Product: oj
Published: Jun 19, 2026
Source: GitHub

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Vendor: rubygems
Product: oj
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54784 HIGH - 7.4

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54783 HIGH - 7.4

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54782 CRITICAL - 10.0

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54781 HIGH - 7.4

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54779 MEDIUM - 5.9

CoreWCF: SAML token replay protection is inoperative

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54778 MEDIUM - 6.2

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

Vendor: nuget
Product: CoreWCF.UnixDomainSocket
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54777 MEDIUM - 6.5

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

Vendor: nuget
Product: CoreWCF.NetNamedPipe
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54776 MEDIUM - 4.4

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

Vendor: nuget
Product: CoreWCF.UnixDomainSocket
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54775 MEDIUM - 6.5

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

Vendor: nuget
Product: CoreWCF.Kafka
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54774 HIGH - 7.4

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54773 MEDIUM - 5.9

CoreWCF: WS-Security signature substitution via document-wide Signature lookup

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54772 HIGH - 7.5

CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake

Vendor: nuget
Product: CoreWCF.NetFramingBase
Published: Jun 19, 2026
Source: GitHub

Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

Vendor: pip
Product: python-liquid
Published: Jun 19, 2026
Source: GitHub