Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,704
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,061 - 2,080 of 36,572 CVEs

OpenFGA Improper Policy Enforcement

Vendor: go
Product: github.com/openfga/openfga
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55093 MEDIUM - 6.1

tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load

Vendor: rust
Product: tract-nnef
Published: Jun 18, 2026
Source: GitHub

PGHoard: Password written to debug log

Vendor: pip
Product: pghoard
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54695 HIGH - 7.5

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

Vendor: pip
Product: pipecat-ai
Published: Jun 18, 2026
Source: GitHub

opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Access to files of top-level drafts is not protected by permissions

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Request header injection in `Http\Remote`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Self cross-site scripting (self-XSS) in the writer field

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub
CVE-2026-47256 MEDIUM - 5.3

opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Published: Jun 18, 2026
Source: GitHub
CVE-2026-44727 CRITICAL - 5.4

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-s...

Vendor: pip
Product: jupyter-server
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55890 MEDIUM - 4.8

Grav: Stored CSS injection via Markdown image ?style=โ€ฆ reaches MediaObjectTrait::style() โ€” incomplete patch of GHSA-r7fx-8g49-7hhr

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55885 MEDIUM - 6.8

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55686 MEDIUM - 5.3

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an un...

Vendor: go
Product: github.com/containers/podman/v5
Published: Jun 18, 2026
Source: GitHub

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

Published: Jun 18, 2026
Source: NVD
CVE-2026-8461 HIGH - 8.8

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpe...

Published: Jun 18, 2026
Source: NVD
CVE-2026-8024 CRITICAL - 9.8

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

Published: Jun 18, 2026
Source: NVD