Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,101 - 2,120 of 34,871 CVEs

An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts within the same organization. The affected access-control checks scoped administrative actions by organization membership but...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD
CVE-2026-54055 MEDIUM - 5.0

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to arbitrary files on the filesystem by exploiting a TOCTOU (Time-of-Check-T...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50552 MEDIUM - 6.3

Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation endpoint (POST /api/radio/stations). The url field validation rules are declared without the bail keyword, so the HasAudioConte...

Vendor: koel
Product: koel
Published: Jun 12, 2026
Source: NVD

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initia...

Vendor: agenticmail
Product: agenticmail
Published: Jun 12, 2026
Source: NVD

Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.

Vendor: actualbudget
Product: actual
Published: Jun 12, 2026
Source: NVD
CVE-2026-42851 HIGH - 7.8

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to execute attacker-supp...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-42850 HIGH - 8.8

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped and will be correctly echoed back to the terminal with CRLF, as such ...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD

Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 `client_secret`—to any caller who knows the bootstrap password. The endpoint also lacks authe...

Vendor: actualbudget
Product: actual
Published: Jun 12, 2026
Source: NVD
CVE-2026-53999 HIGH - 7.7

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

Vendor: go
Product: github.com/radius-project/radius
Published: Jun 12, 2026
Source: GitHub

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation field even when that field was hidden from the requesting client ...

Vendor: parse-community
Product: parse-server
Published: Jun 12, 2026
Source: NVD

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions could expose sensitive user data through the /login and /verify...

Vendor: parse-community
Product: parse-server
Published: Jun 12, 2026
Source: NVD

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwise be blocked (e.g. p...

Vendor: parse-community
Product: parse-server
Published: Jun 12, 2026
Source: NVD
CVE-2026-53408 HIGH - 8.1

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

Vendor: Zoom Communications
Product: Zoom Workplace
Published: Jun 12, 2026
Source: NVD
CVE-2026-53407 HIGH - 8.1

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

Vendor: Zoom Communications
Product: Zoom Workplace
Published: Jun 12, 2026
Source: NVD
CVE-2026-50244 MEDIUM - 5.3

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counte...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-50108 HIGH - 7.5

The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on t...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-50101 HIGH - 8.1

Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain p...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD
CVE-2026-50099 MEDIUM - 4.6

During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell that permits arbitrary...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is only enforced as Express...

Vendor: parse-community
Product: parse-server
Published: Jun 12, 2026
Source: NVD
CVE-2026-47236 MEDIUM - 4.3

Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members API. The Jetstream web team page authorizes access with only belongsToTeam() and then loads and serializ...

Vendor: solidtime-io
Product: solidtime
Published: Jun 12, 2026
Source: NVD