Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,368
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 201 - 220 of 11,958 CVEs
CVE-2026-25425 HIGH - 7.5

Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.

Vendor: ThemeGrill
Product: User Registration
Published: Jun 15, 2026
Source: NVD
CVE-2026-24637 HIGH - 8.5

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

Vendor: Blubrry Podcasting
Product: PowerPress Podcasting
Published: Jun 15, 2026
Source: NVD
CVE-2026-23970 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.

Vendor: Themeisle
Product: Redirection for Contact Form 7
Published: Jun 15, 2026
Source: NVD
CVE-2025-68872 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.

Vendor: Eli
Product: Eli&#039;s WordCents adSense Widget with Analytics
Published: Jun 15, 2026
Source: NVD
CVE-2025-68851 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.

Vendor: ArrayHQ
Product: Okay Toolkit
Published: Jun 15, 2026
Source: NVD
CVE-2025-68840 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.

Vendor: markbeljaars
Product: iRobots.txt SEO
Published: Jun 15, 2026
Source: NVD
CVE-2025-59133 HIGH - 7.5

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

Vendor: Projectopia
Product: Projectopia
Published: Jun 15, 2026
Source: NVD
CVE-2026-54283 HIGH - 7.5

Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

Vendor: pip
Product: starlette
Published: Jun 15, 2026
Source: GitHub

Nest: Middleware Bypass on Fastify via Trailing Slash

Vendor: npm
Product: @nestjs/platform-fastify
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53539 HIGH - 7.5

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

Vendor: pip
Product: python-multipart
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49853 HIGH - 7.7

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

Vendor: pip
Product: tornado
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49855 HIGH - 7.5

tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

Vendor: pip
Product: tornado
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53705 HIGH - 7.6

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack libra...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-53704 HIGH - 7.1

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets r...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-53703 HIGH - 7.1

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sa...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-52722 HIGH - 7.1

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-52720 HIGH - 8.8

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-52719 HIGH - 7.1

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, cau...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-50891 HIGH - 8.1

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

Published: Jun 15, 2026
Source: NVD
CVE-2026-50889 HIGH - 7.5

An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.

Published: Jun 15, 2026
Source: NVD