Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,974
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 201 - 220 of 34,601 CVEs
CVE-2026-8050 HIGH - 7.5

In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash.

Published: Jun 17, 2026
Source: NVD
CVE-2026-8049 MEDIUM - 5.3

In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly permissive default access control, allowing any authenticated local user to obtain a handle to the device and iss...

Published: Jun 17, 2026
Source: NVD
CVE-2026-54386 MEDIUM - 6.1

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Atta...

Vendor: marimo-team
Product: marimo
Published: Jun 17, 2026
Source: NVD
CVE-2026-50200 HIGH - 7.5

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the Environment actuator redac...

Vendor: SteeltoeOSS
Product: Steeltoe.Management.Endpoint, Steeltoe.Management.EndpointCore
Published: Jun 17, 2026
Source: NVD
CVE-2026-50196 HIGH - 7.5

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and 3.4.0, `DataCenterInfo.FromJson` throws `ArgumentException` for any `name` value other than `"MyOwn"` or `&q...

Vendor: SteeltoeOSS
Product: Steeltoe.Discovery.Eureka
Published: Jun 17, 2026
Source: NVD
CVE-2026-50194 HIGH - 8.2

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the middle...

Vendor: SteeltoeOSS
Product: Steeltoe.Management.Endpoint, Steeltoe.Management.EndpointCore
Published: Jun 17, 2026
Source: NVD
CVE-2026-48997 HIGH - 7.1

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destination path. In resize_image(), the source path is escaped with escapeshellarg(), but the destination path is inserted inside raw double quotes in the conve...

Vendor: e107inc
Product: e107
Published: Jun 17, 2026
Source: NVD
CVE-2026-48991 MEDIUM - 5.5

XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or state validation. Explo...

Vendor: XianYuLauncher
Product: XianYuLauncher
Published: Jun 17, 2026
Source: NVD
CVE-2026-48990 MEDIUM - 5.3

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversized RFC7797 b64=false JWS payloads without applying JWSRegistry.max_payload_length, which can lead to resource exhaustion...

Vendor: authlib
Product: joserfc
Published: Jun 17, 2026
Source: NVD

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a P...

Vendor: CursorTouch
Product: Windows-MCP
Published: Jun 17, 2026
Source: NVD

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. W...

Vendor: cakephp
Product: cakephp
Published: Jun 17, 2026
Source: NVD
CVE-2026-12530 HIGH - 7.3

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To ...

Vendor: AWS
Product: bedrock-agentcore
Published: Jun 17, 2026
Source: NVD
CVE-2026-49133 MEDIUM - 6.5

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content directory by supplying traversal sequences in the path query parameter passed to Storage::getFile() with an empty folder argumen...

Vendor: typemill
Product: typemill
Published: Jun 17, 2026
Source: NVD
CVE-2026-48979 HIGH - 7.5

PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADE...

Vendor: php-standard-library
Product: php-standard-library, php-standard-library/h2
Published: Jun 17, 2026
Source: NVD
CVE-2026-48821 MEDIUM - 5.8

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process, malicious bookmark titles are returned via an AJAX response and inserted i...

Vendor: shaarli
Product: Shaarli
Published: Jun 17, 2026
Source: NVD
CVE-2026-55202 HIGH - 8.2

Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorize...

Vendor: tinyproxy
Product: tinyproxy
Published: Jun 17, 2026
Source: NVD
CVE-2026-55201 MEDIUM - 6.8

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server to write files outside the intended download directory by returning filenames with traversal sequences from Get-ChildItem c...

Vendor: Hackplayers
Product: evil-winrm
Published: Jun 17, 2026
Source: NVD
CVE-2026-55200 HIGH - 8.1

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achie...

Vendor: libssh2
Product: libssh2
Published: Jun 17, 2026
Source: NVD
CVE-2026-55199 MEDIUM - 5.9

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can s...

Vendor: libssh2
Product: libssh2
Published: Jun 17, 2026
Source: NVD
CVE-2026-54388 CRITICAL - 9.1

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchr...

Vendor: tinyproxy
Product: tinyproxy
Published: Jun 17, 2026
Source: NVD