Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 201 - 220 of 36,720 CVEs
CVE-2026-13434 MEDIUM - 4.9

A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation ...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 26, 2026
Source: NVD

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

Vendor: PayloadCMS
Product: PayloadCMS
Published: Jun 26, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, th...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the serv...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD

fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`

Vendor: rubygems
Product: fluent-plugin-s3
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44161 HIGH - 7.2

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44160 HIGH - 7.5

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44025 HIGH - 7.5

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44024 CRITICAL - 9.8

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-9640 HIGH - 7.2

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restr...

Published: Jun 26, 2026
Source: NVD
CVE-2026-9639 MEDIUM - 6.5

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

Published: Jun 26, 2026
Source: NVD
CVE-2026-5757 HIGH - 7.5

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

Published: Jun 26, 2026
Source: NVD
CVE-2026-45195 HIGH - 7.8

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the GPU Firmware can be used by the Firmware for more privileged memory accesses t...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 26, 2026
Source: NVD
CVE-2026-21734 HIGH - 7.7

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 26, 2026
Source: NVD
CVE-2026-12411 HIGH - 8.4

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

Vendor: Canonical
Product: lxd
Published: Jun 26, 2026
Source: NVD
CVE-2026-0828 HIGH - 7.5

Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.

Published: Jun 26, 2026
Source: NVD
CVE-2026-0685 CRITICAL - 9.8

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

Published: Jun 26, 2026
Source: NVD
CVE-2025-11919 CRITICAL - 9.6

The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file for the the JVM initialization exists in the vulnerable directory during the startup of the JVM. An attacker w...

Vendor: Wolfram Research Inc.
Product: Cloud
Published: Jun 26, 2026
Source: NVD

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity.

Published: Jun 26, 2026
Source: NVD

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary message input, potentially leading to a loss of data integrity.

Vendor: AMD
Product: AMD Ryzen™ 3000 Series Desktop Processors, AMD Ryzen™ 5000 Series Desktop Processors, AMD Ryzen™ Threadripper™ 3000 Series Processors, AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors, AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors
Published: Jun 26, 2026
Source: NVD