Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,796
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 201 - 220 of 36,724 CVEs
CVE-2026-45407 MEDIUM - 5.5

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creation defeats the netrc binary's built-in 0600 permission setting, leaving git credentials readable by any local...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-45406 HIGH - 8.8

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename cont...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-45405 HIGH - 8.8

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks during extraction and follows them for subsequent e...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-28385 MEDIUM - 5.0

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a...

Vendor: Canonical
Product: lxd
Published: Jun 26, 2026
Source: NVD
CVE-2026-13434 MEDIUM - 4.9

A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation ...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 26, 2026
Source: NVD

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

Vendor: PayloadCMS
Product: PayloadCMS
Published: Jun 26, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, th...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the serv...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD

fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`

Vendor: rubygems
Product: fluent-plugin-s3
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44161 HIGH - 7.2

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44160 HIGH - 7.5

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44025 HIGH - 7.5

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44024 CRITICAL - 9.8

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-9640 HIGH - 7.2

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restr...

Published: Jun 26, 2026
Source: NVD
CVE-2026-9639 MEDIUM - 6.5

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

Published: Jun 26, 2026
Source: NVD
CVE-2026-5757 HIGH - 7.5

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

Published: Jun 26, 2026
Source: NVD
CVE-2026-45195 HIGH - 7.8

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the GPU Firmware can be used by the Firmware for more privileged memory accesses t...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 26, 2026
Source: NVD
CVE-2026-21734 HIGH - 7.7

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 26, 2026
Source: NVD
CVE-2026-12411 HIGH - 8.4

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.

Vendor: Canonical
Product: lxd
Published: Jun 26, 2026
Source: NVD
CVE-2026-0828 HIGH - 7.5

Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.

Published: Jun 26, 2026
Source: NVD