Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,821
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,181 - 2,200 of 36,689 CVEs
CVE-2026-54695 HIGH - 7.5

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

Vendor: pip
Product: pipecat-ai
Published: Jun 18, 2026
Source: GitHub

opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Access to files of top-level drafts is not protected by permissions

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Request header injection in `Http\Remote`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Self cross-site scripting (self-XSS) in the writer field

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub
CVE-2026-47256 MEDIUM - 5.3

opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Published: Jun 18, 2026
Source: GitHub
CVE-2026-44727 CRITICAL - 5.4

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-s...

Vendor: pip
Product: jupyter-server
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55890 MEDIUM - 4.8

Grav: Stored CSS injection via Markdown image ?style=โ€ฆ reaches MediaObjectTrait::style() โ€” incomplete patch of GHSA-r7fx-8g49-7hhr

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55885 MEDIUM - 6.8

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55686 MEDIUM - 5.3

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an un...

Vendor: go
Product: github.com/containers/podman/v5
Published: Jun 18, 2026
Source: GitHub

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

Published: Jun 18, 2026
Source: NVD
CVE-2026-8461 HIGH - 8.8

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpe...

Published: Jun 18, 2026
Source: NVD
CVE-2026-8024 CRITICAL - 9.8

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

Published: Jun 18, 2026
Source: NVD
CVE-2026-56012 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.

Vendor: David Lingren
Product: Media LIbrary Assistant
Published: Jun 18, 2026
Source: NVD
CVE-2026-56009 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83.

Vendor: Bricksable
Product: Bricksable for Bricks Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-56007 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS. This issue affects Ocean Product Sharing: from n/a through 2.2.2.

Vendor: OceanWP
Product: Ocean Product Sharing
Published: Jun 18, 2026
Source: NVD