Total CVEs

138,574

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,049
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,301 - 2,320 of 34,979 CVEs
CVE-2026-6853 CRITICAL - 9.8

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile App: from v1.0.6 before v1.5.

Published: Jun 12, 2026
Source: NVD
CVE-2026-6211 HIGH - 8.7

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

Published: Jun 12, 2026
Source: NVD
CVE-2026-54133 CRITICAL - 9.8

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an a...

Vendor: jmespath
Product: jmespath.php
Published: Jun 12, 2026
Source: NVD
CVE-2026-53787 CRITICAL - 9.8

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint without authent...

Vendor: Amasty
Product: Order Attributes for Magento 2
Published: Jun 12, 2026
Source: NVD
CVE-2026-53722 MEDIUM - 5.4

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> element. When an application binds attac...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD
CVE-2026-53721 HIGH - 8.2

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-10557 CRITICAL - 9.8

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carryin...

Vendor: Yarbo
Product: Yarbo Android/IOS mobile application, Yarbo Cloud MQTT infrastructure
Published: Jun 12, 2026
Source: NVD

SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec

Vendor: swift
Product: github.com/apple/swift-nio-http2
Published: Jun 12, 2026
Source: GitHub

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

Vendor: swift
Product: github.com/apple/swift-nio-extras
Published: Jun 12, 2026
Source: GitHub

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub
CVE-2026-48121 MEDIUM - 6.7

LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access

Vendor: npm
Product: @langchain/langgraph-checkpoint-mongodb
Published: Jun 12, 2026
Source: GitHub

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Vendor: go
Product: github.com/jpillora/chisel
Published: Jun 12, 2026
Source: GitHub

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD
CVE-2026-49993 MEDIUM - 5.7

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspa...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD