Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,053
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,301 - 2,320 of 34,990 CVEs
CVE-2026-45831 HIGH - 8.8

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45830 HIGH - 8.8

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

Vendor: Chroma
Product: ChromaDB
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboarding Step record. This issue has been patched in version 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versions 15.107.2 and 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-44967 MEDIUM - 5.3

OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is a...

Vendor: open-telemetry
Product: opentelemetry-cpp
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.

Vendor: AMD
Product: AMD Management Console (AMC), AMD Ryzen™ Master, AMD µProf
Published: Jun 12, 2026
Source: NVD
CVE-2026-8694 MEDIUM - 5.3

Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.

Vendor: ironmansoftware
Product: powershell_universal
Published: Jun 12, 2026
Source: NVD
CVE-2026-7368 HIGH - 8.1

The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command top...

Published: Jun 12, 2026
Source: NVD
CVE-2026-6853 CRITICAL - 9.8

Improper restriction of excessive authentication attempts vulnerability in BaĹźbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile App: from v1.0.6 before v1.5.

Published: Jun 12, 2026
Source: NVD
CVE-2026-6211 HIGH - 8.7

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

Published: Jun 12, 2026
Source: NVD
CVE-2026-54133 CRITICAL - 9.8

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an a...

Vendor: jmespath
Product: jmespath.php
Published: Jun 12, 2026
Source: NVD
CVE-2026-53787 CRITICAL - 9.8

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint without authent...

Vendor: Amasty
Product: Order Attributes for Magento 2
Published: Jun 12, 2026
Source: NVD
CVE-2026-53722 MEDIUM - 5.4

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> element. When an application binds attac...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD
CVE-2026-53721 HIGH - 8.2

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD