Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,321 - 2,340 of 35,345 CVEs

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer...

Published: Jun 15, 2026
Source: NVD

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions...

Published: Jun 15, 2026
Source: NVD

LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was sized, while the full count was used to fill it, so a polyline whose poi...

Published: Jun 15, 2026
Source: NVD
CVE-2026-49294 MEDIUM - 6.1

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to reflected cross-site scripting (XSS) due to improper neutralization of input in the JSONP callback parameter. When a request specifies a JSONP callback, th...

Vendor: valhalla
Product: valhalla
Published: Jun 15, 2026
Source: NVD
CVE-2026-47777 HIGH - 7.5

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and faking consent. An attacker could forge the FeatureAuth...

Vendor: mastodon
Product: mastodon
Published: Jun 15, 2026
Source: NVD
CVE-2026-20262 MEDIUM - 6.5

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: Jun 15, 2026
Source: NVD

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` โ†’ Generated URL Collapses Off-Route Under RFC 3986 Normalization

Vendor: composer
Product: symfony/routing
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Vendor: composer
Product: symfony/mailomat-mailer
Published: Jun 15, 2026
Source: GitHub

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Vendor: composer
Product: symfony/http-client
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48712 HIGH - 7.5

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversi...

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Vendor: composer
Product: symfony/security-http
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54269 MEDIUM - 5.3

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names su...

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular framework. When the Service ...

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, ...

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during c...

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an issue in the @angular/compiler package allows bypassing DOM property sanitization through the use of two-way property bindings...

Vendor: npm
Product: @angular/compiler
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22, an issue in the @angular/compiler and @angular/core packages allows bypassing element and attribute sanitization/val...

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domi...

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domi...

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub