Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,006
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,321 - 2,340 of 34,990 CVEs
CVE-2026-10557 CRITICAL - 9.8

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carryin...

Vendor: Yarbo
Product: Yarbo Android/IOS mobile application, Yarbo Cloud MQTT infrastructure
Published: Jun 12, 2026
Source: NVD

SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec

Vendor: swift
Product: github.com/apple/swift-nio-http2
Published: Jun 12, 2026
Source: GitHub

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

Vendor: swift
Product: github.com/apple/swift-nio-extras
Published: Jun 12, 2026
Source: GitHub

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub
CVE-2026-48121 MEDIUM - 6.7

LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access

Vendor: npm
Product: @langchain/langgraph-checkpoint-mongodb
Published: Jun 12, 2026
Source: GitHub

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Vendor: go
Product: github.com/jpillora/chisel
Published: Jun 12, 2026
Source: GitHub

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD
CVE-2026-49993 MEDIUM - 5.7

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspa...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Published: Jun 12, 2026
Source: NVD
CVE-2026-12066 HIGH - 7.3

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery...

Product: PbootCMS
Published: Jun 12, 2026
Source: NVD

A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the attack on the physical de...

Vendor: Groww
Product: Stock, Mutual Fund, Gold App
Published: Jun 12, 2026
Source: NVD

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv library from that location during startup, an att...

Vendor: Mobatek
Product: MobaXterm Personal Edition (Portable)
Published: Jun 12, 2026
Source: NVD

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resort...

Vendor: Mobatek
Product: MobaXterm Personal Edition (Portable)
Published: Jun 12, 2026
Source: NVD
CVE-2017-20240 MEDIUM - 5.9

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

Vendor: ARODLAND
Product: Crypt::PBKDF2
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. The latest release still creates a new database ticket and Discord channel for every completed ticket modal submission, without checking whether the sam...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, unbanning, unwarning, kicking, muting, and unmuting, but stored warning reasons are still printed by /warns without mention suppression. A moderator can create a warning with @everyo...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate users above them in the Discord role hierarchy, as long as the bot itself outranks the target. This bypasses Discord’s normal role hierarchy protections an...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD