Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,711
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 221 - 240 of 13,456 CVEs
CVE-2026-52795 MEDIUM - 4.3

Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private repository they have no access to, because the access check in the Watch API handler is inverted. The code checks if repoCtx.ViewerCanRead() (returns 404 when the user CAN read) instead ...

Vendor: gogs
Product: gogs
Published: Jun 24, 2026
Source: NVD
CVE-2026-50128 MEDIUM - 5.3

Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of their articles. To prevent false attribution claims, Mastodon uses the attributionDomains JSON-LD term, however, an error in how it...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-49278 MEDIUM - 6.7

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by-id-1, token is returned in the response. It looks...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD
CVE-2026-47733 MEDIUM - 4.4

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a href> and <img src> attributes without protocol sanitization. Unlike the analogous LinkS...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD
CVE-2026-13208 MEDIUM - 6.5

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through ...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 24, 2026
Source: NVD
CVE-2026-13201 MEDIUM - 5.2

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kern...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 24, 2026
Source: NVD
CVE-2026-48028 MEDIUM - 6.5

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing threat acto...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-46349 MEDIUM - 5.3

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing attackers t...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-53949 MEDIUM - 5.3

Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully acces...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53948 MEDIUM - 5.4

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On ins...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53947 MEDIUM - 5.3

Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site. This vulnerability is fixed...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53946 MEDIUM - 5.4

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card β€” without restricting that URL to trusted image hosts. An authenticated staff user able...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53945 MEDIUM - 4.0

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This ...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53944 MEDIUM - 5.8

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-49220 MEDIUM - 5.7

Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged user to execute arbitrary Javascript in the context of a logged-in Administrative user, resulting in numerous potential issues. The Client header during a...

Vendor: jellyfin
Product: jellyfin
Published: Jun 24, 2026
Source: NVD
CVE-2026-13034 MEDIUM - 4.7

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13030 MEDIUM - 5.3

Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13024 MEDIUM - 4.2

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13023 MEDIUM - 5.3

Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13022 MEDIUM - 6.5

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD