Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,758
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,461 - 2,480 of 35,133 CVEs

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-10557 CRITICAL - 9.8

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carryin...

Vendor: Yarbo
Product: Yarbo Android/IOS mobile application, Yarbo Cloud MQTT infrastructure
Published: Jun 12, 2026
Source: NVD

SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec

Vendor: swift
Product: github.com/apple/swift-nio-http2
Published: Jun 12, 2026
Source: GitHub

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

Vendor: swift
Product: github.com/apple/swift-nio-extras
Published: Jun 12, 2026
Source: GitHub

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub
CVE-2026-48121 MEDIUM - 6.7

LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access

Vendor: npm
Product: @langchain/langgraph-checkpoint-mongodb
Published: Jun 12, 2026
Source: GitHub

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Vendor: go
Product: github.com/jpillora/chisel
Published: Jun 12, 2026
Source: GitHub

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD
CVE-2026-49993 MEDIUM - 5.7

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspa...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Published: Jun 12, 2026
Source: NVD
CVE-2026-12066 HIGH - 7.3

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery...

Product: PbootCMS
Published: Jun 12, 2026
Source: NVD

A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the attack on the physical de...

Vendor: Groww
Product: Stock, Mutual Fund, Gold App
Published: Jun 12, 2026
Source: NVD

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv library from that location during startup, an att...

Vendor: Mobatek
Product: MobaXterm Personal Edition (Portable)
Published: Jun 12, 2026
Source: NVD

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resort...

Vendor: Mobatek
Product: MobaXterm Personal Edition (Portable)
Published: Jun 12, 2026
Source: NVD
CVE-2017-20240 MEDIUM - 5.9

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

Vendor: ARODLAND
Product: Crypt::PBKDF2
Published: Jun 12, 2026
Source: NVD