Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,443
Quick preset (or use dates below)
Clear Filters
Showing 241 - 260 of 12,254 CVEs

@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

vite: `server.fs.deny` bypass on Windows alternate paths

Vendor: npm
Product: vite
Published: Jun 15, 2026
Source: GitHub

@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48779 HIGH - 7.5

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally sm...

Vendor: npm
Product: ws
Published: Jun 15, 2026
Source: GitHub
CVE-2026-9863 HIGH - 7.5

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Maste...

Published: Jun 15, 2026
Source: NVD

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub
CVE-2026-5242 HIGH - 8.8

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5233 HIGH - 7.1

Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5230 HIGH - 7.1

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5079 HIGH - 7.5

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of dee...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD
CVE-2026-49111 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

Vendor: ThemeGrill
Product: Masteriyo - LMS
Published: Jun 15, 2026
Source: NVD
CVE-2026-49064 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

Vendor: Stiofan
Product: GetPaid
Published: Jun 15, 2026
Source: NVD
CVE-2026-49062 HIGH - 8.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

Vendor: WP Engine
Product: Faust.js
Published: Jun 15, 2026
Source: NVD
CVE-2019-25746 HIGH - 7.1

WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_inv...

Vendor: SlicedInvoices
Product: Sliced Invoices
Published: Jun 15, 2026
Source: NVD
CVE-2018-25437 HIGH - 7.5

WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management di...

Vendor: Cherryframework
Product: Cherry Framework Themes
Published: Jun 15, 2026
Source: NVD
CVE-2016-20084 HIGH - 7.2

WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript i...

Vendor: dwbooster
Product: Booking Calendar Contact
Published: Jun 15, 2026
Source: NVD