Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,385
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,661 - 2,680 of 33,671 CVEs
CVE-2025-5089 MEDIUM - 6.5

In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash o...

Published: Jun 05, 2026
Source: NVD
CVE-2025-5088 HIGH - 8.3

An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authenticat...

Published: Jun 05, 2026
Source: NVD
CVE-2026-52878 HIGH - 7.5

Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-52880 HIGH - 7.5

klever-go: REST API slow-header connection exhaustion via Gin Engine.Run

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-52879 HIGH - 7.5

klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-49343 MEDIUM - 5.9

Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-48017 HIGH - 8.8

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no...

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47684 HIGH - 7.7

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed o...

Vendor: npm
Product: @sync-in/server
Published: Jun 05, 2026
Source: GitHub

Source controller: Improper path handling allows traversal

Vendor: go
Product: github.com/fluxcd/source-controller
Published: Jun 05, 2026
Source: GitHub

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47419 HIGH - 8.3

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 05, 2026
Source: GitHub

DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

Vendor: npm
Product: dbgate
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47668 CRITICAL - 10.0

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

Vendor: npm
Product: dbgate-serve
Published: Jun 05, 2026
Source: GitHub

NocoDB: Missing Ownership Check in MCP Attachment Read

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Form View Redirect URL

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: OAuth Authorization Code Race Condition

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Path Traversal via SQLite Source Filename

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: SQL Injection via Column Title in Bulk GroupBy

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Row Comments

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Server-Side Request Forgery via Database Connection Host

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub