Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,948
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 261 - 280 of 12,873 CVEs
CVE-2026-49983 MEDIUM - 5.2

Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49860 MEDIUM - 5.2

Deno: WebSocket API sandbox bypass via missing post-DNS check

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49859 MEDIUM - 5.2

Deno: `fetch()` API sandbox bypass via missing DNS resolution check

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54311 MEDIUM - 6.3

n8n: Merge Node SQL Mode Prototype Pollution

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54306 MEDIUM - 5.4

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54308 MEDIUM - 7.2

n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54313 MEDIUM - 7.7

n8n: NoSQL Injection in MongoDB Node Find And Replace Operation

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54310 MEDIUM - 9.9

n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49465 MEDIUM - 7.7

n8n: Git Node Clone and Push Operations Bypass File Sandbox

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-48520 MEDIUM - 6.1

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

Vendor: pip
Product: langflow
Published: Jun 16, 2026
Source: GitHub
CVE-2026-42867 MEDIUM - 6.5

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

Vendor: pip
Product: langflow
Published: Jun 16, 2026
Source: GitHub
CVE-2024-30476 MEDIUM - 5.4

PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead to script execution in the client browser.

Vendor: Dell
Product: PowerStore
Published: Jun 16, 2026
Source: NVD
CVE-2024-22451 MEDIUM - 6.7

Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious executable, leading to arbitrary code execution.

Vendor: Dell
Product: Peripheral Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-10640 MEDIUM - 4.2

Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-interface ICMP-sent statistics by calling net_pkt_iface(pkt) after net_send_data(pkt) had already returned successfully. On the success path the network...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2026-10639 MEDIUM - 4.8

In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_send_data(), and then, on success, calls net_stats_update_icmp_sent(net_pkt_iface(reply)). net_try_send_data() transfers ownership of reply to the TX pa...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2026-10638 MEDIUM - 5.9

subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_request() and net_icmpv6_send_error(), the post-send statistics update calls net_pkt_iface(reply)/net_pkt_iface(pkt) on the just-sent packet. The send pat...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2026-10637 MEDIUM - 5.9

subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network stack's ownership contract (include/zephyr/net/net_core.h, and the explicit warning in subsys/net/ip/net_core.c:453-460 'do not use pkt after...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2024-22447 MEDIUM - 6.7

Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious dll., leading to arbitrary code execution.

Vendor: Dell
Product: Peripheral Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-54298 MEDIUM - 4.2

Astro: XSS via Unescaped Attribute Names in Spread Props

Vendor: npm
Product: astro
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54300 MEDIUM - 5.3

@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config

Vendor: npm
Product: @astrojs/netlify
Published: Jun 16, 2026
Source: GitHub