Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,753
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 261 - 280 of 35,119 CVEs
CVE-2026-56081 CRITICAL - 9.1

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account cl...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56080 MEDIUM - 4.9

Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat the account as non-c...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56079 MEDIUM - 6.5

Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs. Attackers can query the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing s...

Vendor: Capgo
Product: Capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56073 CRITICAL - 9.4

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabli...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-55878 HIGH - 7.8

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

Vendor: composer
Product: symfony/ux-toolkit
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55877 MEDIUM - 6.1

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

Vendor: composer
Product: symfony/ux-icons
Published: Jun 19, 2026
Source: GitHub

SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected

Vendor: go
Product: github.com/authzed/spicedb
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55776 MEDIUM - 6.5

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao's System Backend allows Unauthorized Management of the containing Namespace

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} โ€” incomplete fix of CVE-2026-45808

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55770 MEDIUM - 6.8

OpenBao: LDAPi ldaputil (wrong escape func)

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55692 HIGH - 7.5

StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55650 MEDIUM - 4.4

Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure

Vendor: npm
Product: @outerbase/studio
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55447 CRITICAL - 9.6

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55446 HIGH - 7.5

Langflow: Unauthenticated DoS through multipart form boundary file upload

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-50559 HIGH - 7.5

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, ...

Vendor: quarkusio
Product: quarkus
Published: Jun 19, 2026
Source: NVD
CVE-2026-50519 MEDIUM - 6.5

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-49346 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size ...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49337 MEDIUM - 4.3

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in at...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49295 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predic...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD