Total CVEs

137,003

Critical Severity

3,265

High Severity

12,158

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 261 - 280 of 33,408 CVEs
CVE-2025-68840 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.

Vendor: markbeljaars
Product: iRobots.txt SEO
Published: Jun 15, 2026
Source: NVD
CVE-2025-68049 MEDIUM - 6.3

Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.

Vendor: bunny.net
Product: bunny.net
Published: Jun 15, 2026
Source: NVD
CVE-2025-60175 MEDIUM - 4.4

Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.

Vendor: vynnus
Product: PopAd
Published: Jun 15, 2026
Source: NVD
CVE-2025-59133 HIGH - 7.5

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

Vendor: Projectopia
Product: Projectopia
Published: Jun 15, 2026
Source: NVD
CVE-2026-48988 MEDIUM - 5.3

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

Vendor: npm
Product: markdown-it
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54283 HIGH - 7.5

Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

Vendor: pip
Product: starlette
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54285 MEDIUM - 5.3

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

Vendor: npm
Product: @opentelemetry/core
Published: Jun 15, 2026
Source: GitHub

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Vendor: pip
Product: Starlette
Published: Jun 15, 2026
Source: GitHub

Nest: Middleware Bypass on Fastify via Trailing Slash

Vendor: npm
Product: @nestjs/platform-fastify
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53539 HIGH - 7.5

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

Vendor: pip
Product: python-multipart
Published: Jun 15, 2026
Source: GitHub

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

Vendor: pip
Product: python-multipart
Published: Jun 15, 2026
Source: GitHub

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

Vendor: pip
Product: python-multipart
Published: Jun 15, 2026
Source: GitHub

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

Vendor: pip
Product: python-multipart
Published: Jun 15, 2026
Source: GitHub

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

Vendor: npm
Product: electron
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49853 HIGH - 7.7

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

Vendor: pip
Product: tornado
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49855 HIGH - 7.5

tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

Vendor: pip
Product: tornado
Published: Jun 15, 2026
Source: GitHub

Rejected reason: ]** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-49489. Reason: This candidate is a duplicate of CVE-2026-49489. Notes: All CVE users should reference CVE-2026-49489 instead of this candidate.

Published: Jun 15, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12075. Reason: This candidate is a duplicate of CVE-2026-12075. Notes: All CVE users should reference CVE-2026-12075 instead of this candidate.

Published: Jun 15, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12061. Reason: This candidate is a duplicate of CVE-2026-12061. Notes: All CVE users should reference CVE-2026-12061 instead of this candidate.

Published: Jun 15, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12072. Reason: This candidate is a duplicate of CVE-2026-12072. Notes: All CVE users should reference CVE-2026-12072 instead of this candidate.

Published: Jun 15, 2026
Source: NVD