Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,800
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 281 - 300 of 13,511 CVEs
CVE-2026-48028 MEDIUM - 6.5

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing threat acto...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-46349 MEDIUM - 5.3

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing attackers t...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-53949 MEDIUM - 5.3

Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully acces...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53948 MEDIUM - 5.4

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On ins...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53947 MEDIUM - 5.3

Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site. This vulnerability is fixed...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53946 MEDIUM - 5.4

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card β€” without restricting that URL to trusted image hosts. An authenticated staff user able...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53945 MEDIUM - 4.0

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This ...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53944 MEDIUM - 5.8

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-49220 MEDIUM - 5.7

Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged user to execute arbitrary Javascript in the context of a logged-in Administrative user, resulting in numerous potential issues. The Client header during a...

Vendor: jellyfin
Product: jellyfin
Published: Jun 24, 2026
Source: NVD
CVE-2026-13034 MEDIUM - 4.7

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13030 MEDIUM - 5.3

Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13024 MEDIUM - 4.2

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13023 MEDIUM - 5.3

Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13022 MEDIUM - 6.5

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13021 MEDIUM - 4.3

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2025-60471 MEDIUM - 5.5

A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

Published: Jun 24, 2026
Source: NVD
CVE-2026-54686 MEDIUM - 4.3

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. A...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD
CVE-2026-48789 MEDIUM - 4.3

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute Windows path that resolves outside the intended documents directory. The shared pa...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Jun 24, 2026
Source: NVD
CVE-2026-53541 MEDIUM - 4.3

OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering

Vendor: go
Product: github.com/OliveTin/OliveTin
Published: Jun 24, 2026
Source: GitHub
CVE-2026-57307 MEDIUM - 4.2

A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Vendor: Jenkins Project
Product: Jenkins Zowe zDevOps Plugin
Published: Jun 24, 2026
Source: NVD