Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,661
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 281 - 300 of 35,133 CVEs

SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected

Vendor: go
Product: github.com/authzed/spicedb
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55776 MEDIUM - 6.5

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao's System Backend allows Unauthorized Management of the containing Namespace

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} โ€” incomplete fix of CVE-2026-45808

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55770 MEDIUM - 6.8

OpenBao: LDAPi ldaputil (wrong escape func)

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55692 HIGH - 7.5

StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55650 MEDIUM - 4.4

Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure

Vendor: npm
Product: @outerbase/studio
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55447 CRITICAL - 9.6

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55446 HIGH - 7.5

Langflow: Unauthenticated DoS through multipart form boundary file upload

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-50559 HIGH - 7.5

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, ...

Vendor: quarkusio
Product: quarkus
Published: Jun 19, 2026
Source: NVD
CVE-2026-50519 MEDIUM - 6.5

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-49346 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size ...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49337 MEDIUM - 4.3

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in at...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49295 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predic...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, due to lack of canonicalization of domains in very specific edge cases, an access control rule may be...

Vendor: authelia
Product: authelia
Published: Jun 19, 2026
Source: NVD
CVE-2026-48584 CRITICAL - 9.9

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-55423 MEDIUM - 6.1

Langflow: Logout button does not clear session

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-48582 CRITICAL - 9.6

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-48129 MEDIUM - 6.5

Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file names directly under the task working directory. When a flow forwards untrusted execution or webhook data into an `inputFiles` file name,...

Vendor: kestra-io
Product: kestra
Published: Jun 19, 2026
Source: NVD
CVE-2026-47645 HIGH - 8.8

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD