Total CVEs

138,500

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,016
Quick preset (or use dates below)
Clear Filters
Showing 301 - 320 of 13,339 CVEs

Gitea: Token scope bypass on web archive download endpoint

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-27783 MEDIUM - 4.3

Gitea: Missing repository-unit authorization on issue-template API endpoints

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-25714 MEDIUM - 4.3

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54314 MEDIUM - 5.9

n8n: Denial of Service via ZIP decompression in webhook workflow

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54303 MEDIUM - 7.6

n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52846 MEDIUM - 4.2

Caddy: stripHTML template function bypass

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50019 MEDIUM - 6.1

yt-dlp: File Downloader cookie leak with curl

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-46448 MEDIUM - 5.4

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

Vendor: OpenStack
Product: Nova
Published: Jun 16, 2026
Source: NVD
CVE-2026-12117 MEDIUM - 4.3

Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not authorized via a crafted API request.

Vendor: Devolutions
Product: Devolutions Server
Published: Jun 16, 2026
Source: NVD
CVE-2026-12105 MEDIUM - 6.5

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.

Vendor: Devolutions
Product: Devolutions Server
Published: Jun 16, 2026
Source: NVD
CVE-2026-11890 MEDIUM - 4.3

Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.

Vendor: Devolutions
Product: Devolutions Server
Published: Jun 16, 2026
Source: NVD
CVE-2026-0165 MEDIUM - 5.7

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD
CVE-2026-0157 MEDIUM - 4.3

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD
CVE-2026-0155 MEDIUM - 4.3

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD
CVE-2026-0144 MEDIUM - 6.5

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD
CVE-2026-0141 MEDIUM - 4.3

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD
CVE-2026-0140 MEDIUM - 4.3

In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD
CVE-2026-0136 MEDIUM - 6.5

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD
CVE-2026-0127 MEDIUM - 6.5

In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication processor crash with no additional execution privileges needed. User interaction is not needed for ...

Vendor: google
Product: android
Published: Jun 16, 2026
Source: NVD

Hugo: Symlink confinement bypass in resources.Get

Vendor: go
Product: github.com/gohugoio/hugo
Published: Jun 16, 2026
Source: GitHub