Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,875
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,481 - 3,500 of 34,481 CVEs
CVE-2026-47419 HIGH - 8.3

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 05, 2026
Source: GitHub

DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

Vendor: npm
Product: dbgate
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47668 CRITICAL - 10.0

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

Vendor: npm
Product: dbgate-serve
Published: Jun 05, 2026
Source: GitHub

NocoDB: Missing Ownership Check in MCP Attachment Read

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Form View Redirect URL

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: OAuth Authorization Code Race Condition

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Path Traversal via SQLite Source Filename

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: SQL Injection via Column Title in Bulk GroupBy

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Row Comments

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Server-Side Request Forgery via Database Connection Host

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub
CVE-2026-9270 CRITICAL - 9.1

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change...

Vendor: binary
Product: datadog\
Published: Jun 05, 2026
Source: NVD

7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image handler's File Identifier Descriptor parser. In CFileId::Parse (CPP/7zip/Archive/Udf/UdfIn.cpp), after validating size < 38 + idLen + i...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-48101 MEDIUM - 6.5

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB) without ze...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-11362 CRITICAL - 9.8

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, w...

Vendor: BINARY
Product: DataDog::DogStatsd
Published: Jun 05, 2026
Source: NVD
CVE-2026-11336 MEDIUM - 6.3

A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of the file dashboard_page/admin_page.php of the component Admin Interface. The manipulation of the argument User...

Vendor: tittuvarghese
Product: CollegeManagementSystem
Published: Jun 05, 2026
Source: NVD

NocoDB: Cross-Workspace Integration Use in Connection Test

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: User Enumeration via Sign-In Timing

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Plaintext Password Comparison in Shared Views

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Hidden Column Exposure in Public Shared View Endpoints

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub