Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,761 - 3,780 of 36,778 CVEs

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Vendor: composer
Product: symfony/mailomat-mailer
Published: Jun 15, 2026
Source: GitHub

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Vendor: composer
Product: symfony/http-client
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48712 HIGH - 7.5

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversi...

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Vendor: composer
Product: symfony/security-http
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54269 MEDIUM - 5.3

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names su...

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54264 HIGH - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular framework. When the Service ...

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54268 HIGH - 7.5

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, ...

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54266 HIGH - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during c...

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54265 MEDIUM - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an issue in the @angular/compiler package allows bypassing DOM property sanitization through the use of two-way property bindings...

Vendor: npm
Product: @angular/compiler
Published: Jun 15, 2026
Source: GitHub
CVE-2026-50557 MEDIUM - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22, an issue in the @angular/compiler and @angular/core packages allows bypassing element and attribute sanitization/val...

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub
CVE-2026-50556 HIGH - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domi...

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub
CVE-2026-50555 HIGH - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domi...

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53655 MEDIUM - 5.5

node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a ...

Vendor: npm
Product: tar
Published: Jun 15, 2026
Source: GitHub

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s...

Vendor: npm
Product: launch-editor
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53571 HIGH - 7.5

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .e...

Vendor: npm
Product: vite
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53550 MEDIUM - 5.3

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and c...

Vendor: npm
Product: js-yaml
Published: Jun 15, 2026
Source: GitHub

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is runnin...

Vendor: npm
Product: @babel/core
Published: Jun 15, 2026
Source: GitHub
CVE-2026-50184 MEDIUM - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/service-worker package compromises the integrity of request-policy enforcement during requ...

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub
CVE-2026-50171 HIGH - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a Denial of Service (DoS) vulnerability exists in the @angular/common package of Angular. The formatNumber function...

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub