Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 361 - 380 of 34,868 CVEs

opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Access to files of top-level drafts is not protected by permissions

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Request header injection in `Http\Remote`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Self cross-site scripting (self-XSS) in the writer field

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub
CVE-2026-47256 MEDIUM - 5.3

opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Published: Jun 18, 2026
Source: GitHub

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

Vendor: pip
Product: jupyter-server
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55890 MEDIUM - 4.8

Grav: Stored CSS injection via Markdown image ?style=โ€ฆ reaches MediaObjectTrait::style() โ€” incomplete patch of GHSA-r7fx-8g49-7hhr

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55885 MEDIUM - 6.8

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55686 MEDIUM - 5.3

Podman: WORKDIR symlink traversal vulnerability

Vendor: go
Product: github.com/containers/podman/v5
Published: Jun 18, 2026
Source: GitHub

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).

Published: Jun 18, 2026
Source: NVD
CVE-2026-8461 HIGH - 8.8

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpe...

Published: Jun 18, 2026
Source: NVD
CVE-2026-8024 CRITICAL - 9.8

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

Published: Jun 18, 2026
Source: NVD
CVE-2026-56012 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.

Vendor: David Lingren
Product: Media LIbrary Assistant
Published: Jun 18, 2026
Source: NVD
CVE-2026-56009 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83.

Vendor: Bricksable
Product: Bricksable for Bricks Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-56007 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS. This issue affects Ocean Product Sharing: from n/a through 2.2.2.

Vendor: OceanWP
Product: Ocean Product Sharing
Published: Jun 18, 2026
Source: NVD
CVE-2026-54419 CRITICAL - 9.8

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The application has no authentication mechanism and passes user-supplied HTTP parameters di...

Vendor: claudiopizzillo
Product: PIAF-HMS
Published: Jun 18, 2026
Source: NVD