Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,781 - 3,800 of 36,778 CVEs

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a vulnerability was discovered in @angular/common when Server-Side Rendering (SSR) and hydration are enabled. The H...

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub
CVE-2026-52725 MEDIUM - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/core package allows bypassing script-execution restrictions during dynamic component creat...

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub
CVE-2026-50169 MEDIUM - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15 20.3.22, and 19.2.23, an issue in the @angular/service-worker package compromises the integrity of request-policy enforcement during reque...

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allows remote attackers to bypass host allowlist constraints and d...

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48779 HIGH - 7.5

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally sm...

Vendor: npm
Product: ws
Published: Jun 15, 2026
Source: GitHub
CVE-2026-9863 HIGH - 7.5

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Maste...

Published: Jun 15, 2026
Source: NVD
CVE-2026-9862 CRITICAL - 9.8

Fortra'sย  Core Privileged Access Manager (BoKS)ย contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration proc...

Published: Jun 15, 2026
Source: NVD
CVE-2026-9595 MEDIUM - 5.3

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's...

Vendor: webpack.js
Product: webpack-dev-server
Published: Jun 15, 2026
Source: NVD
CVE-2026-8683 MEDIUM - 6.5

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD
CVE-2026-5038 MEDIUM - 5.3

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underl...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD
CVE-2026-10634 MEDIUM - 4.8

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connection callback a...

Vendor: zephyrproject
Product: zephyr
Published: Jun 15, 2026
Source: NVD
CVE-2025-15659 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

Vendor: liseperu
Product: Elizaibots
Published: Jun 15, 2026
Source: NVD
CVE-2025-15658 MEDIUM - 5.9

Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.

Vendor: rewish
Product: WP Emmet
Published: Jun 15, 2026
Source: NVD
CVE-2026-54267 HIGH - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, to optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports Hydration via provideClientHydrati...

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub
CVE-2026-6517 MEDIUM - 6.3

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that ro...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD
CVE-2026-5242 HIGH - 8.8

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5233 HIGH - 7.1

Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5230 HIGH - 7.1

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5079 HIGH - 7.5

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of dee...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD