Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,009
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,901 - 3,920 of 34,907 CVEs
CVE-2026-52879 HIGH - 7.5

klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-49343 MEDIUM - 5.9

Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS

Vendor: go
Product: github.com/klever-io/klever-go
Published: Jun 05, 2026
Source: GitHub
CVE-2026-48017 HIGH - 8.8

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no...

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47684 HIGH - 7.7

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed o...

Vendor: npm
Product: @sync-in/server
Published: Jun 05, 2026
Source: GitHub

Source controller: Improper path handling allows traversal

Vendor: go
Product: github.com/fluxcd/source-controller
Published: Jun 05, 2026
Source: GitHub

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47419 HIGH - 8.3

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

Vendor: pip
Product: praisonai-platform
Published: Jun 05, 2026
Source: GitHub

DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

Vendor: npm
Product: dbgate
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47668 CRITICAL - 10.0

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

Vendor: npm
Product: dbgate-serve
Published: Jun 05, 2026
Source: GitHub

NocoDB: Missing Ownership Check in MCP Attachment Read

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Form View Redirect URL

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: OAuth Authorization Code Race Condition

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Path Traversal via SQLite Source Filename

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: SQL Injection via Column Title in Bulk GroupBy

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Row Comments

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub

NocoDB: Server-Side Request Forgery via Database Connection Host

Vendor: npm
Product: nocodb
Published: Jun 05, 2026
Source: GitHub
CVE-2026-9270 CRITICAL - 9.1

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change...

Vendor: binary
Product: datadog\
Published: Jun 05, 2026
Source: NVD

7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image handler's File Identifier Descriptor parser. In CFileId::Parse (CPP/7zip/Archive/Udf/UdfIn.cpp), after validating size < 38 + idLen + i...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-48101 MEDIUM - 6.5

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB) without ze...

Vendor: mcmilk
Product: 7-Zip
Published: Jun 05, 2026
Source: NVD
CVE-2026-11362 CRITICAL - 9.8

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, w...

Vendor: BINARY
Product: DataDog::DogStatsd
Published: Jun 05, 2026
Source: NVD