Total CVEs

138,170

Critical Severity

3,538

High Severity

12,685

Last 7 Days

1,964
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 34,575 CVEs
CVE-2026-9692 MEDIUM - 5.3

Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sou...

Published: Jun 18, 2026
Source: NVD
CVE-2026-55392 MEDIUM - 5.5

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, c...

Vendor: nilfs-dev
Product: nilfs-utils
Published: Jun 18, 2026
Source: NVD
CVE-2026-48937 MEDIUM - 5.3

A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.

Vendor: nodejs
Product: node
Published: Jun 18, 2026
Source: NVD
CVE-2026-47833 MEDIUM - 6.1

setupBpmLogs follows symlink for bpm.log open and chown โ€” container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership ...

Vendor: Cloud Foundry Foundation
Product: bpm-release
Published: Jun 18, 2026
Source: NVD

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

Vendor: AzeoTech
Product: DAQFactory
Published: Jun 18, 2026
Source: NVD
CVE-2026-54390 CRITICAL - 9.8

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive serve...

Vendor: JTL Software
Product: JTL Shop
Published: Jun 18, 2026
Source: NVD
CVE-2026-48986 MEDIUM - 4.7

pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an infinite loop DoS because it does not initialize *ppid on failure. In pusb_local_login(), the same variable is reused as input and output in a process-tree...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48985 MEDIUM - 5.5

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_loginctl_local() can cause a NULL dereference crash when parsing loginctl output. The function calls popen() and reads the result; if the Remote field is only a newline, fgets() su...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48984 MEDIUM - 4.7

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfree() memory release helper in calls free() without first zeroing the buffer contents, releasing heap-allocated buffers containing sensitive data โ€” including one-time pad bytes read ...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 18, 2026
Source: NVD

Armeria: External Control of File Name or Path in xDS SDS DataSource

Vendor: maven
Product: com.linecorp.armeria:armeria-xds
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54683 MEDIUM - 6.5

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

Vendor: maven
Product: nl.nl-portal:documenten-api
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54319 MEDIUM - 4.2

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox โ€” cross-tenant data access and host escape

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56024 MEDIUM - 6.5

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.

Vendor: Saad Iqbal
Product: WP EasyPay
Published: Jun 18, 2026
Source: NVD
CVE-2026-56022 MEDIUM - 5.3

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-56021 MEDIUM - 5.3

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-56020 HIGH - 8.1

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-55237 HIGH - 8.8

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), whi...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD
CVE-2026-55205 MEDIUM - 5.3

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and th...

Vendor: nesquena
Product: hermes-webui
Published: Jun 18, 2026
Source: NVD
CVE-2026-55204 HIGH - 7.5

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions unde...

Vendor: haproxy
Product: haproxy
Published: Jun 18, 2026
Source: NVD