Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 35,133 CVEs
CVE-2025-71339 HIGH - 8.1

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation...

Vendor: Picklescan
Product: Picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2026-46700 MEDIUM - 4.3

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

Vendor: npm
Product: @actual-app/sync-server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46672 MEDIUM - 4.6

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

Vendor: npm
Product: @actual-app/cli
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46611 MEDIUM - 5.3

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46608 HIGH - 7.4

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46607 HIGH - 7.8

Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-55599 MEDIUM - 5.8

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects t...

Vendor: phpseclib
Product: phpseclib
Published: Jun 22, 2026
Source: NVD

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulnerability is fixed in 6.13.1.

Vendor: py-pdf
Product: pypdf
Published: Jun 22, 2026
Source: NVD
CVE-2026-39904 MEDIUM - 6.5

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP...

Vendor: gophish
Product: gophish
Published: Jun 22, 2026
Source: NVD
CVE-2026-46606 HIGH - 7.8

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

Vendor: maven
Product: org.openidentityplatform.opendj:opendj-server-legacy
Published: Jun 22, 2026
Source: GitHub

motionEye: Authentication possible via password hash

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44795 HIGH - 8.5

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

Vendor: maven
Product: io.spinnaker.rosco:rosco-core
Published: Jun 22, 2026
Source: GitHub

OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`

Vendor: maven
Product: org.openidentityplatform.openam:openam-federation-library
Published: Jun 22, 2026
Source: GitHub

Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)

Vendor: go
Product: github.com/inspektor-gadget/inspektor-gadget
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44585 MEDIUM - 5.4

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44584 MEDIUM - 4.3

Paymenter doesn't reset email verification status after email change

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44583 MEDIUM - 5.3

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Vendor: nodejs
Product: node
Published: Jun 22, 2026
Source: NVD
CVE-2026-44274 HIGH - 7.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD