Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,758
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 35,119 CVEs

Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)

Vendor: go
Product: github.com/inspektor-gadget/inspektor-gadget
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44585 MEDIUM - 5.4

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44584 MEDIUM - 4.3

Paymenter doesn't reset email verification status after email change

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44583 MEDIUM - 5.3

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Vendor: composer
Product: paymenter/paymenter
Published: Jun 22, 2026
Source: GitHub

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Vendor: nodejs
Product: node
Published: Jun 22, 2026
Source: NVD
CVE-2026-44274 HIGH - 7.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44273 MEDIUM - 6.0

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44272 HIGH - 8.8

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-44271 HIGH - 8.1

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized ac...

Vendor: Dell
Product: Wyse Management Suite (WMS)
Published: Jun 22, 2026
Source: NVD
CVE-2026-10852 MEDIUM - 5.9

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

Vendor: IBM
Product: i
Published: Jun 22, 2026
Source: NVD
CVE-2026-44517 MEDIUM - 6.3

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

Vendor: go
Product: github.com/containers/buildah
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44203 CRITICAL - 9.3

OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 22, 2026
Source: GitHub

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44179 CRITICAL - 9.9

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

Vendor: maven
Product: com.xwiki.pro:xwiki-pro-macros
Published: Jun 22, 2026
Source: GitHub
CVE-2026-41579 MEDIUM - 3.3

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

Vendor: go
Product: github.com/opencontainers/runc
Published: Jun 22, 2026
Source: GitHub

OpenAM has LDAP Injection via `_queryId` Parameter

Vendor: maven
Product: org.openidentityplatform.openam:openam-core-rest
Published: Jun 22, 2026
Source: GitHub
CVE-2026-33731 MEDIUM - 6.5

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

Vendor: composer
Product: wwbn/avideo
Published: Jun 22, 2026
Source: GitHub
CVE-2026-33692 HIGH - 7.5

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

Vendor: composer
Product: wwbn/avideo
Published: Jun 22, 2026
Source: GitHub
CVE-2026-55443 MEDIUM - 5.1

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agen...

Vendor: langchain-ai
Product: langchain, langchain-anthropic
Published: Jun 22, 2026
Source: NVD
CVE-2026-53779 HIGH - 7.5

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with percent-encoded backslashes (%5C) that bypass the path.Clean() sanitization in handler/router.go. At...

Vendor: webp-sh
Product: webp_server_go
Published: Jun 22, 2026
Source: NVD