Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,531
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 35,159 CVEs
CVE-2026-52808 HIGH - 7.1

Gogs's write-level collaborators can mutate admin-only repository settings via API

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs has DOM-based XSS via Milestone Name on New Issue Page

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52806 CRITICAL - 9.9

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52805 HIGH - 8.7

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52802 MEDIUM - 5.4

Gogs has an Open Redirect via redirect_to

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52801 HIGH - 8.1

Gogs has the ability to import local repositories via Mirror Settings

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52800 HIGH - 8.8

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-52799 HIGH - 7.5

Gogs Missing Authorization in Attachment Download

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-52798 HIGH - 8.9

Gogs has Stored XSS in `.ipynb` Preview

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub

Gogs has DoS in rendering issue index pattern

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-50179 MEDIUM - 4.2

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

Vendor: npm
Product: @actual-app/web
Published: Jun 22, 2026
Source: GitHub
CVE-2026-54353 HIGH - 8.5

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

Vendor: npm
Product: @budibase/backend-core
Published: Jun 22, 2026
Source: GitHub
CVE-2026-54352 CRITICAL - 9.6

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-54351 HIGH - 8.2

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-49229 HIGH - 8.3

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

Vendor: npm
Product: @actual-app/sync-server
Published: Jun 22, 2026
Source: GitHub

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-50136 HIGH - 7.4

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-50132 HIGH - 7.3

Budibase has an Account Impersonation Issue โ€” Chat Identity Link Hijacking via Missing Consent & CSRF

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-48487 MEDIUM - 6.5

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

Vendor: pip
Product: zeroconf
Published: Jun 22, 2026
Source: GitHub