Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,853
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 421 - 440 of 12,881 CVEs
CVE-2026-54270 MEDIUM - 5.3

protobufjs: Memory amplification from preserved unknown fields in binary decode

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

aiohttp: Incomplete websocket frame payloads bypass memory limits

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content

Vendor: npm
Product: dompurify
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49458 MEDIUM - 6.1

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

Vendor: npm
Product: dompurify
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49459 MEDIUM - 6.1

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

Vendor: npm
Product: dompurify
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49294 MEDIUM - 6.1

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to reflected cross-site scripting (XSS) due to improper neutralization of input in the JSONP callback parameter. When a request specifies a JSONP callback, th...

Vendor: valhalla
Product: valhalla
Published: Jun 15, 2026
Source: NVD
CVE-2026-20262 MEDIUM - 6.5

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: Jun 15, 2026
Source: NVD

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` โ†’ Generated URL Collapses Off-Route Under RFC 3986 Normalization

Vendor: composer
Product: symfony/routing
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Vendor: composer
Product: symfony/mailomat-mailer
Published: Jun 15, 2026
Source: GitHub

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Vendor: composer
Product: symfony/http-client
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54269 MEDIUM - 5.3

protobufjs : Schema-derived names can shadow runtime-significant properties

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/compiler
Published: Jun 15, 2026
Source: GitHub

Angular: Template and Attribute Namespace Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Vendor: npm
Product: tar
Published: Jun 15, 2026
Source: GitHub

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

Vendor: npm
Product: launch-editor
Published: Jun 15, 2026
Source: GitHub