Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,706
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 421 - 440 of 36,572 CVEs
CVE-2026-54033 HIGH - 7.7

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-compatible API endpoints by setting a baseURL. This URL is used to construct HTTP requests without any SSRF validation β€” no private IP check, no scheme re...

Vendor: danny-avila
Product: LibreChat
Published: Jun 25, 2026
Source: NVD
CVE-2026-54030 HIGH - 8.0

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter from OAuth Protected Resource metadata (RFC 9728) matches the configured MCP server URL, allowing a malicious MCP server...

Vendor: danny-avila
Product: LibreChat
Published: Jun 25, 2026
Source: NVD
CVE-2026-54029 MEDIUM - 5.3

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMessageReq middleware only validates that the conversationI...

Vendor: danny-avila
Product: LibreChat
Published: Jun 25, 2026
Source: NVD
CVE-2026-54027 MEDIUM - 6.5

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code) without verifying ownership or EDIT permission on the t...

Vendor: danny-avila
Product: LibreChat
Published: Jun 25, 2026
Source: NVD
CVE-2026-54025 MEDIUM - 5.4

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown artifact preview pipeline. The marked library v15.0.12 does not HTML-escape double-quote characters in image alt text when a custom renderer falls thr...

Vendor: danny-avila
Product: LibreChat
Published: Jun 25, 2026
Source: NVD
CVE-2026-54024 MEDIUM - 6.5

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-11171 (commit bb58a2d0) added limits: { fileSize } to createMulterInstance() in the file upload routes. However, the POST /api/convos/import endpoint uses a separate multer instance t...

Vendor: danny-avila
Product: LibreChat
Published: Jun 25, 2026
Source: NVD
CVE-2026-45233 HIGH - 8.1

HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequences in the oldfile parameter at the admin autosave endpoint. Attackers can pass unsanitized traversal sequences direct...

Vendor: danpros
Product: htmly
Published: Jun 25, 2026
Source: NVD
CVE-2026-13351 HIGH - 7.5

Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number of maliciously fragmented IPv6 packets. When such a packet is handled by the fragment-header processing path, the associated RX network packet buffer (allocated from a mem...

Vendor: zephyrproject-rtos
Product: Zephyr
Published: Jun 25, 2026
Source: NVD

Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.

Vendor: pretix
Product: Venueless
Published: Jun 25, 2026
Source: NVD

OpenAM Arbitrary OAuth Token Minting via Push Registration

Vendor: maven
Product: org.openidentityplatform.openam:openam-oauth2
Published: Jun 25, 2026
Source: GitHub

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

Vendor: npm
Product: @anthropic-ai/claude-code
Published: Jun 25, 2026
Source: GitHub

OpenAM has Unsafe Java Deserialization via SNS

Vendor: maven
Product: org.openidentityplatform.openam:openam-push-notification
Published: Jun 25, 2026
Source: GitHub

CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service.

Published: Jun 25, 2026
Source: NVD

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user int...

Published: Jun 25, 2026
Source: NVD

CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.

Published: Jun 25, 2026
Source: NVD

CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.

Published: Jun 25, 2026
Source: NVD

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device i...

Published: Jun 25, 2026
Source: NVD
CVE-2026-57456 HIGH - 7.8

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completio...

Vendor: vim
Product: vim
Published: Jun 25, 2026
Source: NVD
CVE-2026-57455 HIGH - 7.8

Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper ...

Vendor: vim
Product: vim
Published: Jun 25, 2026
Source: NVD
CVE-2026-57454 MEDIUM - 6.1

Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose offset and length point outside the line's property data. When Vim restores or displays such a line it converts the offset into a pointer and reads ...

Vendor: vim
Product: vim
Published: Jun 25, 2026
Source: NVD