Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,971
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 441 - 460 of 34,990 CVEs
CVE-2026-54390 CRITICAL - 9.8

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive serve...

Vendor: JTL Software
Product: JTL Shop
Published: Jun 18, 2026
Source: NVD
CVE-2026-48986 MEDIUM - 4.7

pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an infinite loop DoS because it does not initialize *ppid on failure. In pusb_local_login(), the same variable is reused as input and output in a process-tree...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48985 MEDIUM - 5.5

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_loginctl_local() can cause a NULL dereference crash when parsing loginctl output. The function calls popen() and reads the result; if the Remote field is only a newline, fgets() su...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48984 MEDIUM - 4.7

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfree() memory release helper in calls free() without first zeroing the buffer contents, releasing heap-allocated buffers containing sensitive data โ€” including one-time pad bytes read ...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 18, 2026
Source: NVD

A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to read arbitrary local fil...

Vendor: maven
Product: com.linecorp.armeria:armeria-xds
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54683 MEDIUM - 6.5

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

Vendor: maven
Product: nl.nl-portal:documenten-api
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54319 MEDIUM - 4.2

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox โ€” cross-tenant data access and host escape

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56024 MEDIUM - 6.5

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.

Vendor: Saad Iqbal
Product: WP EasyPay
Published: Jun 18, 2026
Source: NVD
CVE-2026-56022 MEDIUM - 5.3

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-56021 MEDIUM - 5.3

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-56020 HIGH - 8.1

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-55237 HIGH - 8.8

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), whi...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD
CVE-2026-55205 MEDIUM - 5.3

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and th...

Vendor: nesquena
Product: hermes-webui
Published: Jun 18, 2026
Source: NVD
CVE-2026-55204 HIGH - 7.5

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions unde...

Vendor: haproxy
Product: haproxy
Published: Jun 18, 2026
Source: NVD
CVE-2026-55203 HIGH - 7.5

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect recor...

Vendor: haproxy
Product: haproxy
Published: Jun 18, 2026
Source: NVD
CVE-2026-54106 MEDIUM - 4.7

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass net...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-54105 MEDIUM - 5.3

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the 'update-profile/' API endpoint. A remote, unauthenticated attacker can...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-54104 HIGH - 8.8

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated a...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-54103 CRITICAL - 9.8

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attac...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD