Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 461 - 480 of 12,906 CVEs
CVE-2026-54269 MEDIUM - 5.3

protobufjs : Schema-derived names can shadow runtime-significant properties

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/compiler
Published: Jun 15, 2026
Source: GitHub

Angular: Template and Attribute Namespace Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Vendor: npm
Product: tar
Published: Jun 15, 2026
Source: GitHub

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

Vendor: npm
Product: launch-editor
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53550 MEDIUM - 5.3

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Vendor: npm
Product: js-yaml
Published: Jun 15, 2026
Source: GitHub

@angular/service-worker: Request Credential & Cache Policy Stripping

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub
CVE-2026-9595 MEDIUM - 5.3

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's...

Vendor: webpack.js
Product: webpack-dev-server
Published: Jun 15, 2026
Source: NVD
CVE-2026-8683 MEDIUM - 6.5

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD
CVE-2026-5038 MEDIUM - 5.3

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underl...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD
CVE-2026-10634 MEDIUM - 4.8

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connection callback a...

Vendor: zephyrproject
Product: zephyr
Published: Jun 15, 2026
Source: NVD
CVE-2025-15659 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

Vendor: liseperu
Product: Elizaibots
Published: Jun 15, 2026
Source: NVD
CVE-2025-15658 MEDIUM - 5.9

Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.

Vendor: rewish
Product: WP Emmet
Published: Jun 15, 2026
Source: NVD
CVE-2026-6517 MEDIUM - 6.3

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that ro...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD
CVE-2026-48969 MEDIUM - 6.5

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

Vendor: Really Simple Plugins B.V.
Product: Really Simple SSL
Published: Jun 15, 2026
Source: NVD
CVE-2025-64215 MEDIUM - 6.5

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.

Vendor: StylemixThemes
Product: MasterStudy LMS Pro
Published: Jun 15, 2026
Source: NVD
CVE-2016-20083 MEDIUM - 5.3

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes o...

Vendor: henrikmelin
Product: More Fields
Published: Jun 15, 2026
Source: NVD