Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 501 - 520 of 36,708 CVEs
CVE-2026-56770 HIGH - 7.5

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causi...

Vendor: schwehr
Product: libais
Published: Jun 25, 2026
Source: NVD
CVE-2026-56769 HIGH - 8.5

Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal serv...

Vendor: hcengineering
Product: platform
Published: Jun 25, 2026
Source: NVD
CVE-2026-56768 HIGH - 8.8

Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory tr...

Vendor: haiwen
Product: seahub
Published: Jun 25, 2026
Source: NVD
CVE-2026-56767 HIGH - 8.8

Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execu...

Vendor: getmaxun
Product: maxun
Published: Jun 25, 2026
Source: NVD
CVE-2026-56766 HIGH - 8.8

Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an ex...

Vendor: vanhauser-thc
Product: thc-hydra
Published: Jun 25, 2026
Source: NVD
CVE-2026-55667 HIGH - 8.2

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope (other tenants' data...

Vendor: filebrowser
Product: filebrowser
Published: Jun 25, 2026
Source: NVD

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives ...

Vendor: seaweedfs
Product: seaweedfs
Published: Jun 25, 2026
Source: NVD
CVE-2026-54250 MEDIUM - 5.8

K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names can be written to a...

Vendor: k3s-io
Product: k3s
Published: Jun 25, 2026
Source: NVD
CVE-2026-54089 CRITICAL - 9.1

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server direc...

Vendor: filebrowser
Product: filebrowser
Published: Jun 25, 2026
Source: NVD

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied c...

Vendor: filebrowser
Product: filebrowser
Published: Jun 25, 2026
Source: NVD
CVE-2026-50549 CRITICAL - 9.8

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to the original path and w...

Vendor: cursor
Product: cursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-50548 CRITICAL - 9.8

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which co...

Vendor: cursor
Product: cursor
Published: Jun 25, 2026
Source: NVD

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing). DPA Countermeasures on SYMCRYPTO can be weakened (reduced entropy) by forcing certain seed values if an attacker gai...

Published: Jun 25, 2026
Source: NVD

In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

Vendor: AzeoTech
Product: DAQFactory
Published: Jun 25, 2026
Source: NVD

Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.

Vendor: Horner Automation
Product: Cscape
Published: Jun 25, 2026
Source: NVD
CVE-2026-48508 HIGH - 8.8

Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48504 MEDIUM - 5.3

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

Vendor: rust
Product: opentelemetry_sdk
Published: Jun 25, 2026
Source: GitHub
CVE-2026-6291 MEDIUM - 6.5

Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depending on whether RSA padding validation failed versus whether the decrypted content was malformed. An attacker able to s...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6094 CRITICAL - 9.1

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6091 MEDIUM - 6.5

Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted anchor. An attacker could present a chain that ends at an intermediate they control and have it accepted as valid. This affects the OpenSSL compatibili...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD