Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 501 - 520 of 35,345 CVEs
CVE-2026-55446 HIGH - 7.5

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinit...

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-50559 HIGH - 7.5

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, ...

Vendor: quarkusio
Product: quarkus
Published: Jun 19, 2026
Source: NVD
CVE-2026-50519 MEDIUM - 6.5

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-49346 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size ...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49337 MEDIUM - 4.3

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in at...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49295 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predic...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, due to lack of canonicalization of domains in very specific edge cases, an access control rule may be...

Vendor: authelia
Product: authelia
Published: Jun 19, 2026
Source: NVD
CVE-2026-48584 CRITICAL - 9.9

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-55423 MEDIUM - 6.1

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-48582 CRITICAL - 9.6

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-48129 MEDIUM - 6.5

Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file names directly under the task working directory. When a flow forwards untrusted execution or webhook data into an `inputFiles` file name,...

Vendor: kestra-io
Product: kestra
Published: Jun 19, 2026
Source: NVD
CVE-2026-47645 HIGH - 8.8

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-45480 CRITICAL - 10.0

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-55255 CRITICAL - 9.9

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID...

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-42895 MEDIUM - 6.5

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-32208 HIGH - 8.8

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge_chromium
Published: Jun 19, 2026
Source: NVD

py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()

Vendor: pip
Product: py7zr
Published: Jun 19, 2026
Source: GitHub

py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size

Vendor: pip
Product: py7zr
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55187 MEDIUM - 5.8

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Vendor: go
Product: github.com/axllent/mailpit
Published: Jun 19, 2026
Source: GitHub

Open Redirect Bypass in miniflux-v2

Vendor: go
Product: miniflux.app/v2
Published: Jun 19, 2026
Source: GitHub