Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,446
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 501 - 520 of 33,519 CVEs

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` โ†’ Generated URL Collapses Off-Route Under RFC 3986 Normalization

Vendor: composer
Product: symfony/routing
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Vendor: composer
Product: symfony/mailomat-mailer
Published: Jun 15, 2026
Source: GitHub

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Vendor: composer
Product: symfony/http-client
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48712 HIGH - 7.5

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Vendor: composer
Product: symfony/security-http
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54269 MEDIUM - 5.3

protobufjs : Schema-derived names can shadow runtime-significant properties

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/compiler
Published: Jun 15, 2026
Source: GitHub

Angular: Template and Attribute Namespace Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Vendor: npm
Product: tar
Published: Jun 15, 2026
Source: GitHub

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

Vendor: npm
Product: launch-editor
Published: Jun 15, 2026
Source: GitHub

vite: `server.fs.deny` bypass on Windows alternate paths

Vendor: npm
Product: vite
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53550 MEDIUM - 5.3

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Vendor: npm
Product: js-yaml
Published: Jun 15, 2026
Source: GitHub

@babel/core: Arbitrary File Read via sourceMappingURL Comment

Vendor: npm
Product: @babel/core
Published: Jun 15, 2026
Source: GitHub

@angular/service-worker: Request Credential & Cache Policy Stripping

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub