Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 521 - 540 of 36,778 CVEs
CVE-2020-37256 MEDIUM - 5.4

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.

Vendor: Grav
Product: Grav
Published: Jun 25, 2026
Source: NVD
CVE-2026-55166 CRITICAL - 9.9

Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55165 MEDIUM - 4.8

Lemur: JWT verifier honors attacker-supplied alg, enabling ATO

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55164 MEDIUM - 4.9

Lemur user-update path stores plaintext passwords

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55163 MEDIUM - 6.3

Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-55162 MEDIUM - 6.3

Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48722 MEDIUM - 5.5

nextflow auth login command has incorrect default permissions

Vendor: maven
Product: io.nextflow:nextflow
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48702 HIGH - 7.5

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

Vendor: go
Product: github.com/sigstore/rekor
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48529 MEDIUM - 6.0

GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent requests from ...

Vendor: go
Product: github.com/github/github-mcp-server
Published: Jun 25, 2026
Source: GitHub
CVE-2026-6731 HIGH - 7.5

X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6681 MEDIUM - 5.3

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6679 HIGH - 7.5

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This aff...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6678 MEDIUM - 5.3

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6450 MEDIUM - 5.3

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be accepted. This only affects builds with CRL support enabled and where a crafted CRL had a trusted signature when parsed...

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-6412 MEDIUM - 4.3

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

Vendor: wolfssl
Product: wolfssl
Published: Jun 25, 2026
Source: NVD
CVE-2026-56445 CRITICAL - 9.1

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

Vendor: pydicom
Product: pynetdicom Library
Published: Jun 25, 2026
Source: NVD
CVE-2026-38640 HIGH - 7.5

A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.

Published: Jun 25, 2026
Source: NVD
CVE-2026-38637 HIGH - 7.5

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published: Jun 25, 2026
Source: NVD
CVE-2026-37452 HIGH - 7.5

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component

Published: Jun 25, 2026
Source: NVD
CVE-2026-12473 HIGH - 8.2

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attack...

Vendor: Open Health Imaging Foundation (OHIF)
Product: DICOM Web Viewer Framework
Published: Jun 25, 2026
Source: NVD