Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,908
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 541 - 560 of 12,906 CVEs

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub
CVE-2026-54094 MEDIUM - 6.8

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub
CVE-2026-53606 MEDIUM - 5.4

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the `na...

Vendor: apostrophecms
Product: sanitize-html
Published: Jun 12, 2026
Source: NVD
CVE-2026-47264 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag group a tag belonged to without filtering against the requesting use...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-47263 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for /web_hook_events/<id> in Jobs::RedeliverWebHookEvents did not pass group_ids, leaving t...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-45775 MEDIUM - 6.8

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability in Discourse backup handling could allow an authenticated administrator on one site in a multi...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-45085 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in the chat plugin (one also involving discourse-calendar): read-only category users cou...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44785 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper only checks can_see? on the post being explained, not its reply_to_post, so any authenticat...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44784 MEDIUM - 6.5

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are not necessarily admins or moderators can view a group's outgoing email/SMTP credentials in plaintex...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44783 MEDIUM - 5.4

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to whisper posts are handled allows authenticated users outside the groups configured in whispers_allow...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44782 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer declared include_user_long_name? as the predicate for its :name attribute, but AMS looks for include_name...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44780 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, ReviewableQueuedPostSerializer unconditionally included payload["raw_email"] for posts that arrived via incoming em...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44779 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disclose whisper translation audit logs. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-24618 MEDIUM - 4.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4.

Vendor: HashThemes
Product: Hash Elements
Published: Jun 12, 2026
Source: NVD
CVE-2026-46371 MEDIUM - 6.5

Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint

Vendor: go
Product: github.com/fleetdm/fleet/v4
Published: Jun 12, 2026
Source: GitHub
CVE-2026-46370 MEDIUM - 6.5

Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint

Vendor: go
Product: github.com/fleetdm/fleet/v4
Published: Jun 12, 2026
Source: GitHub
CVE-2026-44311 MEDIUM - 5.4

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

Vendor: npm
Product: fabric
Published: Jun 12, 2026
Source: GitHub
CVE-2026-54055 MEDIUM - 5.0

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to arbitrary files on the filesystem by exploiting a TOCTOU (Time-of-Check-T...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-50552 MEDIUM - 6.3

Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation endpoint (POST /api/radio/stations). The url field validation rules are declared without the bail keyword, so the HasAudioConte...

Vendor: koel
Product: koel
Published: Jun 12, 2026
Source: NVD
CVE-2026-50244 MEDIUM - 5.3

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counte...

Vendor: Naxclow
Product: Smart Doorbell X3, X Smart Home, V720, ix cam
Published: Jun 12, 2026
Source: NVD