Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 541 - 560 of 35,847 CVEs
CVE-2026-11820 MEDIUM - 6.5

Module: plugins/modules/nexmo.py CVSS 3.1: 6.5 MEDIUM — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: api_key and api_secret are declared no_log=True at the input level, but both credentials are immediately URL-encoded into a GET request as query parameters, bypassing all no_log protection. Vulner...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 23, 2026
Source: NVD
CVE-2026-11819 MEDIUM - 5.5

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into result["passphrase"] with no ou...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 23, 2026
Source: NVD
CVE-2026-11807 CRITICAL - 9.6

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive pla...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Automation Platform 2.6
Published: Jun 23, 2026
Source: NVD

FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0.6.21 through 0.7.2 are vulnerable to IDOR through the support ticket creation workflow. By manipulating rel_id when rel_type=order, an authenticated c...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 23, 2026
Source: NVD
CVE-2026-54555 HIGH - 7.8

rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split or reject several shell constructs that Bash treats as command execution boundaries or nested execution. As a result, a command beginning with an allow...

Vendor: rtk-ai
Product: rtk
Published: Jun 23, 2026
Source: NVD
CVE-2026-39253 HIGH - 8.1

An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.

Published: Jun 23, 2026
Source: NVD

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action arguments declared with public?: false are meant to ...

Vendor: ash-project
Product: ash
Published: Jun 23, 2026
Source: NVD
CVE-2026-55249 MEDIUM - 6.3

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewrite OpenClaw plugin passes attacker-controlled input directly into a shell-backed execSync() template string without shell-safe escaping. JSON.stri...

Vendor: rtk-ai
Product: rtk
Published: Jun 23, 2026
Source: NVD
CVE-2026-54320 HIGH - 8.4

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitations could be accepted (and declined) by a user whose email matched the invitation but had not been verified. Daytona authenticates users via OIDC and mat...

Vendor: daytonaio
Product: daytona
Published: Jun 23, 2026
Source: NVD
CVE-2026-55863 MEDIUM - 5.3

motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution

Vendor: pip
Product: motioneye
Published: Jun 23, 2026
Source: GitHub

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary ...

Vendor: pip
Product: motioneye
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55448 MEDIUM - 6.3

Mise's local credential_command executes untrusted config

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55441 HIGH - 8.6

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

Vendor: GnuPG
Product: GnuPG
Published: Jun 23, 2026
Source: NVD
CVE-2026-57053 MEDIUM - 4.0

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

Vendor: GNU
Product: libidn
Published: Jun 23, 2026
Source: NVD
CVE-2026-54323 MEDIUM - 5.9

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization h...

Vendor: daytonaio
Product: daytona
Published: Jun 23, 2026
Source: NVD
CVE-2026-54318 HIGH - 7.1

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResul...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-54317 HIGH - 7.6

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = F...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-53662 CRITICAL - 9.6

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The co...

Vendor: immich-app
Product: immich
Published: Jun 23, 2026
Source: NVD

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redire...

Vendor: OpenStack
Product: Swift
Published: Jun 23, 2026
Source: NVD