Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 541 - 560 of 35,345 CVEs

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Vendor: rubygems
Product: oj
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54784 HIGH - 7.4

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54783 HIGH - 7.4

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54782 CRITICAL - 10.0

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54781 HIGH - 7.4

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54779 MEDIUM - 5.9

CoreWCF: SAML token replay protection is inoperative

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54778 MEDIUM - 6.2

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

Vendor: nuget
Product: CoreWCF.UnixDomainSocket
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54777 MEDIUM - 6.5

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

Vendor: nuget
Product: CoreWCF.NetNamedPipe
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54776 MEDIUM - 4.4

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

Vendor: nuget
Product: CoreWCF.UnixDomainSocket
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54775 MEDIUM - 6.5

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

Vendor: nuget
Product: CoreWCF.Kafka
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54774 HIGH - 7.4

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54773 MEDIUM - 5.9

CoreWCF: WS-Security signature substitution via document-wide Signature lookup

Vendor: nuget
Product: CoreWCF.Primitives
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54772 HIGH - 7.5

CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake

Vendor: nuget
Product: CoreWCF.NetFramingBase
Published: Jun 19, 2026
Source: GitHub

Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

Vendor: pip
Product: python-liquid
Published: Jun 19, 2026
Source: GitHub

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery (SSRF) vulnerability exists in Mercator's CVE configuration panel (`/admin/config/parameters`). The `testProvider()` method in `ConfigurationCont...

Vendor: sourcentis
Product: mercator
Published: Jun 19, 2026
Source: NVD

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/admin/queries/execute`) accepts a JSON DSL (`from` / `select` / `filters` / `traverse` / `output`), translates it into an Eloquent query, and return...

Vendor: sourcentis
Product: mercator
Published: Jun 19, 2026
Source: NVD
CVE-2026-49342 MEDIUM - 5.3

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html`...

Vendor: lsegal
Product: yard
Published: Jun 19, 2026
Source: NVD

gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit this vulnerability by injecting attacker-controlled Go source code through POST /autoCode/addFunc, and then invo...

Vendor: flipped-aurora
Product: gin-vue-admin
Published: Jun 19, 2026
Source: NVD
CVE-2026-48774 HIGH - 7.5

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool violates its documented read-only contract for MySQL targets. The tool validates only the full input string with a substring blacklist and first-keyw...

Vendor: sysown
Product: proxysql
Published: Jun 19, 2026
Source: NVD