Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,230
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,621 - 5,640 of 35,861 CVEs

Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44180 CRITICAL - 9.8

Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass

Vendor: pip
Product: jupyter_enterprise_gateway
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44023 HIGH - 8.6

Docling Core: Unsafe remote filename resolution

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44019 HIGH - 8.1

Docling Core: Insufficient validation of image reference URIs

Vendor: pip
Product: docling-core
Published: Jun 03, 2026
Source: GitHub
CVE-2026-47214 HIGH - 7.1

Docling: Unsafe URI and Path Handling in HTML Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44022 MEDIUM - 5.5

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers could craft malic...

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44020 HIGH - 7.5

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard xml.sax.parseString() without protection against XML External Entity (XXE) attacks. An attacker could...

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44018 MEDIUM - 5.5

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-44016 HIGH - 8.2

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for rendering (rendering option by default deactivated), then the Playwright-based rend...

Vendor: pip
Product: docling
Published: Jun 03, 2026
Source: GitHub
CVE-2026-43980 MEDIUM - 6.3

malla: Stored XSS via Meshtastic node names in multiple frontend pages

Vendor: pip
Product: malla
Published: Jun 03, 2026
Source: GitHub
CVE-2026-41234 HIGH - 7.6

Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record l...

Vendor: composer
Product: froxlor/froxlor
Published: Jun 03, 2026
Source: GitHub
CVE-2026-40898 MEDIUM - 5.3

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique fie...

Vendor: go
Product: github.com/quic-go/quic-go
Published: Jun 03, 2026
Source: GitHub
CVE-2026-50033 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44682 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD
CVE-2026-44609 HIGH - 7.3

Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This allows arbitrary external URLs to be configured as redirect tar...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 03, 2026
Source: NVD
CVE-2026-42061 HIGH - 7.3

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Jun 03, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hide_version_public` security setting. The FOSSBilling version is embedded in the query string of every ...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 03, 2026
Source: NVD
CVE-2026-37700 MEDIUM - 4.1

Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page

Published: Jun 03, 2026
Source: NVD
CVE-2026-26825 MEDIUM - 5.3

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lea...

Vendor: libxls_project
Product: libxls
Published: Jun 03, 2026
Source: NVD