Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 561 - 580 of 12,930 CVEs
CVE-2025-7018 MEDIUM - 5.5

Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.64.

Published: Jun 12, 2026
Source: NVD
CVE-2025-7010 MEDIUM - 5.5

Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a malformed PDF file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and ...

Published: Jun 12, 2026
Source: NVD
CVE-2025-7006 MEDIUM - 5.5

Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux f...

Published: Jun 12, 2026
Source: NVD
CVE-2025-7005 MEDIUM - 5.5

Uncontrolled recursion vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus...

Published: Jun 12, 2026
Source: NVD

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub
CVE-2026-54094 MEDIUM - 6.8

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub
CVE-2026-53606 MEDIUM - 5.4

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the `na...

Vendor: apostrophecms
Product: sanitize-html
Published: Jun 12, 2026
Source: NVD
CVE-2026-47264 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag group a tag belonged to without filtering against the requesting use...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-47263 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for /web_hook_events/<id> in Jobs::RedeliverWebHookEvents did not pass group_ids, leaving t...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-45775 MEDIUM - 6.8

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability in Discourse backup handling could allow an authenticated administrator on one site in a multi...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-45085 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in the chat plugin (one also involving discourse-calendar): read-only category users cou...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44785 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper only checks can_see? on the post being explained, not its reply_to_post, so any authenticat...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44784 MEDIUM - 6.5

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are not necessarily admins or moderators can view a group's outgoing email/SMTP credentials in plaintex...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44783 MEDIUM - 5.4

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to whisper posts are handled allows authenticated users outside the groups configured in whispers_allow...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44782 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer declared include_user_long_name? as the predicate for its :name attribute, but AMS looks for include_name...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44780 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, ReviewableQueuedPostSerializer unconditionally included payload["raw_email"] for posts that arrived via incoming em...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44779 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disclose whisper translation audit logs. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-24618 MEDIUM - 4.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4.

Vendor: HashThemes
Product: Hash Elements
Published: Jun 12, 2026
Source: NVD
CVE-2026-46371 MEDIUM - 6.5

Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint

Vendor: go
Product: github.com/fleetdm/fleet/v4
Published: Jun 12, 2026
Source: GitHub
CVE-2026-46370 MEDIUM - 6.5

Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint

Vendor: go
Product: github.com/fleetdm/fleet/v4
Published: Jun 12, 2026
Source: GitHub