Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 561 - 580 of 35,861 CVEs

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action arguments declared with public?: false are meant to ...

Vendor: ash-project
Product: ash
Published: Jun 23, 2026
Source: NVD
CVE-2026-55249 MEDIUM - 6.3

@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewrite OpenClaw plugin passes attacker-controlled input directly into a shell-backed execSync() template string without shell-safe escaping. JSON.stri...

Vendor: rtk-ai
Product: rtk
Published: Jun 23, 2026
Source: NVD
CVE-2026-54320 HIGH - 8.4

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitations could be accepted (and declined) by a user whose email matched the invitation but had not been verified. Daytona authenticates users via OIDC and mat...

Vendor: daytonaio
Product: daytona
Published: Jun 23, 2026
Source: NVD
CVE-2026-55863 MEDIUM - 5.3

motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution

Vendor: pip
Product: motioneye
Published: Jun 23, 2026
Source: GitHub

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary ...

Vendor: pip
Product: motioneye
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55448 MEDIUM - 6.3

Mise's local credential_command executes untrusted config

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55441 HIGH - 8.6

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

Vendor: GnuPG
Product: GnuPG
Published: Jun 23, 2026
Source: NVD
CVE-2026-57053 MEDIUM - 4.0

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

Vendor: GNU
Product: libidn
Published: Jun 23, 2026
Source: NVD
CVE-2026-54323 MEDIUM - 5.9

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization h...

Vendor: daytonaio
Product: daytona
Published: Jun 23, 2026
Source: NVD
CVE-2026-54318 HIGH - 7.1

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResul...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-54317 HIGH - 7.6

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = F...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-53662 CRITICAL - 9.6

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The co...

Vendor: immich-app
Product: immich
Published: Jun 23, 2026
Source: NVD

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redire...

Vendor: OpenStack
Product: Swift
Published: Jun 23, 2026
Source: NVD

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Published: Jun 23, 2026
Source: NVD
CVE-2025-71382 MEDIUM - 6.5

MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable...

Vendor: ArtifexSoftware
Product: mupdf
Published: Jun 23, 2026
Source: NVD
CVE-2025-61029 HIGH - 7.5

An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61024 HIGH - 7.5

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2020-9713 MEDIUM - 5.5

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose se...

Published: Jun 23, 2026
Source: NVD
CVE-2020-9711 MEDIUM - 5.5

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of t...

Published: Jun 23, 2026
Source: NVD