Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,758
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 561 - 580 of 35,133 CVEs

OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the target is an absolute path. A subsequent file entry in the same archive traverses the symlink, writing t...

Vendor: theonedev
Product: onedev
Published: Jun 18, 2026
Source: NVD
CVE-2026-46699 HIGH - 7.6

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.61.0, a vulnerability in the conda-forge automated webservices allowed unintended write access to feedstock repositories through GitHub userna...

Vendor: conda-forge
Product: conda-smithy
Published: Jun 18, 2026
Source: NVD

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The ht_undo_im...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Jun 18, 2026
Source: NVD
CVE-2026-44663 MEDIUM - 6.1

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl() in src/lib/OpenEXRCore/internal_ht.cpp leads to a heap-buffer overflow when decoding a crafted HTJ2K...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Jun 18, 2026
Source: NVD
CVE-2026-43994 HIGH - 8.1

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth access token (0-65535) is passed directly to memcpy() as the copy length into a 2...

Vendor: coturn
Product: coturn
Published: Jun 18, 2026
Source: NVD
CVE-2025-15661 MEDIUM - 6.5

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME respons...

Vendor: libssh2
Product: libssh2
Published: Jun 18, 2026
Source: NVD
CVE-2026-55591 MEDIUM - 5.8

Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints

Vendor: npm
Product: signalk-server
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56099 MEDIUM - 5.3

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

Vendor: openbsd
Product: src
Published: Jun 18, 2026
Source: NVD
CVE-2026-48983 MEDIUM - 5.8

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink race condition exists in per-device and per-user pad directory creation. pam_usb uses a check-then-act pattern: it calls lstat() to test for existence and then calls mkdir() separ...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48982 MEDIUM - 5.8

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, when updating a one-time pad file, a temporary file is created using open() without the O_EXCL flag. Without O_EXCL, the create operation is not atomic: two concurrent processes racing to u...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48981 MEDIUM - 6.7

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags=0 when loading the configuration file, allowing libxml2 to process external entity references (XXE), potentially making outbound network connections o...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48980 MEDIUM - 6.3

pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environment variable injection into local-check logic. These environment variables influence whether a current session is local o...

Vendor: mcdope
Product: pam_usb
Published: Jun 18, 2026
Source: NVD
CVE-2026-48716 HIGH - 8.7

nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path using the fileName field from an incoming WhatsApp document message without sanitization. The WhatsApp bridge downloads media attachments and writes them ...

Vendor: HKUDS
Product: nanobot
Published: Jun 18, 2026
Source: NVD
CVE-2026-47847 MEDIUM - 5.3

Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables defaulted to monitor and monitor respectively. This use...

Vendor: Bitnami
Product: bitnami/mariadb-galera, bitnami/mariadb-galera Helm chart
Published: Jun 18, 2026
Source: NVD
CVE-2026-47846 CRITICAL - 9.8

Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the container initialization script creates the new superuser account but fails to drop the built-in cassandra...

Vendor: Bitnami
Product: bitnami/cassandra
Published: Jun 18, 2026
Source: NVD
CVE-2026-43915 MEDIUM - 5.4

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/JavaScript that execute...

Vendor: coturn
Product: coturn
Published: Jun 18, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 18, 2026
Source: NVD
CVE-2026-25865 HIGH - 7.8

Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call to WinExec without a fully qualified path for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll. Attac...

Vendor: Yandex
Product: Punto Switcher
Published: Jun 18, 2026
Source: NVD
CVE-2026-9692 MEDIUM - 5.3

Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous hash, and the PID. These are predictable or low-entropy sou...

Published: Jun 18, 2026
Source: NVD
CVE-2026-55392 MEDIUM - 5.5

NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, c...

Vendor: nilfs-dev
Product: nilfs-utils
Published: Jun 18, 2026
Source: NVD