Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,531
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 41 - 60 of 35,159 CVEs
CVE-2026-48170 CRITICAL - 9.1

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

Vendor: npm
Product: scim-patch
Published: Jun 22, 2026
Source: GitHub

Gogs has SSRF in webhook deliveries

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-48167 MEDIUM - 6.4

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plan...

Vendor: filamentphp
Product: filament
Published: Jun 22, 2026
Source: NVD
CVE-2026-48166 MEDIUM - 5.3

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an ...

Vendor: filamentphp
Product: filament
Published: Jun 22, 2026
Source: NVD
CVE-2025-71358 HIGH - 8.1

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims using pickle.load().

Vendor: picklescan
Product: picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2025-71344 HIGH - 8.1

picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._run_pip calls in __reduce__ methods bypass picklescan detecti...

Vendor: picklescan
Product: picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2025-71339 HIGH - 8.1

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation...

Vendor: Picklescan
Product: Picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2026-46700 MEDIUM - 4.3

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

Vendor: npm
Product: @actual-app/sync-server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46672 MEDIUM - 4.6

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

Vendor: npm
Product: @actual-app/cli
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46611 MEDIUM - 5.3

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46608 HIGH - 7.4

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46607 HIGH - 7.8

Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-55599 MEDIUM - 5.8

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects t...

Vendor: phpseclib
Product: phpseclib
Published: Jun 22, 2026
Source: NVD

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulnerability is fixed in 6.13.1.

Vendor: py-pdf
Product: pypdf
Published: Jun 22, 2026
Source: NVD
CVE-2026-39904 MEDIUM - 6.5

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP...

Vendor: gophish
Product: gophish
Published: Jun 22, 2026
Source: NVD
CVE-2026-46606 HIGH - 7.8

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

Vendor: maven
Product: org.openidentityplatform.opendj:opendj-server-legacy
Published: Jun 22, 2026
Source: GitHub

motionEye: Authentication possible via password hash

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44795 HIGH - 8.5

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

Vendor: maven
Product: io.spinnaker.rosco:rosco-core
Published: Jun 22, 2026
Source: GitHub

OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`

Vendor: maven
Product: org.openidentityplatform.openam:openam-federation-library
Published: Jun 22, 2026
Source: GitHub