Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,121 - 6,140 of 34,990 CVEs

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentication. The endpoint is registered on the console listener and returns JSON containing license informa...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origin value back as Access-Control-Allow-Origin and also sets Access-Control-Allow-Credentials: true...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD
CVE-2026-46526 MEDIUM - 5.0

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The m...

Vendor: LearningCircuit
Product: local-deep-research
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing destination bucket restrictions on allowed copy sources. The implementation validates GetObject permissio...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses it in production via parse_license() to "verify" license tokens. Because the key is embedded...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (JWT), SecretAccessKey, and full JWT claims are printed in pla...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD
CVE-2026-45039 CRITICAL - 9.8

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret() in crates/ecstore/src/rpc/http_auth.rs, falls back ...

Vendor: rustfs
Product: rustfs
Published: May 28, 2026
Source: NVD
CVE-2026-44394 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapp...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-43000 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token car...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-42999 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set fr...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-42998 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credent...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-30761 HIGH - 7.3

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

Published: May 28, 2026
Source: NVD
CVE-2026-30760 HIGH - 7.3

An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

Published: May 28, 2026
Source: NVD
CVE-2026-46439 HIGH - 7.8

compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-46405 MEDIUM - 5.3

OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46380 MEDIUM - 6.7

compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-45323 CRITICAL - 9.6

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewi...

Vendor: jpettitt
Product: meshcore-card
Published: May 28, 2026
Source: NVD
CVE-2026-45307 MEDIUM - 6.1

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urljoin(request.host_url, target) before parsing, while the controller passed the raw target to redirect(...

Vendor: murtaza-nasir
Product: speakr
Published: May 28, 2026
Source: NVD

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS api/auth/auth_project.py:14-38 and EE ee/api/auth/auth_project.py:14-46) only runs projects.is_autho...

Vendor: openreplay
Product: openreplay
Published: May 28, 2026
Source: NVD