Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 601 - 620 of 34,990 CVEs
CVE-2026-12530 HIGH - 7.3

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To ...

Vendor: AWS
Product: bedrock-agentcore
Published: Jun 17, 2026
Source: NVD
CVE-2026-49133 MEDIUM - 6.5

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content directory by supplying traversal sequences in the path query parameter passed to Storage::getFile() with an empty folder argumen...

Vendor: typemill
Product: typemill
Published: Jun 17, 2026
Source: NVD
CVE-2026-48979 HIGH - 7.5

PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADE...

Vendor: php-standard-library
Product: php-standard-library, php-standard-library/h2
Published: Jun 17, 2026
Source: NVD
CVE-2026-48821 MEDIUM - 5.8

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process, malicious bookmark titles are returned via an AJAX response and inserted i...

Vendor: shaarli
Product: Shaarli
Published: Jun 17, 2026
Source: NVD
CVE-2026-55202 HIGH - 8.2

Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorize...

Vendor: tinyproxy
Product: tinyproxy
Published: Jun 17, 2026
Source: NVD
CVE-2026-55201 MEDIUM - 6.8

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server to write files outside the intended download directory by returning filenames with traversal sequences from Get-ChildItem c...

Vendor: Hackplayers
Product: evil-winrm
Published: Jun 17, 2026
Source: NVD
CVE-2026-55200 HIGH - 8.1

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achie...

Vendor: libssh2
Product: libssh2
Published: Jun 17, 2026
Source: NVD
CVE-2026-55199 MEDIUM - 5.9

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can s...

Vendor: libssh2
Product: libssh2
Published: Jun 17, 2026
Source: NVD
CVE-2026-54388 CRITICAL - 9.1

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchr...

Vendor: tinyproxy
Product: tinyproxy
Published: Jun 17, 2026
Source: NVD
CVE-2026-54387 CRITICAL - 9.1

Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can desynchronize the prox...

Vendor: tinyproxy
Product: tinyproxy
Published: Jun 17, 2026
Source: NVD
CVE-2026-50107 HIGH - 8.1

When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format ...

Vendor: F5
Product: NGINX Gateway Fabric
Published: Jun 17, 2026
Source: NVD
CVE-2026-48823 MEDIUM - 4.8

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An authenticated user can inject arbitrary JavaScript into the tags field when creating a bookmark (Shaare). The malicious pay...

Vendor: shaarli
Product: Shaarli
Published: Jun 17, 2026
Source: NVD
CVE-2026-48822 MEDIUM - 5.8

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in the Bookmark Description field. An authenticated user can inject a malicious javascript: URI inside a Markdown link. The v...

Vendor: shaarli
Product: Shaarli
Published: Jun 17, 2026
Source: NVD
CVE-2026-48814 CRITICAL - 9.1

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with ...

Vendor: Jovancoding
Product: Network-AI
Published: Jun 17, 2026
Source: NVD
CVE-2026-32682 MEDIUM - 6.5

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: So...

Vendor: F5
Product: NGINX Gateway Fabric
Published: Jun 17, 2026
Source: NVD
CVE-2026-12529 HIGH - 7.3

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitat...

Vendor: SourceCodester
Product: CET Automated Grading System with AI Predictive Analytics
Published: Jun 17, 2026
Source: NVD
CVE-2026-11407 HIGH - 7.2

Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAllowed() implementations in the custom Twig SecurityPolicy. Attackers can s...

Vendor: Pimcore GmbH
Product: Pimcore CMS/DXP
Published: Jun 17, 2026
Source: NVD

Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.

Vendor: Sonatype
Product: Nexus Repository Manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-10696 HIGH - 7.5

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-con...

Vendor: Devolutions
Product: UniGetUI
Published: Jun 17, 2026
Source: NVD
CVE-2026-55198 MEDIUM - 6.5

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before serializing session d...

Vendor: nesquena
Product: hermes-webui
Published: Jun 17, 2026
Source: NVD