Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 621 - 640 of 34,990 CVEs
CVE-2026-55197 MEDIUM - 6.5

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to other profiles via GET /a...

Vendor: nesquena
Product: hermes-webui
Published: Jun 17, 2026
Source: NVD
CVE-2026-55196 CRITICAL - 9.1

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and...

Vendor: hermes-webui
Product: hermes-webui
Published: Jun 17, 2026
Source: NVD
CVE-2026-53871 HIGH - 8.1

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization check...

Vendor: nesquena
Product: hermes-webui
Published: Jun 17, 2026
Source: NVD
CVE-2026-53870 MEDIUM - 5.5

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including con...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 17, 2026
Source: NVD
CVE-2026-53869 HIGH - 7.5

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling atta...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 17, 2026
Source: NVD

CakePHP Authentication: Open redirect weakness via backslash bypass

Vendor: composer
Product: cakephp/authentication
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55518 CRITICAL - 9.6

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

Vendor: rubygems
Product: avo
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55517 MEDIUM - 4.3

Deno: Denial of service via non-ASCII bytes in WebSocket response headers

Vendor: rust
Product: deno
Published: Jun 17, 2026
Source: GitHub

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.utilities
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55470 HIGH - 7.5

HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55450 CRITICAL - 9.3

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Vendor: pip
Product: langflow
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55760 HIGH - 7.5

handlebars.java FileTemplateLoader Path Traversal

Vendor: maven
Product: com.github.jknack:handlebars
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55409 HIGH - 7.6

Filament: Disabled RichEditor field state can be used for XSS

Vendor: composer
Product: filament/forms
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55405 HIGH - 7.6

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

Vendor: maven
Product: dev.langchain4j:langchain4j-mariadb
Published: Jun 17, 2026
Source: GitHub
CVE-2026-9697 HIGH - 7.4

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-9679 MEDIUM - 5.9

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 ยง5.4 does not specify any decoding and browsers do not decode either. Applications that parse a ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-9678 MEDIUM - 5.9

Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow.This issue affects Connext Professional: from 7.4.0 before 7.*, from 7.0.0 before 7.3.1.3, from 6.1.2 bef...

Published: Jun 17, 2026
Source: NVD
CVE-2026-6734 HIGH - 7.5

Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination. This c...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-6733 LOW - 3.7

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD