Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,781 - 6,800 of 35,345 CVEs
CVE-2026-9208 HIGH - 8.8

Tanium addressed an unauthorized code execution vulnerability in Connect.

Vendor: tanium
Product: connect
Published: May 27, 2026
Source: NVD

AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username

Vendor: pip
Product: asyncssh
Published: May 27, 2026
Source: GitHub

Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex

Vendor: composer
Product: symfony/yaml
Published: May 27, 2026
Source: GitHub

Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")

Vendor: composer
Product: symfony/yaml
Published: May 27, 2026
Source: GitHub

Symfony hardened the parser when handling untrusted input

Vendor: composer
Product: symfony/yaml
Published: May 27, 2026
Source: GitHub
CVE-2026-45332 HIGH - 7.5

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collectio...

Vendor: composer
Product: automad/automad
Published: May 27, 2026
Source: GitHub
CVE-2026-47270 MEDIUM - 6.3

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb is a PAM module loaded into the host process (sudo, login, GDM, GNOME Shell). Display managers such as GDM run multiple concurrent authentication threads. Three functions used by the deny_remot...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-47269 HIGH - 7.4

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb's deny_remote feature checks utmpx ut_addr_v6 to detect whether an authentication request originates from a remote session. The outer guard was if (utent->ut_addr_v6[0] != 0), which on...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44713 HIGH - 8.8

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment variable, splits it on commas, and interpolates the socket-path component directly into a shell command passed to popen(). Because the value is placed...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44712 HIGH - 8.2

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-conf --reset-pads is run. A USB device with a crafted filesystem UUID (some controllers allow this) can inject the pay...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44711 HIGH - 7.9

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44710 MEDIUM - 4.6

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed the return values of udisks_drive_get_serial(), udisks_drive_get_vendor(), and udisks_drive_get_model() directly to strcmp() without NULL checks. The GIO/UDisks API documentation st...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44709 HIGH - 7.8

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set environment variables before pamusb-pinentry is invoked ca...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-21785 MEDIUM - 4.0

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

Vendor: HCLSoftware
Product: BigFix Remote Control Server
Published: May 27, 2026
Source: NVD

Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener

Vendor: composer
Product: symfony/monolog-bridge
Published: May 27, 2026
Source: GitHub

Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]

Vendor: composer
Product: symfony/http-kernel
Published: May 27, 2026
Source: GitHub

Symfony's Cas2Handler Derives CAS service URL from Client Host Header โ†’ Cross-Service Ticket Replay

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix

Vendor: composer
Product: symfony/cache
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() โ€” Unescaped Non-PHP File Rendering

Vendor: composer
Product: symfony/symfony
Published: May 27, 2026
Source: GitHub

Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true

Vendor: composer
Product: symfony/dom-crawler
Published: May 27, 2026
Source: GitHub