Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,277
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 701 - 720 of 35,853 CVEs
CVE-2026-49229 HIGH - 8.3

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

Vendor: npm
Product: @actual-app/sync-server
Published: Jun 22, 2026
Source: GitHub

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-54232 HIGH - 8.8

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using --extra-index-url, but the p...

Vendor: vllm-project
Product: vllm
Published: Jun 22, 2026
Source: NVD
CVE-2026-50136 HIGH - 7.4

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-50132 HIGH - 7.3

Budibase has an Account Impersonation Issue โ€” Chat Identity Link Hijacking via Missing Consent & CSRF

Vendor: npm
Product: @budibase/server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-48487 MEDIUM - 6.5

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

Vendor: pip
Product: zeroconf
Published: Jun 22, 2026
Source: GitHub
CVE-2026-48170 CRITICAL - 9.1

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

Vendor: npm
Product: scim-patch
Published: Jun 22, 2026
Source: GitHub
CVE-2026-47267 MEDIUM - 8.3

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is ...

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-56698 MEDIUM - 6.1

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supply javascript: URLs through the open parameter to execute arbitrary scripts in the application's origin when user-c...

Vendor: Nuxt
Product: Nuxt
Published: Jun 22, 2026
Source: NVD
CVE-2026-56697 MEDIUM - 6.1

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but resolve to a cross-origin URL against the current page protocol. Attackers can inject paths like //evil.com to redirect use...

Vendor: Nuxt
Product: Nuxt
Published: Jun 22, 2026
Source: NVD
CVE-2026-56357 MEDIUM - 4.0

n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data, spoofing GitHub webhook e...

Vendor: n8n
Product: n8n
Published: Jun 22, 2026
Source: NVD
CVE-2026-56348 CRITICAL - 9.1

n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with cre...

Vendor: n8n
Product: n8n
Published: Jun 22, 2026
Source: NVD
CVE-2026-56326 MEDIUM - 6.1

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like /..//evil.com and /.//evil.com. Attackers can bypass external-host checks using path-normalization techniques to redire...

Vendor: Nuxt
Product: Nuxt
Published: Jun 22, 2026
Source: NVD
CVE-2026-56324 HIGH - 8.2

Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by rotating the user-controlled device_id parameter. Attackers can send multiple requests per second by changing device_id values to flood the channel_devic...

Vendor: Capgo
Product: Capgo
Published: Jun 22, 2026
Source: NVD
CVE-2026-56323 HIGH - 7.5

Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and determine app existence and subscription status. Remote attackers can send GET requests with arbitrary app...

Vendor: Capgo
Product: Capgo
Published: Jun 22, 2026
Source: NVD
CVE-2026-56321 MEDIUM - 5.3

Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id endpoint, unlike the POST and DELETE role_bindings routes, so unauthenticated requests reach the handler instead of being rejected at the middleware l...

Vendor: Capgo
Product: Capgo
Published: Jun 22, 2026
Source: NVD
CVE-2026-56314 HIGH - 7.1

Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing app_versions.deleted filter in channel version joins.

Vendor: Capgo
Product: Capgo
Published: Jun 22, 2026
Source: NVD
CVE-2026-56311 MEDIUM - 5.3

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function that allows unauthenticated attackers to retrieve arbitrary organization plan limits. Attackers can call the RPC endpoint with any organization UUID using only the public Supabase...

Vendor: Capgo
Product: Capgo
Published: Jun 22, 2026
Source: NVD
CVE-2026-56306 MEDIUM - 6.4

Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypass subkey enforcement by submitting malformed values, zero, or duplicate headers that result in NaN or falsy values. Remote attackers can manipulate the x-limited-key-id header to ...

Vendor: Capgo
Product: Capgo
Published: Jun 22, 2026
Source: NVD
CVE-2026-56280 HIGH - 7.1

Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE stream that unconditionally invokes cancelBuildOnDisconnect() using the privileged ...

Vendor: Cap-go
Product: capgo
Published: Jun 22, 2026
Source: NVD