Total CVEs

148,723

Critical Severity

4,730

High Severity

16,902

Last 7 Days

3,069
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,181 - 7,200 of 45,128 CVEs

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.

Vendor: pion
Product: dtls
Published: Jul 01, 2026
Source: NVD
CVE-2026-54164 MEDIUM - 6.5

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unin...

Vendor: api-platform
Product: core
Published: Jul 01, 2026
Source: NVD
CVE-2026-49858 MEDIUM - 5.9

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per requ...

Vendor: api-platform
Product: core, api-platform/hal, api-platform/json-api
Published: Jul 01, 2026
Source: NVD
CVE-2026-14363 CRITICAL - 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

Vendor: The Wikimedia Foundation
Product: Mediawiki - Cargo Extension
Published: Jul 01, 2026
Source: NVD
CVE-2026-14265 HIGH - 7.5

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted...

Vendor: AWS
Product: AWS Advanced JDBC Wrapper
Published: Jul 01, 2026
Source: NVD
CVE-2026-48815 HIGH - 7.5

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications rely...

Vendor: npm
Product: sigstore
Published: Jul 01, 2026
Source: GitHub
CVE-2026-48816 MEDIUM - 6.5

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind i...

Vendor: npm
Product: @sigstore/verify
Published: Jul 01, 2026
Source: GitHub

CrateDB's Blob HTTP handler bypasses authorization

Vendor: maven
Product: io.crate:crate
Published: Jul 01, 2026
Source: GitHub

Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.

Vendor: The Wikimedia Foundation
Product: Mediawiki - WikiLambda Extension
Published: Jul 01, 2026
Source: NVD
CVE-2026-58451 MEDIUM - 6.5

Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding traversal sequences after a CKEditor path prefix in img src URLs. Attackers can bypass the stripos() prefix validation...

Vendor: horde
Product: imp
Published: Jul 01, 2026
Source: NVD
CVE-2026-55628 MEDIUM - 5.5

In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.

Vendor: ImageMagick
Product: ImageMagick
Published: Jul 01, 2026
Source: NVD
CVE-2026-55597 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.

Vendor: imagemagick
Product: imagemagick
Published: Jul 01, 2026
Source: NVD
CVE-2026-55595 MEDIUM - 4.7

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

Vendor: imagemagick
Product: imagemagick
Published: Jul 01, 2026
Source: NVD
CVE-2026-55594 MEDIUM - 5.3

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1....

Vendor: imagemagick
Product: imagemagick
Published: Jul 01, 2026
Source: NVD
CVE-2026-55577 MEDIUM - 5.9

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions...

Vendor: imagemagick
Product: imagemagick
Published: Jul 01, 2026
Source: NVD
CVE-2026-55510 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in versions 6.9.13-51 an...

Vendor: imagemagick
Product: imagemagick
Published: Jul 01, 2026
Source: NVD
CVE-2026-53492 CRITICAL - 9.6

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoi...

Vendor: linuxfoundation
Product: containerd
Published: Jul 01, 2026
Source: NVD
CVE-2026-53489 MEDIUM - 6.5

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has ...

Vendor: linuxfoundation
Product: containerd
Published: Jul 01, 2026
Source: NVD
CVE-2026-53467 MEDIUM - 5.3

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions ...

Vendor: imagemagick
Product: imagemagick
Published: Jul 01, 2026
Source: NVD
CVE-2026-53466 MEDIUM - 6.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixe...

Vendor: imagemagick
Product: imagemagick
Published: Jul 01, 2026
Source: NVD