Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 721 - 740 of 12,942 CVEs
CVE-2026-53736 MEDIUM - 4.3

Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type.

Vendor: bplugins
Product: Easy Twitter Feeds
Published: Jun 10, 2026
Source: NVD
CVE-2026-53634 MEDIUM - 4.3

Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity c...

Vendor: code16
Product: sharp
Published: Jun 10, 2026
Source: NVD
CVE-2026-48108 MEDIUM - 5.3

Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, the server-side identification reader used the same permissive path as the client, allowing pre-b...

Vendor: Eugeny
Product: russh
Published: Jun 10, 2026
Source: NVD
CVE-2026-48107 MEDIUM - 6.5

Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count dir...

Vendor: Eugeny
Product: russh
Published: Jun 10, 2026
Source: NVD
CVE-2026-45384 MEDIUM - 6.1

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in version 4.0.12.

Vendor: rikyoz
Product: bit7z
Published: Jun 10, 2026
Source: NVD
CVE-2026-47768 MEDIUM - 5.5

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub

PDM: Project-Local State and Config Writes Follow Symlinks

Vendor: pip
Product: pdm
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50127 MEDIUM - 5.9

Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictio...

Vendor: WeblateOrg
Product: weblate
Published: Jun 10, 2026
Source: NVD

Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)

Vendor: go
Product: github.com/lxc/incus/v7
Published: Jun 10, 2026
Source: GitHub

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Vendor: actions
Product: anthropics/claude-code-action
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50639 MEDIUM - 6.5

Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::...

Vendor: PEVANS
Product: Metrics::Any::Adapter::SignalFx
Published: Jun 10, 2026
Source: NVD
CVE-2026-10740 MEDIUM - 5.3

Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate this issue, users should upgrade to v1.8.2.

Vendor: AWS
Product: s2n-quic
Published: Jun 10, 2026
Source: NVD
CVE-2026-48061 MEDIUM - 5.9

Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header

Vendor: pip
Product: litestar
Published: Jun 10, 2026
Source: GitHub

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub

nebula-mesh: Decrypted CA private key persists in heap after signing

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 10, 2026
Source: GitHub
CVE-2026-50569 MEDIUM - 4.3

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeUR...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-50565 MEDIUM - 4.9

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-builder and no AutomountServiceAccountToken: false, so the kubelet...

Vendor: fission
Product: fission
Published: Jun 10, 2026
Source: NVD
CVE-2026-46642 MEDIUM - 6.1

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file can execute arbitrary JavaScript in the editor's origin when the file is opened. The vulnerability is not in the label sanitizer (which works correctly on the rendering path) bu...

Vendor: jgraph
Product: drawio
Published: Jun 10, 2026
Source: NVD
CVE-2026-20260 MEDIUM - 4.3

In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files through specially crafted HTTP request paths, which a terminal emulator might int...

Vendor: Splunk
Product: Splunk SOAR
Published: Jun 10, 2026
Source: NVD
CVE-2026-20259 MEDIUM - 5.5

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign s...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Jun 10, 2026
Source: NVD