Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
Showing 761 - 780 of 12,815 CVEs
CVE-2025-59133 HIGH - 7.5

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

Vendor: Projectopia
Product: Projectopia
Published: Jun 15, 2026
Source: NVD
CVE-2026-54283 HIGH - 7.5

Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

Vendor: pip
Product: starlette
Published: Jun 15, 2026
Source: GitHub

Nest: Middleware Bypass on Fastify via Trailing Slash

Vendor: npm
Product: @nestjs/platform-fastify
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53539 HIGH - 7.5

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

Vendor: pip
Product: python-multipart
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49853 HIGH - 7.7

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

Vendor: pip
Product: tornado
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49855 HIGH - 7.5

tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

Vendor: pip
Product: tornado
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53705 HIGH - 7.6

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack libra...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-53704 HIGH - 7.1

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets r...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-53703 HIGH - 7.1

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sa...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-52722 HIGH - 7.1

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-52720 HIGH - 8.8

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-52719 HIGH - 7.1

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, cau...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 15, 2026
Source: NVD
CVE-2026-50891 HIGH - 8.1

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

Published: Jun 15, 2026
Source: NVD
CVE-2026-50889 HIGH - 7.5

An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.

Vendor: lldap
Product: lldap
Published: Jun 15, 2026
Source: NVD
CVE-2026-50888 HIGH - 8.1

An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.

Published: Jun 15, 2026
Source: NVD
CVE-2026-50885 HIGH - 7.5

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.

Published: Jun 15, 2026
Source: NVD
CVE-2026-50884 HIGH - 8.8

Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.

Published: Jun 15, 2026
Source: NVD
CVE-2026-50882 HIGH - 7.5

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

Published: Jun 15, 2026
Source: NVD
CVE-2026-50881 HIGH - 8.1

Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.

Published: Jun 15, 2026
Source: NVD
CVE-2026-48818 HIGH - 7.5

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service accountโ€™s NTLMv...

Vendor: pip
Product: starlette
Published: Jun 15, 2026
Source: GitHub