Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 761 - 780 of 35,345 CVEs

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 18, 2026
Source: NVD

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method ent...

Published: Jun 18, 2026
Source: NVD

Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standar...

Published: Jun 18, 2026
Source: NVD
CVE-2026-54130 CRITICAL - 9.8

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-49205 MEDIUM - 6.5

phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4 other write endpo...

Vendor: thorsten
Product: phpMyFAQ
Published: Jun 18, 2026
Source: NVD
CVE-2026-47647 CRITICAL - 9.9

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-47633 HIGH - 7.5

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-32174 HIGH - 7.7

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-22674 MEDIUM - 4.8

Hashgraph Guardian through 3.5.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers...

Vendor: hashgraph
Product: guardian
Published: Jun 18, 2026
Source: NVD
CVE-2026-49454 CRITICAL - 9.1

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified before the library returned a successful authentication result. The XMLDSig trust boundary was inco...

Vendor: szTheory
Product: relyra
Published: Jun 18, 2026
Source: NVD
CVE-2026-49257 CRITICAL - 10.0

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including SQL query execution, schema creation, and ta...

Vendor: startreedata
Product: mcp-pinot
Published: Jun 18, 2026
Source: NVD
CVE-2026-49252 CRITICAL - 9.9

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write permission to any record...

Vendor: deepstreamIO
Product: deepstream.io
Published: Jun 18, 2026
Source: NVD

OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the target is an absolute path. A subsequent file entry in the same archive traverses the symlink, writing t...

Vendor: theonedev
Product: onedev
Published: Jun 18, 2026
Source: NVD
CVE-2026-46699 HIGH - 7.6

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.61.0, a vulnerability in the conda-forge automated webservices allowed unintended write access to feedstock repositories through GitHub userna...

Vendor: conda-forge
Product: conda-smithy
Published: Jun 18, 2026
Source: NVD

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The ht_undo_im...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Jun 18, 2026
Source: NVD
CVE-2026-44663 MEDIUM - 6.1

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl() in src/lib/OpenEXRCore/internal_ht.cpp leads to a heap-buffer overflow when decoding a crafted HTJ2K...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Jun 18, 2026
Source: NVD
CVE-2026-43994 HIGH - 8.1

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth access token (0-65535) is passed directly to memcpy() as the copy length into a 2...

Vendor: coturn
Product: coturn
Published: Jun 18, 2026
Source: NVD
CVE-2025-15661 MEDIUM - 6.5

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME respons...

Vendor: libssh2
Product: libssh2
Published: Jun 18, 2026
Source: NVD
CVE-2026-55591 MEDIUM - 5.8

Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints

Vendor: npm
Product: signalk-server
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56099 MEDIUM - 5.3

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

Vendor: openbsd
Product: src
Published: Jun 18, 2026
Source: NVD