Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,908
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 61 - 80 of 12,906 CVEs
CVE-2026-54319 MEDIUM - 4.2

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox โ€” cross-tenant data access and host escape

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56024 MEDIUM - 6.5

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.

Vendor: Saad Iqbal
Product: WP EasyPay
Published: Jun 18, 2026
Source: NVD
CVE-2026-56022 MEDIUM - 5.3

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-56021 MEDIUM - 5.3

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-55205 MEDIUM - 5.3

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and th...

Vendor: nesquena
Product: hermes-webui
Published: Jun 18, 2026
Source: NVD
CVE-2026-54106 MEDIUM - 4.7

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass net...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-54105 MEDIUM - 5.3

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the 'update-profile/' API endpoint. A remote, unauthenticated attacker can...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-11791 MEDIUM - 5.0

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload whi...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 18, 2026
Source: NVD
CVE-2026-55093 MEDIUM - 6.1

tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load

Vendor: rust
Product: tract-nnef
Published: Jun 18, 2026
Source: GitHub

opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver
Published: Jun 18, 2026
Source: GitHub

Kirby: Access to files of top-level drafts is not protected by permissions

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Request header injection in `Http\Remote`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub
CVE-2026-47256 MEDIUM - 5.3

opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55890 MEDIUM - 4.8

Grav: Stored CSS injection via Markdown image ?style=โ€ฆ reaches MediaObjectTrait::style() โ€” incomplete patch of GHSA-r7fx-8g49-7hhr

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55885 MEDIUM - 6.8

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Vendor: composer
Product: getgrav/grav
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55686 MEDIUM - 5.3

Podman: WORKDIR symlink traversal vulnerability

Vendor: go
Product: github.com/containers/podman/v5
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56009 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83.

Vendor: Bricksable
Product: Bricksable for Bricks Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-56007 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS. This issue affects Ocean Product Sharing: from n/a through 2.2.2.

Vendor: OceanWP
Product: Ocean Product Sharing
Published: Jun 18, 2026
Source: NVD
CVE-2026-44942 MEDIUM - 6.5

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

Vendor: SUSE
Product: libzypp
Published: Jun 18, 2026
Source: NVD