Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 61 - 80 of 35,133 CVEs

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 22, 2026
Source: NVD
CVE-2026-10789 CRITICAL - 9.6

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user...

Vendor: Autodesk
Product: Fusion
Published: Jun 22, 2026
Source: NVD
CVE-2026-33684 MEDIUM - 5.3

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

Vendor: composer
Product: wwbn/avideo
Published: Jun 22, 2026
Source: GitHub
CVE-2026-33646 CRITICAL - 9.6

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

Vendor: rust
Product: mise
Published: Jun 22, 2026
Source: GitHub
CVE-2026-32315 MEDIUM - 5.5

motionEye's World-Readable Configuration File Exposes Admin Password Hash

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub
CVE-2026-31978 MEDIUM - 6.5

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2025-64719 MEDIUM - 4.9

Gogs has a Denial of Service in repository/wiki file listing web pages

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-9610 LOW - 2.3

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.

Published: Jun 22, 2026
Source: NVD
CVE-2026-9320 MEDIUM - 5.9

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resour...

Published: Jun 22, 2026
Source: NVD
CVE-2026-9072 HIGH - 8.1

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an...

Published: Jun 22, 2026
Source: NVD
CVE-2026-9071 HIGH - 7.5

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resour...

Published: Jun 22, 2026
Source: NVD
CVE-2026-9006 HIGH - 7.4

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.

Published: Jun 22, 2026
Source: NVD

A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on...

Published: Jun 22, 2026
Source: NVD
CVE-2026-8858 HIGH - 7.5

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application s...

Published: Jun 22, 2026
Source: NVD
CVE-2026-8823 LOW - 3.8

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669

Published: Jun 22, 2026
Source: NVD
CVE-2026-8646 HIGH - 7.4

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security contr...

Published: Jun 22, 2026
Source: NVD
CVE-2026-8636 MEDIUM - 5.5

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

Published: Jun 22, 2026
Source: NVD
CVE-2026-8059 MEDIUM - 6.1

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...

Published: Jun 22, 2026
Source: NVD
CVE-2026-7664 CRITICAL - 9.8

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Published: Jun 22, 2026
Source: NVD