Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 61 - 80 of 34,996 CVEs
CVE-2026-56242 HIGH - 7.5

Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the owning user_id for supplied API keys, creating an API key validity oracle and user identity disclosure primitive. Attackers can call this endpoint with valid or invalid API keys ...

Vendor: Capgo
Product: Capgo
Published: Jun 21, 2026
Source: NVD
CVE-2026-56239 HIGH - 7.6

Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which performs sensitive billing operations without enforcing internal authorization checks (no validation of auth.uid(), org membership, or check_min_rights). B...

Vendor: Capgo
Product: Capgo
Published: Jun 21, 2026
Source: NVD
CVE-2026-56236 MEDIUM - 6.1

Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with world-readable permissions wh...

Vendor: capgo
Product: cli
Published: Jun 21, 2026
Source: NVD
CVE-2026-56229 MEDIUM - 6.5

Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access build jobs belonging to different applications by supplying a mismatched app_id and job_id combination. Limited API keys restricted to a single app can ...

Vendor: Capgo
Product: Capgo
Published: Jun 21, 2026
Source: NVD
CVE-2025-71378 HIGH - 8.1

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD
CVE-2025-71357 HIGH - 8.1

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD

picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allowing remote code execution. Attackers can craft pickle files that import dangerous libraries like os and execute arbitrary system commands, which evade picklescan detection and exec...

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD
CVE-2025-71348 HIGH - 8.1

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply...

Vendor: picklescan
Product: picklescan
Published: Jun 21, 2026
Source: NVD
CVE-2026-12799 MEDIUM - 4.3

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization....

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12798 MEDIUM - 6.3

A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of the argument spec_path ...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12797 MEDIUM - 6.3

A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_hooks/banned_keywords.py of the component Completions Interface. The manipulation of the argument prompt results in incorrect authorization. The attack ...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12796 MEDIUM - 6.3

A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation leads to session expiration. The attack is possible to be ca...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12795 HIGH - 7.3

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit...

Vendor: BerriAI
Product: litellm
Published: Jun 21, 2026
Source: NVD
CVE-2026-12789 MEDIUM - 4.7

A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learning Progress Tracking. Such manipulation of the argument troup_table_nav leads to...

Vendor: ILIAS
Product: Learning Management System
Published: Jun 21, 2026
Source: NVD
CVE-2026-12788 MEDIUM - 6.3

A vulnerability was determined in zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to ini...

Vendor: zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ
Product: ADP Application Developer Platform 应用开发者平台
Published: Jun 21, 2026
Source: NVD
CVE-2026-12787 MEDIUM - 6.3

A vulnerability was found in zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization. The attack may be performed from remote. The exploit has be...

Vendor: zhilink 智互联(深圳)η§‘ζŠ€ζœ‰ι™ε…¬εΈ
Product: ADP Application Developer Platform 应用开发者平台
Published: Jun 21, 2026
Source: NVD
CVE-2026-12786 HIGH - 7.8

A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library bootpt64.sys of the component Kernel Driver. The manipulation leads to improper access controls. Local access is required to approach this attack. The...

Vendor: Ezbsystems
Product: UltraISO Premium Edition
Published: Jun 21, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stays set after the call so that the global session lookup in ksmbd_session_lookup_all() can find ...

Vendor: Linux
Product: Linux
Published: Jun 21, 2026
Source: NVD
CVE-2026-12784 HIGH - 7.8

A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the publ...

Vendor: IM-Magic
Product: Partition Resizer
Published: Jun 21, 2026
Source: NVD
CVE-2026-12782 HIGH - 7.8

A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released...

Vendor: EaseUS
Product: Partition Master
Published: Jun 21, 2026
Source: NVD