Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 61 - 80 of 35,345 CVEs
CVE-2025-61029 HIGH - 7.5

An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61024 HIGH - 7.5

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2020-9713 MEDIUM - 5.5

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose se...

Published: Jun 23, 2026
Source: NVD
CVE-2020-9711 MEDIUM - 5.5

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of t...

Published: Jun 23, 2026
Source: NVD
CVE-2020-9695 HIGH - 7.8

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic...

Published: Jun 23, 2026
Source: NVD
CVE-2026-54557 MEDIUM - 5.5

mise HTTP backend uses raw version path for install symlink destination

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub

OctoPrint has possible file exfiltration via query parameters on upload endpoints

Vendor: pip
Product: OctoPrint
Published: Jun 23, 2026
Source: GitHub
CVE-2026-53925 HIGH - 7.8

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

Vendor: pip
Product: glances
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54350 CRITICAL - 10.0

Budibase has nonymous NoSQL operator injection via published-app query templates

Vendor: npm
Product: @budibase/server
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55173 HIGH - 8.1

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

Vendor: composer
Product: wwbn/avideo
Published: Jun 23, 2026
Source: GitHub

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-45049 HIGH - 8.3

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

Vendor: maven
Product: org.openidentityplatform.openam:openam-federation
Published: Jun 23, 2026
Source: GitHub
CVE-2026-45048 HIGH - 8.5

OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jun 23, 2026
Source: GitHub

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

Vendor: GNU
Product: GNU SASL
Published: Jun 23, 2026
Source: NVD
CVE-2026-56117 MEDIUM - 4.7

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege separation is disabled. Attackers can connect to the control socket an...

Vendor: NetworkConfiguration
Product: dhcpcd
Published: Jun 23, 2026
Source: NVD
CVE-2026-56116 MEDIUM - 6.5

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router...

Vendor: NetworkConfiguration
Product: dhcpcd
Published: Jun 23, 2026
Source: NVD
CVE-2026-56115 MEDIUM - 5.3

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. At...

Vendor: NetworkConfiguration
Product: dhcpcd
Published: Jun 23, 2026
Source: NVD
CVE-2026-56114 MEDIUM - 5.3

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. At...

Vendor: NetworkConfiguration
Product: dhcpcd
Published: Jun 23, 2026
Source: NVD
CVE-2026-56113 MEDIUM - 5.3

dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting...

Vendor: NetworkConfiguration
Product: dhcpcd
Published: Jun 23, 2026
Source: NVD

The XMLโ€‘RPC API addUser method has a validation bypass introduced in the fix for CVEโ€‘2025โ€‘55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.

Vendor: Revive
Product: Adserver
Published: Jun 23, 2026
Source: NVD