Total CVEs

148,862

Critical Severity

4,746

High Severity

16,954

Last 7 Days

3,075
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,121 - 8,140 of 45,267 CVEs
CVE-2026-55219 MEDIUM - 5.3

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction. Because MySQL/MariaDB ...

Vendor: composer
Product: paymenter/paymenter
Published: Jun 30, 2026
Source: GitHub
CVE-2026-48808 MEDIUM - 7.5

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic propert...

Vendor: composer
Product: twig/twig
Published: Jun 30, 2026
Source: GitHub
CVE-2026-48807 MEDIUM - 9.1

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the s...

Vendor: composer
Product: twig/twig
Published: Jun 30, 2026
Source: GitHub
CVE-2026-48806 MEDIUM - 9.1

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in ve...

Vendor: composer
Product: twig/twig
Published: Jun 30, 2026
Source: GitHub

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arr...

Vendor: composer
Product: twig/twig
Published: Jun 30, 2026
Source: GitHub
CVE-2026-49835 MEDIUM - 5.9

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an una...

Vendor: go
Product: github.com/sigstore/timestamp-authority/v2
Published: Jun 30, 2026
Source: GitHub
CVE-2026-49478 HIGH - 8.7

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

Vendor: go
Product: github.com/sigstore/fulcio
Published: Jun 30, 2026
Source: GitHub
CVE-2026-48796 MEDIUM - 5.3

CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder

Vendor: nuget
Product: CefSharp.Common
Published: Jun 30, 2026
Source: GitHub
CVE-2026-48795 HIGH - 8.6

AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via @poppinss/utils to crea...

Vendor: npm
Product: @adonisjs/bodyparser
Published: Jun 30, 2026
Source: GitHub
CVE-2026-49820 MEDIUM - 4.7

Probo has an open redirect bypass via path normalization

Vendor: go
Product: go.probo.inc/probo
Published: Jun 30, 2026
Source: GitHub

Sigstore Java has a vulnerability with bundle verification of integratedTime

Vendor: maven
Product: dev.sigstore:sigstore-java
Published: Jun 30, 2026
Source: GitHub
CVE-2026-49473 HIGH - 8.8

@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation

Vendor: npm
Product: @cedar-policy/authorization-for-expressjs
Published: Jun 30, 2026
Source: GitHub
CVE-2026-9263 MEDIUM - 6.5

The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per the Bluetooth specification a start segment (sc=0) always carries a 3-byte time_offset, so its segment-header len must be at leas...

Vendor: zephyrproject
Product: zephyr
Published: Jun 30, 2026
Source: NVD

The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released to mitigate this potential vulnerability.

Published: Jun 30, 2026
Source: NVD
CVE-2026-58377 HIGH - 8.1

JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController endpoints which lack Shiro au...

Vendor: jeecgboot
Product: JeecgBoot
Published: Jun 30, 2026
Source: NVD
CVE-2026-58376 HIGH - 7.6

Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictionary and multicurrencies REST API endpoints. The a...

Vendor: Dolibarr
Product: dolibarr
Published: Jun 30, 2026
Source: NVD
CVE-2026-58375 HIGH - 7.5

JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so JimuReportTokenInterceptor skips all authentication and authorization, and the export service streams the rendered report for any supplied report id with...

Vendor: jeecgboot
Product: jimureport
Published: Jun 30, 2026
Source: NVD
CVE-2026-58373 MEDIUM - 4.3

CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter...

Vendor: cvat-ai
Product: cvat
Published: Jun 30, 2026
Source: NVD
CVE-2026-58372 HIGH - 8.1

SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../ sequences in th...

Vendor: seaweedfs
Product: seaweedfs
Published: Jun 30, 2026
Source: NVD

SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application/javascript in the shared writeJson helper (weed/server/common.go), with no callback-name validation, no X-Content-Type-Options: nosniff header, and no CORS allow-list. Every JSON ...

Vendor: seaweedfs
Product: seaweedfs
Published: Jun 30, 2026
Source: NVD