Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,434
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 841 - 860 of 33,646 CVEs

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_group_id to a sharing group they were not authorized to use. When distribution was set to sharing group distribution, the n...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD

An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown was populated using the attacker-controlled AuthKey.user_id value from the submitted request data. An authenticated user with permis...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD

MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScript handler using HTML escaping inside a single-quoted JavaScript string. Because browsers HTML-decode attribute values before JavaScript parsing, a craf...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and uuid without ensuring that the resolved file remains inside the intended APP/files/img/orgs/ directo...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD

A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypassing the normal setSetting() validation logic, including validate_homepage, which requires homepage ...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD

An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have been visible to their organisation. The custom access-control condition intended to restrict galaxies to those owned by the user’s organisation or dis...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD
CVE-2026-54057 HIGH - 7.8

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue.

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD
CVE-2026-54056 HIGH - 7.6

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote `text/uri-list` drops are staged in a temporary directory, but on case-sensiti...

Vendor: kovidgoyal
Product: kitty
Published: Jun 12, 2026
Source: NVD

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a documented SEO feature for serving uploaded files at clean URLs), the public pretty-URL handler builds the upstream URL using the ...

Vendor: apostrophecms
Product: apostrophe
Published: Jun 12, 2026
Source: NVD
CVE-2026-53606 MEDIUM - 5.4

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the `na...

Vendor: apostrophecms
Product: sanitize-html
Published: Jun 12, 2026
Source: NVD
CVE-2026-4870 HIGH - 7.5

IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion in the parser.

Vendor: ibm
Product: qiskit_software_development_kit
Published: Jun 12, 2026
Source: NVD
CVE-2026-47264 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag group a tag belonged to without filtering against the requesting use...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-47263 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for /web_hook_events/<id> in Jobs::RedeliverWebHookEvents did not pass group_ids, leaving t...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-45775 MEDIUM - 6.8

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability in Discourse backup handling could allow an authenticated administrator on one site in a multi...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-45085 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in the chat plugin (one also involving discourse-calendar): read-only category users cou...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting via unsanitized user display name in draft version tooltip. As of time of publication, no known patched versions are available.

Vendor: apostrophecms
Product: apostrophe
Published: Jun 12, 2026
Source: NVD
CVE-2026-44786 HIGH - 7.5

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public category channels are published to MessageBus without permission scoping, so any MessageBus subscriber...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44785 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper only checks can_see? on the post being explained, not its reply_to_post, so any authenticat...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44784 MEDIUM - 6.5

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are not necessarily admins or moderators can view a group's outgoing email/SMTP credentials in plaintex...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD
CVE-2026-44783 MEDIUM - 5.4

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to whisper posts are handled allows authenticated users outside the groups configured in whispers_allow...

Vendor: discourse
Product: discourse
Published: Jun 12, 2026
Source: NVD