Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 881 - 900 of 35,345 CVEs
CVE-2026-55672 HIGH - 7.4

ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)

Vendor: go
Product: github.com/zitadel/zitadel
Published: Jun 18, 2026
Source: GitHub

SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.

Published: Jun 18, 2026
Source: NVD
CVE-2026-8039 MEDIUM - 6.4

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possibl...

Published: Jun 18, 2026
Source: NVD

8cc is vulnerable to an Outโ€‘ofโ€‘Bounds Read due to improper handling of #line directives and GNU linemarkers. The compiler accepts attacker-controlled filename and line number metadata and later uses it without validation when accessing source line arrays. By supplying invalid or oversized line numbe...

Vendor: rui314
Product: 8cc
Published: Jun 18, 2026
Source: NVD
CVE-2026-2021 MEDIUM - 6.4

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it p...

Published: Jun 18, 2026
Source: NVD

Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed AWS credentials authent...

Vendor: Silver Leaf Technologies, Inc.
Product: Worksnaps.net Worksnaps
Published: Jun 18, 2026
Source: NVD

ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers

Vendor: go
Product: github.com/zitadel/zitadel
Published: Jun 18, 2026
Source: GitHub

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

Vendor: npm
Product: tinacms
Published: Jun 18, 2026
Source: GitHub

Hydro: Insufficient session expiration when recreating sessions

Vendor: npm
Product: hydrooj
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55603 HIGH - 7.5

http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the outgoing Content-Type is multipart/form-data, it rebuilds the body wi...

Vendor: npm
Product: http-proxy-middleware
Published: Jun 18, 2026
Source: GitHub

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request met...

Vendor: npm
Product: http-proxy-middleware
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55254 MEDIUM - 4.8

NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation

Vendor: nuget
Product: NCalc.Core
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55388 HIGH - 8.1

piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller's options object doesn't have filename as an own ...

Vendor: npm
Product: piscina
Published: Jun 18, 2026
Source: GitHub

Docker MCP Gateway: Argument injection via OCI image label YAML

Vendor: go
Product: github.com/docker/mcp-gateway
Published: Jun 18, 2026
Source: GitHub

jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()

Vendor: npm
Product: jodit
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55229 HIGH - 7.5

Gotenberg: SSRF via LibreOffice document processing

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55226 MEDIUM - 5.4

Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator

Vendor: maven
Product: io.strimzi:strimzi
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55225 HIGH - 8.0

Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`

Vendor: maven
Product: io.strimzi:strimzi
Published: Jun 18, 2026
Source: GitHub
CVE-2026-9815 MEDIUM - 6.5

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.

Published: Jun 18, 2026
Source: NVD
CVE-2026-55746 HIGH - 7.6

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip or encode HTML (the tag check in cot_import is disabled), so an authenti...

Vendor: Cotonti
Product: Cotonti
Published: Jun 18, 2026
Source: NVD