Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 81 - 100 of 35,861 CVEs
CVE-2026-10043 HIGH - 7.8

MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MosaicML Composer. User interaction is required to exploit this vulnerability in that the target must visit a mal...

Vendor: MosaicML
Product: Composer
Published: Jun 24, 2026
Source: NVD

GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580): function gf_filter_pid_inst_swap_delete_task() improperly accesses free...

Published: Jun 24, 2026
Source: NVD

A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability.

Published: Jun 24, 2026
Source: NVD
CVE-2026-52795 MEDIUM - 4.3

Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private repository they have no access to, because the access check in the Watch API handler is inverted. The code checks if repoCtx.ViewerCanRead() (returns 404 when the user CAN read) instead ...

Vendor: gogs
Product: gogs
Published: Jun 24, 2026
Source: NVD
CVE-2026-50129 HIGH - 7.5

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability), due to missing exception handling in the math sanitizer. Malformed <math> nodes can result in a DoS of a whole server or...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-50128 MEDIUM - 5.3

Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of their articles. To prevent false attribution claims, Mastodon uses the attributionDomains JSON-LD term, however, an error in how it...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-49278 MEDIUM - 6.7

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by-id-1, token is returned in the response. It looks...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or refresh tokens when a user is deactivated. A deactivated user can continue using an existing OAuth ac...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD
CVE-2026-47733 MEDIUM - 4.4

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a href> and <img src> attributes without protocol sanitization. Unlike the analogous LinkS...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML service provider implementation silently skips both SAML Response and Assertion signature validation when the configured ...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued login tokens. A user that an administrator has mar...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD
CVE-2026-45689 CRITICAL - 9.1

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with Mongo...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD
CVE-2026-45688 CRITICAL - 9.1

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards the client-supplied options.cas.credentialToken value straight into a MongoDB findOne({_id: ...}) q...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD
CVE-2026-45687 HIGH - 8.5

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes the entire attacker-supplied file object into Uploads.updateFileComplete, which merges it di...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML integration does not verify the signature on inbound LogoutRequest messages. An unauthenticated remote attacker who knows...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. Due to a flawed admin-existence check, the endpoint remains usable after an administrator already exis...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 24, 2026
Source: NVD
CVE-2026-33235 HIGH - 7.7

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block is vulnerable to a Denial of Service (DoS) attack. While the backend implements a SandboxedEnvironment to prevent unaut...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 24, 2026
Source: NVD
CVE-2026-1840 HIGH - 7.5

The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter operational parameters and trigger system restarts without res...

Published: Jun 24, 2026
Source: NVD
CVE-2026-13208 MEDIUM - 6.5

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through ...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 24, 2026
Source: NVD
CVE-2026-13201 MEDIUM - 5.2

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kern...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 24, 2026
Source: NVD