Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,428
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 81 - 100 of 35,847 CVEs

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML integration does not verify the signature on inbound LogoutRequest messages. An unauthenticated remote attacker who knows...

Vendor: RocketChat
Product: Rocket.Chat
Published: Jun 24, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. Due to a flawed admin-existence check, the endpoint remains usable after an administrator already exis...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 24, 2026
Source: NVD
CVE-2026-33235 HIGH - 7.7

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block is vulnerable to a Denial of Service (DoS) attack. While the backend implements a SandboxedEnvironment to prevent unaut...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 24, 2026
Source: NVD
CVE-2026-1840 HIGH - 7.5

The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter operational parameters and trigger system restarts without res...

Published: Jun 24, 2026
Source: NVD
CVE-2026-13208 MEDIUM - 6.5

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through ...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 24, 2026
Source: NVD
CVE-2026-13201 MEDIUM - 5.2

A flaw was found in KubeVirt's safepath package. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream helpers operate via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it, defeating the...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 24, 2026
Source: NVD
CVE-2026-11998 HIGH - 7.6

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to ensure that only trusted or safe values are used...

Vendor: Google
Product: AngularJS
Published: Jun 24, 2026
Source: NVD
CVE-2026-55583 HIGH - 7.6

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the AI agent monitor's AgentTurnResolver, in packages/twenty-server/src/engine/metadata-modules/ai/ai-agent-monitor/res...

Vendor: twentyhq
Product: twenty
Published: Jun 24, 2026
Source: NVD
CVE-2026-48028 MEDIUM - 6.5

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing threat acto...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-47389 HIGH - 8.6

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressCheck.private_address? returns false for IPv4-mapped IPv6 addresses (::ffff:a.b.c.d) corresponding to some private IPv4 addresses, d...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD
CVE-2026-46349 MEDIUM - 5.3

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data Signatures does not sufficiently protect the activities from a certain class of spoofing, allowing attackers t...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ranges was lacking an IP address range that can be used to reach local IP addresses. An attacker can use an IP address in the affected range to make Mast...

Vendor: mastodon
Product: mastodon
Published: Jun 24, 2026
Source: NVD

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated client owns it, potentially exposing cross-client...

Vendor: FOSSBilling
Product: FOSSBilling
Published: Jun 24, 2026
Source: NVD
CVE-2026-23879 HIGH - 8.0

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious sy...

Vendor: miurahr
Product: py7zr
Published: Jun 24, 2026
Source: NVD
CVE-2026-53950 HIGH - 7.5

@tryghost/activitypub is Ghostโ€™s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53949 MEDIUM - 5.3

Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully acces...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53948 MEDIUM - 5.4

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On ins...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53947 MEDIUM - 5.3

Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site. This vulnerability is fixed...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53946 MEDIUM - 5.4

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card โ€” without restricting that URL to trusted image hosts. An authenticated staff user able...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD
CVE-2026-53945 MEDIUM - 4.0

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghostโ€™s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This ...

Vendor: TryGhost
Product: Ghost
Published: Jun 24, 2026
Source: NVD