Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,422
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 981 - 1,000 of 33,646 CVEs

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub
CVE-2026-48121 MEDIUM - 6.7

LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access

Vendor: npm
Product: @langchain/langgraph-checkpoint-mongodb
Published: Jun 12, 2026
Source: GitHub

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Vendor: go
Product: github.com/jpillora/chisel
Published: Jun 12, 2026
Source: GitHub

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD
CVE-2026-49993 MEDIUM - 5.7

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspa...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Published: Jun 12, 2026
Source: NVD
CVE-2026-12066 HIGH - 7.3

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery...

Product: PbootCMS
Published: Jun 12, 2026
Source: NVD

A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the attack on the physical de...

Vendor: Groww
Product: Stock, Mutual Fund, Gold App
Published: Jun 12, 2026
Source: NVD

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv library from that location during startup, an att...

Vendor: Mobatek
Product: MobaXterm Personal Edition (Portable)
Published: Jun 12, 2026
Source: NVD

MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resort...

Vendor: Mobatek
Product: MobaXterm Personal Edition (Portable)
Published: Jun 12, 2026
Source: NVD
CVE-2017-20240 MEDIUM - 5.9

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

Vendor: ARODLAND
Product: Crypt::PBKDF2
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. The latest release still creates a new database ticket and Discord channel for every completed ticket modal submission, without checking whether the sam...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, unbanning, unwarning, kicking, muting, and unmuting, but stored warning reasons are still printed by /warns without mention suppression. A moderator can create a warning with @everyo...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate users above them in the Discord role hierarchy, as long as the bot itself outranks the target. This bypasses Discord’s normal role hierarchy protections an...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not reject an empty result. Adding a rule containing only whitespace stores an empty word. The message listener later checks content.includes(""), which is always true, causing...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking member. They do not check the member’s effective permissions in the channel where the command is run. A user denied channel-level moderation permissions ...

Vendor: duck-organization
Product: questbot
Published: Jun 12, 2026
Source: NVD

A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure aga...

Published: Jun 12, 2026
Source: NVD
CVE-2026-11849 CRITICAL - 9.8

The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.

Vendor: IEI Integration Corp
Product: iRM-TSi410X
Published: Jun 12, 2026
Source: NVD