Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

962
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,001 - 1,020 of 35,348 CVEs
CVE-2026-47774 HIGH - 7.5

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentia...

Vendor: envoyproxy
Product: envoy
Published: Jun 17, 2026
Source: NVD

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.

Published: Jun 17, 2026
Source: NVD

snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.

Vendor: Snes9X team
Product: Snes9X
Published: Jun 17, 2026
Source: NVD

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0.

Vendor: RTI
Product: Connext Micro
Published: Jun 17, 2026
Source: NVD

Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0.

Vendor: RTI
Product: Connext Micro
Published: Jun 17, 2026
Source: NVD

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.*, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.

Vendor: RTI
Product: Connext Professional
Published: Jun 17, 2026
Source: NVD

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5....

Published: Jun 17, 2026
Source: NVD

Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers, Overflow Buffers, Overflow Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 befor...

Published: Jun 17, 2026
Source: NVD

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 ...

Published: Jun 17, 2026
Source: NVD
CVE-2026-20266 CRITICAL - 9.1

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which...

Vendor: Splunk
Product: Splunk AI Toolkit
Published: Jun 17, 2026
Source: NVD
CVE-2026-20265 MEDIUM - 4.3

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration. The vul...

Vendor: Splunk
Product: Splunk AI Toolkit
Published: Jun 17, 2026
Source: NVD
CVE-2026-20178 MEDIUM - 4.3

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to impro...

Vendor: Cisco
Product: Cisco Webex App
Published: Jun 17, 2026
Source: NVD

Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSit...

Vendor: undici
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-55636 MEDIUM - 5.7

Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected

Vendor: go
Product: github.com/projectcapsule/capsule
Published: Jun 17, 2026
Source: GitHub

Gitea: Open Redirect via redirect_to

Vendor: go
Product: github.com/go-gitea/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-28737 HIGH - 8.7

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-24791 HIGH - 8.1

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-22555 HIGH - 8.1

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54324 MEDIUM - 6.5

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authorization flaw in Daytona's notification WebSocket gateway allowed any authenticated user to subscribe to another organization's realtime notific...

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 17, 2026
Source: GitHub

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to...

Vendor: npm
Product: @anthropic-ai/claude-code
Published: Jun 17, 2026
Source: GitHub