Total CVEs

149,293

Critical Severity

4,762

High Severity

17,016

Last 7 Days

2,818
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,181 - 10,200 of 45,698 CVEs

Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1.0.1 allows a remote, unauthenticated attacker to self-register a working account on instances where registration is intended to be restricted, b...

Vendor: Mailerup
Product: Mailerup
Published: Jun 24, 2026
Source: NVD
CVE-2026-56121 CRITICAL - 9.8

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from ba...

Vendor: feast-dev
Product: feast
Published: Jun 24, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 24, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 24, 2026
Source: NVD
CVE-2026-56111 CRITICAL - 9.1

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that allows attackers to corrupt firmware memory by supplying out-of-range X and Y grid indices. Attackers can send a single c...

Vendor: MarlinFirmware
Product: Marlin
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD
CVE-2026-49269 HIGH - 8.6

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads stale register values left by a separate sandboxed victim app. In the proof of concept, GPUVictim.app generates a fresh random 128...

Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto ...

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain. A Server-Sid...

Vendor: Payara
Product: Payara Server
Published: Jun 24, 2026
Source: NVD
CVE-2026-11878 MEDIUM - 6.1

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.

Vendor: OpenText
Product: Access Manager
Published: Jun 24, 2026
Source: NVD