Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,292
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,021 - 1,040 of 35,847 CVEs
CVE-2026-55187 MEDIUM - 5.8

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Vendor: go
Product: github.com/axllent/mailpit
Published: Jun 19, 2026
Source: GitHub

Open Redirect Bypass in miniflux-v2

Vendor: go
Product: miniflux.app/v2
Published: Jun 19, 2026
Source: GitHub

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported ngi...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55847 MEDIUM - 6.1

Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering

Vendor: maven
Product: io.qameta.allure:allure-generator
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55846 MEDIUM - 6.2

Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read

Vendor: maven
Product: io.qameta.allure:allure-commandline
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55837 MEDIUM - 6.8

dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens

Vendor: pip
Product: dbt-mcp
Published: Jun 19, 2026
Source: GitHub

go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)

Vendor: go
Product: go.qbee.io/transport
Published: Jun 19, 2026
Source: GitHub

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

Vendor: npm
Product: tinacms
Published: Jun 19, 2026
Source: GitHub

Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass

Vendor: composer
Product: craftcms/commerce
Published: Jun 19, 2026
Source: GitHub

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Vendor: composer
Product: craftcms/cms
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54074 HIGH - 7.8

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration โ€” unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

Vendor: npm
Product: @tinacms/cli
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55691 HIGH - 8.6

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55690 HIGH - 7.5

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55091 HIGH - 7.5

flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key

Vendor: npm
Product: flat-to-nested
Published: Jun 19, 2026
Source: GitHub

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

Vendor: npm
Product: @cyclonedx/cyclonedx-npm
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54911 MEDIUM - 6.5

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into diffe...

Vendor: pip
Product: ujson
Published: Jun 19, 2026
Source: GitHub

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can...

Vendor: rubygems
Product: concurrent-ruby
Published: Jun 19, 2026
Source: GitHub

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The lock stores a thread's local read and write hold counts in one integer. The low 15 bits are use...

Vendor: rubygems
Product: concurrent-ruby
Published: Jun 19, 2026
Source: GitHub

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is caused by the interaction between AtomicReference#update, which retries until compare_and_set(old_value,...

Vendor: rubygems
Product: concurrent-ruby
Published: Jun 19, 2026
Source: GitHub

Oj: Integer Overflow in Oj.load 2GB String Handling

Vendor: rubygems
Product: oj
Published: Jun 19, 2026
Source: GitHub