Total CVEs

149,335

Critical Severity

4,787

High Severity

17,139

Last 7 Days

2,860
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,621 - 10,640 of 45,740 CVEs
CVE-2026-48506 HIGH - 7.5

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses MessagePackSecurity.MaximumObjectGraphDepth, the...

Vendor: messagepack
Product: messagepack
Published: Jun 22, 2026
Source: NVD
CVE-2026-48505 HIGH - 7.4

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affec...

Vendor: filamentphp
Product: filament
Published: Jun 22, 2026
Source: NVD
CVE-2026-48502 HIGH - 7.5

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension ...

Vendor: messagepack
Product: messagepack
Published: Jun 22, 2026
Source: NVD
CVE-2026-48167 MEDIUM - 6.4

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plan...

Vendor: filamentphp
Product: filament
Published: Jun 22, 2026
Source: NVD
CVE-2026-48166 MEDIUM - 5.3

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an ...

Vendor: filamentphp
Product: filament
Published: Jun 22, 2026
Source: NVD
CVE-2025-71358 HIGH - 8.1

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims using pickle.load().

Vendor: picklescan
Product: picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2025-71344 HIGH - 8.1

picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._run_pip calls in __reduce__ methods bypass picklescan detecti...

Vendor: picklescan
Product: picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2025-71339 HIGH - 8.1

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation...

Vendor: Picklescan
Product: Picklescan
Published: Jun 22, 2026
Source: NVD
CVE-2026-46700 MEDIUM - 4.3

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any au...

Vendor: npm
Product: @actual-app/sync-server
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46672 MEDIUM - 4.6

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neu...

Vendor: npm
Product: @actual-app/cli
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46611 MEDIUM - 5.3

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leaving it vulnerable to DNS rebinding attacks. An attacker can exploit DNS rebinding to exfiltrate the f...

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46608 HIGH - 7.4

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silently falls back to Access-Control-Allow-Origin: * w...

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-46607 HIGH - 7.8

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity ...

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub
CVE-2026-55599 MEDIUM - 5.8

phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects t...

Vendor: phpseclib
Product: phpseclib
Published: Jun 22, 2026
Source: NVD
CVE-2026-54651 MEDIUM - 5.5

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulnerability is fixed in 6.13.1.

Vendor: py-pdf
Product: pypdf
Published: Jun 22, 2026
Source: NVD
CVE-2026-39904 MEDIUM - 6.5

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP...

Vendor: gophish
Product: gophish
Published: Jun 22, 2026
Source: NVD
CVE-2026-46606 HIGH - 7.8

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/virsh.py) passes VM domain names, read directly from virsh list --all output, into f-string command templates that are processed by secure_popen(). sec...

Vendor: pip
Product: glances
Published: Jun 22, 2026
Source: GitHub

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

Vendor: maven
Product: org.openidentityplatform.opendj:opendj-server-legacy
Published: Jun 22, 2026
Source: GitHub

motionEye: Authentication possible via password hash

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub
CVE-2026-44795 HIGH - 8.5

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of...

Vendor: maven
Product: io.spinnaker.rosco:rosco-core
Published: Jun 22, 2026
Source: GitHub