Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,711
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,061 - 1,080 of 36,572 CVEs

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD
CVE-2026-49269 HIGH - 8.6

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads stale register values left by a separate sandboxed victim app. In the proof of concept, GPUVictim.app generates a fresh random 128...

Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto ...

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain. A Server-Sid...

Vendor: Payara
Product: Payara Server
Published: Jun 24, 2026
Source: NVD

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.

Vendor: OpenText
Product: Access Manager
Published: Jun 24, 2026
Source: NVD

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager.Β This issue affects Access Manager before 5.1.3.

Vendor: OpenText
Product: Access Manager
Published: Jun 24, 2026
Source: NVD
CVE-2026-57307 MEDIUM - 4.2

A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Vendor: Jenkins Project
Product: Jenkins Zowe zDevOps Plugin
Published: Jun 24, 2026
Source: NVD
CVE-2026-57306 MEDIUM - 4.2

A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Vendor: Jenkins Project
Product: Jenkins Zowe zDevOps Plugin
Published: Jun 24, 2026
Source: NVD
CVE-2026-57305 MEDIUM - 5.4

A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified username and password.

Vendor: Jenkins Project
Product: Jenkins Assembla Plugin
Published: Jun 24, 2026
Source: NVD
CVE-2026-57304 MEDIUM - 5.4

A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.

Vendor: Jenkins Project
Product: Jenkins Assembla Plugin
Published: Jun 24, 2026
Source: NVD
CVE-2026-57303 HIGH - 7.1

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.

Vendor: Jenkins Project
Product: Jenkins Assembla Plugin
Published: Jun 24, 2026
Source: NVD