Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,364
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,121 - 1,140 of 33,671 CVEs
CVE-2026-50245 HIGH - 7.7

Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.

Vendor: Brickcom
Product: Cube, Dome, Bullet, Box
Published: Jun 11, 2026
Source: NVD
CVE-2026-50005 HIGH - 7.7

Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.

Vendor: Brickcom
Product: Cube, Dome, Bullet, Box
Published: Jun 11, 2026
Source: NVD
CVE-2026-41005 CRITICAL - 9.0

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to fa...

Vendor: Cloud Foundry
Product: UAA, CF Deployment
Published: Jun 11, 2026
Source: NVD
CVE-2026-48109 HIGH - 8.2

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

Vendor: nuget
Product: MessagePack
Published: Jun 11, 2026
Source: GitHub
CVE-2025-27511 HIGH - 7.2

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

Vendor: maven
Product: org.geoserver.extension:gs-db2
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48099 HIGH - 7.1

WsgiDAV encoded dot segments can escape filesystem share roots

Vendor: pip
Product: wsgidav
Published: Jun 11, 2026
Source: GitHub

DevGuard has improper authorization on public assets

Vendor: go
Product: github.com/l3montree-dev/devguard
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48067 MEDIUM - 6.5

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

Vendor: composer
Product: filament/tables
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48059 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested ...

Vendor: maven
Product: io.netty:netty-codec-haproxy
Published: Jun 11, 2026
Source: GitHub
CVE-2026-53782 HIGH - 7.4

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, or other reserved destinations by supplying malicio...

Vendor: steipete
Product: summarize
Published: Jun 11, 2026
Source: NVD
CVE-2026-53781 MEDIUM - 4.3

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attacke...

Vendor: steipete
Product: summarize
Published: Jun 11, 2026
Source: NVD
CVE-2026-49973 CRITICAL - 9.4

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable networ...

Vendor: nesquena
Product: hermes-webui
Published: Jun 11, 2026
Source: NVD
CVE-2026-49949 MEDIUM - 5.3

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carryi...

Vendor: steipete
Product: CodexBar
Published: Jun 11, 2026
Source: NVD
CVE-2026-46622 HIGH - 8.1

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconf...

Vendor: SolidInvoice
Product: SolidInvoice
Published: Jun 11, 2026
Source: NVD
CVE-2026-46489 HIGH - 8.1

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every ...

Vendor: SolidInvoice
Product: SolidInvoice
Published: Jun 11, 2026
Source: NVD

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to ...

Vendor: CyberArk Software, a Palo Alto Networks Company
Product: Idira Endpoint Privilege Manager
Published: Jun 11, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 11, 2026
Source: NVD
CVE-2026-53702 MEDIUM - 6.5

A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the r...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 11, 2026
Source: NVD
CVE-2026-53701 MEDIUM - 6.5

An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bou...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 11, 2026
Source: NVD
CVE-2026-52860 HIGH - 7.8

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD