Total CVEs

149,967

Critical Severity

4,910

High Severity

17,396

Last 7 Days

1,779
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 11,541 - 11,560 of 46,372 CVEs
CVE-2026-55255 CRITICAL - 9.9

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID...

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-42895 MEDIUM - 6.5

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-32208 HIGH - 8.8

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge_chromium
Published: Jun 19, 2026
Source: NVD

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafte...

Vendor: pip
Product: py7zr
Published: Jun 19, 2026
Source: GitHub

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that e...

Vendor: pip
Product: py7zr
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55187 MEDIUM - 5.8

Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.IsInternalIP deny-list in internal/tools/net.go relies on Go's standard library classification helpers and does not block IPv6 transition mechanis...

Vendor: go
Product: github.com/axllent/mailpit
Published: Jun 19, 2026
Source: GitHub

Open Redirect Bypass in miniflux-v2

Vendor: go
Product: miniflux.app/v2
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54762 MEDIUM - 8.6

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported ngi...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55847 MEDIUM - 6.1

Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering

Vendor: maven
Product: io.qameta.allure:allure-generator
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55846 MEDIUM - 6.2

Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read

Vendor: maven
Product: io.qameta.allure:allure-commandline
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55837 MEDIUM - 6.8

dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens

Vendor: pip
Product: dbt-mcp
Published: Jun 19, 2026
Source: GitHub

go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)

Vendor: go
Product: go.qbee.io/transport
Published: Jun 19, 2026
Source: GitHub

Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich-text URL-sanitization bypass enable stored XSS and session takeover. The library registers window message listeners โ€” the useTina overlay handler, the...

Vendor: npm
Product: tinacms
Published: Jun 19, 2026
Source: GitHub

Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass

Vendor: composer
Product: craftcms/commerce
Published: Jun 19, 2026
Source: GitHub

Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default pe...

Vendor: composer
Product: craftcms/cms
Published: Jun 19, 2026
Source: GitHub
CVE-2026-54074 HIGH - 7.8

Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-Tina migration command. The internal helper addVariablesToCode unquotes any value matching the marker "__TINA_INTERNAL__:::(.*?):::" inside th...

Vendor: npm
Product: @tinacms/cli
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55691 HIGH - 8.6

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55690 HIGH - 7.5

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55091 HIGH - 7.5

flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key

Vendor: npm
Product: flat-to-nested
Published: Jun 19, 2026
Source: GitHub

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges...

Vendor: npm
Product: @cyclonedx/cyclonedx-npm
Published: Jun 19, 2026
Source: GitHub