Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,704
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,241 - 1,260 of 36,572 CVEs

Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55482 MEDIUM - 6.3

Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-50550 MEDIUM - 5.8

Snipe-IT has a 2FA reset privilege bypass

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-49976 MEDIUM - 6.5

Snipe-IT Vulnerable to User Account Escalation via CSV Import

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-49870 MEDIUM - 5.9

Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-48500 MEDIUM - 6.5

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, ...

Vendor: composer
Product: filament/filament
Published: Jun 23, 2026
Source: GitHub
CVE-2026-48496 MEDIUM - 6.2

opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent

Vendor: go
Product: go.opentelemetry.io/ebpf-profiler
Published: Jun 23, 2026
Source: GitHub
CVE-2026-48493 MEDIUM - 5.5

Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser โ€” for example `assets.view`, `assets.create`, `reports.view`, import, etc. The is...

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub

Snipe-IT's selectlist visibility is too permissive

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54517 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54516 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54515 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54514 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54513 HIGH - 8.1

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating t...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54512 HIGH - 8.1

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorph...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNod...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-9073 MEDIUM - 6.2

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credentials, at an informational level. The other, when debug logging...

Published: Jun 23, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-56784.

Published: Jun 23, 2026
Source: NVD
CVE-2026-54518 MEDIUM - 6.5

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(act...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users service is an empty stub being called from passwordChange, passwordForgot, and passwordReset. OAuth access and refresh tokens were not revoked when the user changed, reset, or recov...

Vendor: nocodb
Product: nocodb
Published: Jun 23, 2026
Source: NVD