Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,920
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,241 - 1,260 of 34,601 CVEs

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_bo...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code executi...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD
CVE-2026-48723 HIGH - 7.8

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a sh...

Vendor: browserstack
Product: browserstack-cypress-cli
Published: Jun 15, 2026
Source: NVD

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body. In 'Elixir.GRPC.Server.Transc...

Vendor: elixir-grpc
Product: grpc
Published: Jun 15, 2026
Source: NVD
CVE-2026-12205 CRITICAL - 9.1

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same obj...

Vendor: TIMLEGGE
Product: Crypt::DSA
Published: Jun 15, 2026
Source: NVD

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial of service. HP is releasing software updates to mitigate these potential vulnerabilities.

Published: Jun 15, 2026
Source: NVD
CVE-2026-48714 CRITICAL - 9.1

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did n...

Vendor: i18next
Product: i18next-http-middleware
Published: Jun 15, 2026
Source: NVD
CVE-2026-48713 CRITICAL - 9.1

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configu...

Vendor: i18next
Product: i18next-fs-backend
Published: Jun 15, 2026
Source: NVD
CVE-2026-48157 MEDIUM - 6.1

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses HttpException::setTitle() and/or setDescription() to include untrusted/request-derived data in the error title or description (e.g. "No products fou...

Vendor: slimphp
Product: Slim
Published: Jun 15, 2026
Source: NVD
CVE-2026-12087 CRITICAL - 9.1

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-b...

Vendor: PEVANS
Product: Socket
Published: Jun 15, 2026
Source: NVD
CVE-2026-11832 CRITICAL - 9.1

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

Vendor: BIAFRA
Product: Dancer2::Plugin::Auth::OAuth
Published: Jun 15, 2026
Source: NVD
CVE-2026-9691 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

Published: Jun 15, 2026
Source: NVD
CVE-2026-52703 CRITICAL - 9.6

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

Vendor: Ninja Team
Product: FastDup
Published: Jun 15, 2026
Source: NVD
CVE-2026-52702 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

Vendor: wp-buy
Product: SEO Redirection
Published: Jun 15, 2026
Source: NVD
CVE-2026-52700 HIGH - 8.5

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

Vendor: WcMultishipping โ€“ Mondial Relay & Chronopost for Wooommerce
Product: WCMultiShipping
Published: Jun 15, 2026
Source: NVD
CVE-2026-52699 HIGH - 7.5

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

Vendor: e4jvikwp
Product: VikRentCar
Published: Jun 15, 2026
Source: NVD
CVE-2026-52697 HIGH - 8.5

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

Vendor: Taskbuilder
Product: Taskbuilder
Published: Jun 15, 2026
Source: NVD
CVE-2026-52695 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

Vendor: Al Monsor
Product: ABC Crypto Checkout
Published: Jun 15, 2026
Source: NVD
CVE-2026-52694 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

Vendor: WP E-Signature
Product: Signature Add-On for WooCommerce
Published: Jun 15, 2026
Source: NVD