Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,704
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,281 - 1,300 of 36,572 CVEs
CVE-2026-54323 MEDIUM - 5.9

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization h...

Vendor: daytonaio
Product: daytona
Published: Jun 23, 2026
Source: NVD
CVE-2026-54318 HIGH - 7.1

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResul...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-54317 HIGH - 7.6

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = F...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-53662 CRITICAL - 9.6

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The co...

Vendor: immich-app
Product: immich
Published: Jun 23, 2026
Source: NVD

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redire...

Vendor: OpenStack
Product: Swift
Published: Jun 23, 2026
Source: NVD

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Published: Jun 23, 2026
Source: NVD
CVE-2025-71382 MEDIUM - 6.5

MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable...

Vendor: ArtifexSoftware
Product: mupdf
Published: Jun 23, 2026
Source: NVD
CVE-2025-61029 HIGH - 7.5

An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61024 HIGH - 7.5

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2020-9713 MEDIUM - 5.5

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose se...

Vendor: adobe
Product: acrobat_dc
Published: Jun 23, 2026
Source: NVD
CVE-2020-9711 MEDIUM - 5.5

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of t...

Vendor: adobe
Product: acrobat_dc
Published: Jun 23, 2026
Source: NVD
CVE-2020-9695 HIGH - 7.8

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic...

Vendor: adobe
Product: acrobat_dc
Published: Jun 23, 2026
Source: NVD
CVE-2026-54557 MEDIUM - 5.5

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the HTTP backend's syml...

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub

OctoPrint has possible file exfiltration via query parameters on upload endpoints

Vendor: pip
Product: OctoPrint
Published: Jun 23, 2026
Source: GitHub
CVE-2026-53925 HIGH - 7.8

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation o...

Vendor: pip
Product: glances
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54350 CRITICAL - 10.0

Budibase has nonymous NoSQL operator injection via published-app query templates

Vendor: npm
Product: @budibase/server
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55173 HIGH - 8.1

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

Vendor: composer
Product: wwbn/avideo
Published: Jun 23, 2026
Source: GitHub

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST /-/api/sanitize_ipynb allows arbitrary data: URIs without proper restrictions, potentially leading to Cross-Site Scripting (XSS). The endpoint uses bluemonday.UGCPolicy() with p.A...

Vendor: go
Product: gogs.io/gogs
Published: Jun 23, 2026
Source: GitHub
CVE-2026-45049 HIGH - 8.3

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

Vendor: maven
Product: org.openidentityplatform.openam:openam-federation
Published: Jun 23, 2026
Source: GitHub
CVE-2026-45048 HIGH - 8.5

OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC

Vendor: maven
Product: org.openidentityplatform.openam:openam-core
Published: Jun 23, 2026
Source: GitHub