Total CVEs

139,258

Critical Severity

3,630

High Severity

13,017

Last 7 Days

1,247
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,301 - 1,320 of 35,663 CVEs
CVE-2026-55517 MEDIUM - 4.3

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket connection could be crashed by the remote server. While handling the WebSocket handshake response, Deno parsed the Sec-WebSocket-Protocol and Sec-WebSocket-Extensions response head...

Vendor: rust
Product: deno
Published: Jun 17, 2026
Source: GitHub

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.utilities
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55470 HIGH - 7.5

HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55450 CRITICAL - 9.3

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server....

Vendor: pip
Product: langflow
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55760 HIGH - 7.5

handlebars.java FileTemplateLoader Path Traversal

Vendor: maven
Product: com.github.jknack:handlebars
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55409 HIGH - 7.6

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized already when the form state was filled, an...

Vendor: composer
Product: filament/forms
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55405 HIGH - 7.6

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

Vendor: maven
Product: dev.langchain4j:langchain4j-mariadb
Published: Jun 17, 2026
Source: GitHub
CVE-2026-9697 HIGH - 7.4

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-9679 MEDIUM - 5.9

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 ยง5.4 does not specify any decoding and browsers do not decode either. Applications that parse a ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-9678 MEDIUM - 5.9

Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow.This issue affects Connext Professional: from 7.4.0 before 7.*, from 7.0.0 before 7.3.1.3, from 6.1.2 bef...

Published: Jun 17, 2026
Source: NVD
CVE-2026-6734 HIGH - 7.5

Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination. This c...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-6733 LOW - 3.7

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-53805 CRITICAL - 9.8

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input...

Vendor: nv-tlabs
Product: GEN3C
Published: Jun 17, 2026
Source: NVD

Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site scripting via unescaped HTML attribute values. 'Elixir.Earmark.Transform':_make_att1/2 in lib/earmark/transform.ex splices attribute values verbatim between two literal...

Vendor: pragdave
Product: earmark
Published: Jun 17, 2026
Source: NVD
CVE-2026-47774 HIGH - 7.5

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentia...

Vendor: envoyproxy
Product: envoy
Published: Jun 17, 2026
Source: NVD

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.

Published: Jun 17, 2026
Source: NVD

snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.

Vendor: Snes9X team
Product: Snes9X
Published: Jun 17, 2026
Source: NVD

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0.

Vendor: RTI
Product: Connext Micro
Published: Jun 17, 2026
Source: NVD

Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0.

Vendor: RTI
Product: Connext Micro
Published: Jun 17, 2026
Source: NVD