Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,638
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,301 - 1,320 of 36,815 CVEs

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 24, 2026
Source: NVD
CVE-2026-56111 CRITICAL - 9.1

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that allows attackers to corrupt firmware memory by supplying out-of-range X and Y grid indices. Attackers can send a single c...

Vendor: MarlinFirmware
Product: Marlin
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD
CVE-2026-49269 HIGH - 8.6

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads stale register values left by a separate sandboxed victim app. In the proof of concept, GPUVictim.app generates a fresh random 128...

Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto ...

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component.

Vendor: Frappe
Product: Frappe Framework
Published: Jun 24, 2026
Source: NVD

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain. A Server-Sid...

Vendor: Payara
Product: Payara Server
Published: Jun 24, 2026
Source: NVD

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.

Vendor: OpenText
Product: Access Manager
Published: Jun 24, 2026
Source: NVD

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager.Β This issue affects Access Manager before 5.1.3.

Vendor: OpenText
Product: Access Manager
Published: Jun 24, 2026
Source: NVD
CVE-2026-57307 MEDIUM - 4.2

A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Vendor: Jenkins Project
Product: Jenkins Zowe zDevOps Plugin
Published: Jun 24, 2026
Source: NVD
CVE-2026-57306 MEDIUM - 4.2

A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Vendor: Jenkins Project
Product: Jenkins Zowe zDevOps Plugin
Published: Jun 24, 2026
Source: NVD