Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 121 - 140 of 12,906 CVEs
CVE-2026-48990 MEDIUM - 5.3

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversized RFC7797 b64=false JWS payloads without applying JWSRegistry.max_payload_length, which can lead to resource exhaustion...

Vendor: authlib
Product: joserfc
Published: Jun 17, 2026
Source: NVD
CVE-2026-49133 MEDIUM - 6.5

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content directory by supplying traversal sequences in the path query parameter passed to Storage::getFile() with an empty folder argumen...

Vendor: typemill
Product: typemill
Published: Jun 17, 2026
Source: NVD
CVE-2026-48821 MEDIUM - 5.8

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process, malicious bookmark titles are returned via an AJAX response and inserted i...

Vendor: shaarli
Product: Shaarli
Published: Jun 17, 2026
Source: NVD
CVE-2026-55201 MEDIUM - 6.8

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server to write files outside the intended download directory by returning filenames with traversal sequences from Get-ChildItem c...

Vendor: Hackplayers
Product: evil-winrm
Published: Jun 17, 2026
Source: NVD
CVE-2026-55199 MEDIUM - 5.9

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can s...

Vendor: libssh2
Product: libssh2
Published: Jun 17, 2026
Source: NVD
CVE-2026-48823 MEDIUM - 4.8

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An authenticated user can inject arbitrary JavaScript into the tags field when creating a bookmark (Shaare). The malicious pay...

Vendor: shaarli
Product: Shaarli
Published: Jun 17, 2026
Source: NVD
CVE-2026-48822 MEDIUM - 5.8

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in the Bookmark Description field. An authenticated user can inject a malicious javascript: URI inside a Markdown link. The v...

Vendor: shaarli
Product: Shaarli
Published: Jun 17, 2026
Source: NVD
CVE-2026-32682 MEDIUM - 6.5

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: So...

Vendor: F5
Product: NGINX Gateway Fabric
Published: Jun 17, 2026
Source: NVD
CVE-2026-55198 MEDIUM - 6.5

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before serializing session d...

Vendor: nesquena
Product: hermes-webui
Published: Jun 17, 2026
Source: NVD
CVE-2026-55197 MEDIUM - 6.5

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to other profiles via GET /a...

Vendor: nesquena
Product: hermes-webui
Published: Jun 17, 2026
Source: NVD
CVE-2026-53870 MEDIUM - 5.5

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including con...

Vendor: NousResearch
Product: hermes-agent
Published: Jun 17, 2026
Source: NVD

CakePHP Authentication: Open redirect weakness via backslash bypass

Vendor: composer
Product: cakephp/authentication
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55517 MEDIUM - 4.3

Deno: Denial of service via non-ASCII bytes in WebSocket response headers

Vendor: rust
Product: deno
Published: Jun 17, 2026
Source: GitHub
CVE-2026-9679 MEDIUM - 5.9

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 ยง5.4 does not specify any decoding and browsers do not decode either. Applications that parse a ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-9678 MEDIUM - 5.9

Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves ...

Vendor: npm
Product: undici
Published: Jun 17, 2026
Source: NVD
CVE-2026-20265 MEDIUM - 4.3

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration. The vul...

Vendor: Splunk
Product: Splunk AI Toolkit
Published: Jun 17, 2026
Source: NVD
CVE-2026-20178 MEDIUM - 4.3

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to impro...

Vendor: Cisco
Product: Cisco Webex App
Published: Jun 17, 2026
Source: NVD
CVE-2026-55636 MEDIUM - 5.7

Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected

Vendor: go
Product: github.com/projectcapsule/capsule
Published: Jun 17, 2026
Source: GitHub

Gitea: Open Redirect via redirect_to

Vendor: go
Product: github.com/go-gitea/gitea
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54324 MEDIUM - 6.5

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 17, 2026
Source: GitHub