Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 121 - 140 of 36,689 CVEs
CVE-2026-44732 MEDIUM - 4.3

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and then updated. During update, attacker-controlled attributes are ap...

Vendor: opf
Product: openproject
Published: Jun 26, 2026
Source: NVD
CVE-2026-44731 MEDIUM - 4.3

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all existing user ...

Vendor: opf
Product: openproject
Published: Jun 26, 2026
Source: NVD
CVE-2026-44696 MEDIUM - 5.7

OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for inline style sanitization. This configuration permits essentially all CSS properties in style attributes on permitte...

Vendor: opf
Product: openproject
Published: Jun 26, 2026
Source: NVD
CVE-2026-32833 HIGH - 8.8

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. Attac...

Vendor: Shenzhen Cudy Technology Co., Ltd.
Product: LT300 3.0
Published: Jun 26, 2026
Source: NVD
CVE-2026-29509 MEDIUM - 5.4

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison,...

Vendor: wummel
Product: patool
Published: Jun 26, 2026
Source: NVD
CVE-2026-48785 MEDIUM - 4.8

Apptainer has incorrect path matching for 'limit container paths' directive

Vendor: go
Product: github.com/apptainer/apptainer
Published: Jun 26, 2026
Source: GitHub
CVE-2026-54753 MEDIUM - 5.9

Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Origin: * on every response, letting any website a developer visited read the server's responses cross-origin — includ...

Vendor: nrwl
Product: nx
Published: Jun 26, 2026
Source: NVD
CVE-2026-48090 MEDIUM - 5.9

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream that has already been torn down. A late AsyncClie...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD
CVE-2026-47220 HIGH - 7.5

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST, it's possible to crash Envoy when the specif...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD
CVE-2026-47205 MEDIUM - 5.9

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentation fault exists in Envoy's ext_authz HTTP filter when processing per-route authorization overri...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD
CVE-2026-13372 HIGH - 7.2

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name col...

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 26, 2026
Source: NVD
CVE-2026-48769 CRITICAL - 9.9

Incus has an arbitrary file write on its client due to trusted image hash

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48758 MEDIUM - 5.4

@sigstore/core has DSSE payloadType type-binding failure

Vendor: npm
Product: @sigstore/core
Published: Jun 26, 2026
Source: GitHub

Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48755 CRITICAL - 9.9

Incus has an argument injection in backup compression algorithm leading to AFW and ACE

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub

Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48753 CRITICAL - 9.9

Incus has an arbitrary file write via path traversal in S3 multipart upload

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48752 CRITICAL - 9.9

Incus has arbitrary file read+write on host via templates/ symlink in malicious image

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48751 CRITICAL - 9.9

Incus has a restricted project bypass leading to arbitrary command execution

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48750 CRITICAL - 9.9

Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub