Total CVEs

139,961

Critical Severity

3,664

High Severity

13,210

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 121 - 140 of 36,366 CVEs

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

Published: Jun 25, 2026
Source: NVD

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be accepted. This only affects builds with CRL support enabled and where a crafted CRL had a trusted signature when parsed...

Published: Jun 25, 2026
Source: NVD

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

Published: Jun 25, 2026
Source: NVD
CVE-2026-56445 CRITICAL - 9.1

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

Vendor: pydicom
Product: pynetdicom Library
Published: Jun 25, 2026
Source: NVD
CVE-2026-38640 HIGH - 7.5

A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.

Published: Jun 25, 2026
Source: NVD

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published: Jun 25, 2026
Source: NVD

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component

Published: Jun 25, 2026
Source: NVD
CVE-2026-12473 HIGH - 8.2

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attack...

Vendor: Open Health Imaging Foundation (OHIF)
Product: DICOM Web Viewer Framework
Published: Jun 25, 2026
Source: NVD

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.

Published: Jun 25, 2026
Source: NVD

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template reference...

Vendor: bitwarden
Product: server
Published: Jun 25, 2026
Source: NVD
CVE-2026-57521 MEDIUM - 4.3

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization checks. Attackers ca...

Vendor: bitwarden
Product: server
Published: Jun 25, 2026
Source: NVD
CVE-2026-57520 HIGH - 7.1

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin or...

Vendor: bitwarden
Product: server
Published: Jun 25, 2026
Source: NVD

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is present, but chain-supplied temporary CAs (WOLFSSL_TEMP_CA) added while building a certificate path were previously exemp...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so ParseCertRelative() accepts it without performing any trust verification; it must therefore only be accepted when RPK was actually negotiated for that peer...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fails to return, so execution falls through to an XMEMCPY that writes past the end of the buffer once the accumulated TLS 1...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

Vendor: golang.org/x/image
Product: golang.org/x/image/tiff
Published: Jun 25, 2026
Source: NVD

The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.

Vendor: golang.org/x/image
Product: golang.org/x/image/webp
Published: Jun 25, 2026
Source: NVD

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-ECB encryption

Published: Jun 25, 2026
Source: NVD

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_SERVICE_2 pipe

Published: Jun 25, 2026
Source: NVD

GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

Published: Jun 25, 2026
Source: NVD