Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,668
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,381 - 1,400 of 36,344 CVEs
CVE-2026-12804 MEDIUM - 4.3

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is poss...

Product: lemonldap-ng
Published: Jun 21, 2026
Source: NVD
CVE-2026-56412 MEDIUM - 4.9

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56411 MEDIUM - 6.9

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56410 MEDIUM - 6.9

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56409 MEDIUM - 6.5

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56408 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in copyString.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56407 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56406 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56405 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in getAttributeId.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56404 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in addBinding.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56403 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in storeAtts.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56397 CRITICAL - 9.6

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayNa...

Vendor: SiYuan
Product: SiYuan
Published: Jun 21, 2026
Source: NVD
CVE-2026-56396 HIGH - 8.8

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to Super...

Vendor: phpMyFAQ
Product: phpMyFAQ
Published: Jun 21, 2026
Source: NVD
CVE-2026-56395 CRITICAL - 9.6

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayNa...

Vendor: SiYuan
Product: SiYuan
Published: Jun 21, 2026
Source: NVD
CVE-2026-56394 MEDIUM - 6.5

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowi...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56393 MEDIUM - 4.8

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw ...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56385 MEDIUM - 4.3

Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to supply a...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56384 MEDIUM - 4.3

Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback transform preview link...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56383 MEDIUM - 4.8

Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an administrator account (with allowAdminC...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56382 HIGH - 7.2

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cle...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD