Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,607
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,481 - 1,500 of 36,815 CVEs
CVE-2026-54329 HIGH - 8.5

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub

Snipe-IT has Improper Authorization in File Deletion (IDOR)

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub

Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55482 MEDIUM - 6.3

Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-50550 MEDIUM - 5.8

Snipe-IT has a 2FA reset privilege bypass

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-49976 MEDIUM - 6.5

Snipe-IT Vulnerable to User Account Escalation via CSV Import

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-49870 MEDIUM - 5.9

Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-48500 MEDIUM - 6.5

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, ...

Vendor: composer
Product: filament/filament
Published: Jun 23, 2026
Source: GitHub
CVE-2026-48496 MEDIUM - 6.2

opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent

Vendor: go
Product: go.opentelemetry.io/ebpf-profiler
Published: Jun 23, 2026
Source: GitHub
CVE-2026-48493 MEDIUM - 5.5

Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser โ€” for example `assets.view`, `assets.create`, `reports.view`, import, etc. The is...

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub

Snipe-IT's selectlist visibility is too permissive

Vendor: composer
Product: snipe/snipe-it
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54517 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54516 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54515 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54514 MEDIUM - 5.3

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54513 HIGH - 8.1

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating t...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54512 HIGH - 8.1

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorph...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-50193 MEDIUM - 7.5

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNod...

Vendor: maven
Product: com.fasterxml.jackson.core:jackson-databind
Published: Jun 23, 2026
Source: GitHub
CVE-2026-9073 MEDIUM - 6.2

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credentials, at an informational level. The other, when debug logging...

Published: Jun 23, 2026
Source: NVD