Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,766
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,481 - 1,500 of 36,556 CVEs
CVE-2026-42127 HIGH - 7.5

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token ...

Vendor: Grafana
Product: Grafana Enterprise, Grafana OSS
Published: Jun 22, 2026
Source: NVD
CVE-2026-12249 CRITICAL - 9.0

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plai...

Vendor: Canonical
Product: Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, Ubuntu 26.04 LTS
Published: Jun 22, 2026
Source: NVD

Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.

Vendor: Akaunting
Product: Akaunting
Published: Jun 22, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 22, 2026
Source: NVD
CVE-2026-10789 CRITICAL - 9.6

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user...

Vendor: Autodesk
Product: Fusion
Published: Jun 22, 2026
Source: NVD
CVE-2026-33684 MEDIUM - 5.3

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

Vendor: composer
Product: wwbn/avideo
Published: Jun 22, 2026
Source: GitHub
CVE-2026-33646 CRITICAL - 9.6

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files, .tool-versions files are not su...

Vendor: rust
Product: mise
Published: Jun 22, 2026
Source: GitHub
CVE-2026-32315 MEDIUM - 5.5

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable by any local user on the system. This file contains...

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub
CVE-2026-31978 MEDIUM - 6.5

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal in the picture and movie API endpoints, suhc as /picture/{id}/preview/{filename}. Neither the API handlers, nor the medi...

Vendor: pip
Product: motioneye
Published: Jun 22, 2026
Source: GitHub

Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from client requests without validating that the request originated from a trusted reverse proxy....

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2025-64719 MEDIUM - 4.9

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition in which the pages containing the listing of files will return HTTP error 500 and render the web interface unusabl...

Vendor: go
Product: gogs.io/gogs
Published: Jun 22, 2026
Source: GitHub
CVE-2026-9610 LOW - 2.3

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.

Published: Jun 22, 2026
Source: NVD
CVE-2026-9320 MEDIUM - 5.9

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resour...

Vendor: ibm
Product: websphere_application_server
Published: Jun 22, 2026
Source: NVD
CVE-2026-9072 HIGH - 8.1

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an...

Vendor: ibm
Product: i
Published: Jun 22, 2026
Source: NVD
CVE-2026-9071 HIGH - 7.5

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resour...

Vendor: ibm
Product: websphere_application_server
Published: Jun 22, 2026
Source: NVD
CVE-2026-9006 HIGH - 7.4

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.

Vendor: ibm
Product: websphere_application_server
Published: Jun 22, 2026
Source: NVD

A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on...

Published: Jun 22, 2026
Source: NVD
CVE-2026-8858 HIGH - 7.5

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application s...

Vendor: ibm
Product: i
Published: Jun 22, 2026
Source: NVD
CVE-2026-8823 LOW - 3.8

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669

Vendor: mattermost
Product: mattermost_server
Published: Jun 22, 2026
Source: NVD
CVE-2026-8646 HIGH - 7.4

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security contr...

Vendor: ibm
Product: websphere_application_server
Published: Jun 22, 2026
Source: NVD